Edit tour

Windows Analysis Report
https://img.coomer.su

Overview

General Information

Sample URL:https://img.coomer.su
Analysis ID:1409083
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5548 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2316,i,6034162144704438259,7818471723701003585,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6544 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://img.coomer.su MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: img.coomer.suConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: img.coomer.suConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://img.coomer.su/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __ddg1_=wRx2pnhc8IugwHWTzys7
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: img.coomer.suConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __ddg1_=wRx2pnhc8IugwHWTzys7
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=czY+TvggYDdC3WB&MD=6F2LWcDO HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=czY+TvggYDdC3WB&MD=6F2LWcDO HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: img.coomer.su
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2316,i,6034162144704438259,7818471723701003585,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://img.coomer.su
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2316,i,6034162144704438259,7818471723701003585,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1409083 URL: https://img.coomer.su Startdate: 14/03/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49734 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.176.196, 443, 49738, 49752 GOOGLEUS United States 10->17 19 coomer.su 190.115.31.47, 443, 49734, 49735 DDOS-GUARDCORPBZ Belize 10->19 21 img.coomer.su 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://img.coomer.su0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://img.coomer.su/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
coomer.su
190.115.31.47
truefalse
    unknown
    www.google.com
    142.250.176.196
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        img.coomer.su
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://img.coomer.su/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://img.coomer.su/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            190.115.31.47
            coomer.suBelize
            262254DDOS-GUARDCORPBZfalse
            142.250.176.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1409083
            Start date and time:2024-03-14 17:00:02 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 6s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://img.coomer.su
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/5@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.80.67, 142.250.80.46, 172.253.63.84, 34.104.35.123, 72.21.81.240, 192.229.211.108, 20.166.126.56, 20.242.39.171
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://img.coomer.su
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):2
            Entropy (8bit):1.0
            Encrypted:false
            SSDEEP:3:V:V
            MD5:E0AA021E21DDDBD6D8CECEC71E9CF564
            SHA1:9CE3BD4224C8C1780DB56B4125ECF3F24BF748B7
            SHA-256:565339BC4D33D72817B583024112EB7F5CDF3E5EEF0252D6EC1B9C9A94E12BB3
            SHA-512:900110C951560EFF857B440E89CC29F529416E0E3B3D7F0AD51651BFDBD8025B91768C5ED7DB5352D1A5523354CE06CED2C42047E33A3E958A1BBA5F742DB874
            Malicious:false
            Reputation:low
            URL:https://img.coomer.su/
            Preview:OK
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:dropped
            Size (bytes):15086
            Entropy (8bit):2.913397257535209
            Encrypted:false
            SSDEEP:192:jtyNleokldLjU81AisBolpxXvjfBGylShipmgP:jtNLH1ATcxXrYthipb
            MD5:C5B6E16C783BF7B32242A13629F59D35
            SHA1:5B644AEDD4787226A1F5DEDAE03D09FAE6E1EC92
            SHA-256:4122ABA8DFE280BB80B0769CBAC2787C93FAAC9A8A0CA3BD9D7AF8A183A6EBA9
            SHA-512:70055F4BD862737DD432AE1EFDFB72D188E4AE53D78DF406C1A002D252EF4DC0DD882E4F6D2775D2EEC2EDCC935D964CBE13EC48ED568BC46E66AD614766E613
            Malicious:false
            Reputation:low
            Preview:......00.... ..%..6... .... ......%........ .h....6..(...0...`..... ......$.............................................................................................................E...E...E...E...0...0.......................................................................................................................................................................s...........................................................................................................................................................................................0...................................E.......................................................................................................................................................................................................................................................................................................................................................[#....t......t...f...W...f..........#......[..............
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:downloaded
            Size (bytes):15086
            Entropy (8bit):2.913397257535209
            Encrypted:false
            SSDEEP:192:jtyNleokldLjU81AisBolpxXvjfBGylShipmgP:jtNLH1ATcxXrYthipb
            MD5:C5B6E16C783BF7B32242A13629F59D35
            SHA1:5B644AEDD4787226A1F5DEDAE03D09FAE6E1EC92
            SHA-256:4122ABA8DFE280BB80B0769CBAC2787C93FAAC9A8A0CA3BD9D7AF8A183A6EBA9
            SHA-512:70055F4BD862737DD432AE1EFDFB72D188E4AE53D78DF406C1A002D252EF4DC0DD882E4F6D2775D2EEC2EDCC935D964CBE13EC48ED568BC46E66AD614766E613
            Malicious:false
            Reputation:low
            URL:https://img.coomer.su/favicon.ico
            Preview:......00.... ..%..6... .... ......%........ .h....6..(...0...`..... ......$.............................................................................................................E...E...E...E...0...0.......................................................................................................................................................................s...........................................................................................................................................................................................0...................................E.......................................................................................................................................................................................................................................................................................................................................................[#....t......t...f...W...f..........#......[..............
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 113
            • 443 (HTTPS)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Mar 14, 2024 17:00:45.094410896 CET49678443192.168.2.4104.46.162.224
            Mar 14, 2024 17:00:45.547439098 CET49675443192.168.2.4173.222.162.32
            Mar 14, 2024 17:00:55.892465115 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.892549038 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:55.892709017 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.893115997 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.893163919 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:55.893222094 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.893528938 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.893559933 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:55.893759966 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:55.893785000 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.172410011 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.172744036 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.172781944 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.174103975 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.174299002 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.174336910 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.174647093 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.174715996 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.175672054 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.175759077 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.175882101 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.175895929 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.175904989 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.175939083 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.176868916 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.176964998 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.218481064 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.218483925 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.218521118 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.264784098 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.520883083 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.521039009 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.521250010 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.532229900 CET49734443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.532263994 CET44349734190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.686151028 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.686201096 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.686280966 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.686883926 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.686897993 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.752235889 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.796276093 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.890908003 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.891310930 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.891340971 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.892879963 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.892954111 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.893960953 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.894032001 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.910938978 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.910967112 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.910975933 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.910993099 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.911000967 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.911009073 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.911045074 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.911078930 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.911096096 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.911106110 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.911130905 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.911143064 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.913110018 CET49735443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:56.913127899 CET44349735190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:56.945687056 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:56.945714951 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:00:56.985665083 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:00:57.049525976 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.049575090 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.049633026 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.050029039 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.050045013 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.297322989 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.303992033 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.304069996 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.305085897 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.305159092 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.305999041 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.306072950 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.306396961 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.306410074 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.358694077 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572340965 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572360039 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572365999 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572428942 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572432995 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572478056 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572500944 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572524071 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572530031 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572530031 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572531939 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:57.572567940 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572568893 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.572596073 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.574086905 CET49739443192.168.2.4190.115.31.47
            Mar 14, 2024 17:00:57.574121952 CET44349739190.115.31.47192.168.2.4
            Mar 14, 2024 17:00:58.482908964 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:58.482997894 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:58.483088017 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:58.491862059 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:58.491899967 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:58.678971052 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:58.679099083 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:58.683545113 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:58.683571100 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:58.683825970 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:58.733717918 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.063802958 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.104274988 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.155797958 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.155975103 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.156030893 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.156363964 CET49742443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.156384945 CET4434974223.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.212879896 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.212923050 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.213000059 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.213725090 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.213746071 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.395632029 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.395823002 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.398716927 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.398742914 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.399013996 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.402697086 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.448239088 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.576541901 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.576664925 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.576853037 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.579056978 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.579102039 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:00:59.579132080 CET49743443192.168.2.423.51.58.94
            Mar 14, 2024 17:00:59.579145908 CET4434974323.51.58.94192.168.2.4
            Mar 14, 2024 17:01:06.910626888 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:06.910803080 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:06.910881042 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:07.769726038 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:07.769781113 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:07.769869089 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:07.772259951 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:07.772280931 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:07.939188957 CET49738443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:07.939244032 CET44349738142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:08.200871944 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:08.200963974 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:08.210529089 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:08.210544109 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:08.211517096 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:08.265525103 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:08.810812950 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:08.852240086 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085069895 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085102081 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085113049 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085130930 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085139990 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085149050 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085175991 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.085213900 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085235119 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085235119 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.085251093 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085263014 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.085269928 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085283995 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.085309982 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.085315943 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085354090 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.085467100 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.346541882 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.346609116 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:09.346656084 CET49744443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:09.346673965 CET4434974452.165.165.26192.168.2.4
            Mar 14, 2024 17:01:45.787523031 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:45.787556887 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:45.787616014 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:45.788700104 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:45.788716078 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.206027031 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.206222057 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.227271080 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.227307081 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.228176117 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.255898952 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.300230980 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.604700089 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.604732990 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.604777098 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.604820013 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.604839087 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.604877949 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.605133057 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.605144024 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.605161905 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.605180025 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.605210066 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.605210066 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.605222940 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.605283022 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.605317116 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.605504036 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.612883091 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.612909079 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:46.612981081 CET49750443192.168.2.452.165.165.26
            Mar 14, 2024 17:01:46.612988949 CET4434975052.165.165.26192.168.2.4
            Mar 14, 2024 17:01:56.657169104 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:56.657259941 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.657342911 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:56.657653093 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:56.657687902 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.846613884 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.847183943 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:56.847220898 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.847695112 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.848151922 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:01:56.848248005 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:01:56.890372038 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:02:06.845928907 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:02:06.846098900 CET44349752142.250.176.196192.168.2.4
            Mar 14, 2024 17:02:06.846257925 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:02:07.939168930 CET49752443192.168.2.4142.250.176.196
            Mar 14, 2024 17:02:07.939237118 CET44349752142.250.176.196192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Mar 14, 2024 17:00:53.826404095 CET53618361.1.1.1192.168.2.4
            Mar 14, 2024 17:00:53.829942942 CET53524921.1.1.1192.168.2.4
            Mar 14, 2024 17:00:54.380461931 CET53568581.1.1.1192.168.2.4
            Mar 14, 2024 17:00:55.617919922 CET6399353192.168.2.41.1.1.1
            Mar 14, 2024 17:00:55.620693922 CET5129353192.168.2.41.1.1.1
            Mar 14, 2024 17:00:55.867646933 CET53639931.1.1.1192.168.2.4
            Mar 14, 2024 17:00:55.889360905 CET53512931.1.1.1192.168.2.4
            Mar 14, 2024 17:00:56.593698978 CET6027053192.168.2.41.1.1.1
            Mar 14, 2024 17:00:56.594083071 CET5614053192.168.2.41.1.1.1
            Mar 14, 2024 17:00:56.681996107 CET53561401.1.1.1192.168.2.4
            Mar 14, 2024 17:00:56.682188988 CET53602701.1.1.1192.168.2.4
            Mar 14, 2024 17:00:56.930860043 CET5215053192.168.2.41.1.1.1
            Mar 14, 2024 17:00:56.931616068 CET5631953192.168.2.41.1.1.1
            Mar 14, 2024 17:00:57.019673109 CET53521501.1.1.1192.168.2.4
            Mar 14, 2024 17:00:57.178886890 CET53563191.1.1.1192.168.2.4
            Mar 14, 2024 17:01:11.574763060 CET53601061.1.1.1192.168.2.4
            Mar 14, 2024 17:01:15.615715981 CET138138192.168.2.4192.168.2.255
            Mar 14, 2024 17:01:30.635935068 CET53556601.1.1.1192.168.2.4
            Mar 14, 2024 17:01:52.693588972 CET53521521.1.1.1192.168.2.4
            Mar 14, 2024 17:01:53.849323988 CET53527491.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Mar 14, 2024 17:00:57.178986073 CET192.168.2.41.1.1.1c226(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 14, 2024 17:00:55.617919922 CET192.168.2.41.1.1.10xce65Standard query (0)img.coomer.suA (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:55.620693922 CET192.168.2.41.1.1.10x1cd4Standard query (0)img.coomer.su65IN (0x0001)false
            Mar 14, 2024 17:00:56.593698978 CET192.168.2.41.1.1.10xe7b2Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:56.594083071 CET192.168.2.41.1.1.10xf30eStandard query (0)www.google.com65IN (0x0001)false
            Mar 14, 2024 17:00:56.930860043 CET192.168.2.41.1.1.10x8504Standard query (0)img.coomer.suA (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:56.931616068 CET192.168.2.41.1.1.10xb803Standard query (0)img.coomer.su65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 14, 2024 17:00:55.867646933 CET1.1.1.1192.168.2.40xce65No error (0)img.coomer.sucoomer.suCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:00:55.867646933 CET1.1.1.1192.168.2.40xce65No error (0)coomer.su190.115.31.47A (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:55.889360905 CET1.1.1.1192.168.2.40x1cd4No error (0)img.coomer.sucoomer.suCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:00:56.681996107 CET1.1.1.1192.168.2.40xf30eNo error (0)www.google.com65IN (0x0001)false
            Mar 14, 2024 17:00:56.682188988 CET1.1.1.1192.168.2.40xe7b2No error (0)www.google.com142.250.176.196A (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:57.019673109 CET1.1.1.1192.168.2.40x8504No error (0)img.coomer.sucoomer.suCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:00:57.019673109 CET1.1.1.1192.168.2.40x8504No error (0)coomer.su190.115.31.47A (IP address)IN (0x0001)false
            Mar 14, 2024 17:00:57.178886890 CET1.1.1.1192.168.2.40xb803No error (0)img.coomer.sucoomer.suCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:01:08.920517921 CET1.1.1.1192.168.2.40xb99No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:01:08.920517921 CET1.1.1.1192.168.2.40xb99No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 14, 2024 17:01:21.683576107 CET1.1.1.1192.168.2.40x5e1fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:01:21.683576107 CET1.1.1.1192.168.2.40x5e1fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 14, 2024 17:01:45.724159002 CET1.1.1.1192.168.2.40x5ccNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:01:45.724159002 CET1.1.1.1192.168.2.40x5ccNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 14, 2024 17:02:05.385049105 CET1.1.1.1192.168.2.40xe400No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 14, 2024 17:02:05.385049105 CET1.1.1.1192.168.2.40xe400No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • img.coomer.su
            • https:
            • fs.microsoft.com
            • slscr.update.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449734190.115.31.474435900C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-14 16:00:56 UTC656OUTGET / HTTP/1.1
            Host: img.coomer.su
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-14 16:00:56 UTC310INHTTP/1.1 200 OK
            Server: ddos-guard
            Connection: close
            Content-Security-Policy: upgrade-insecure-requests;
            Set-Cookie: __ddg1_=wRx2pnhc8IugwHWTzys7; Domain=.coomer.su; HttpOnly; Path=/; Expires=Fri, 14-Mar-2025 16:00:56 GMT
            Date: Thu, 14 Mar 2024 16:00:56 GMT
            Content-Type: text/html
            Content-Length: 2
            2024-03-14 16:00:56 UTC2INData Raw: 4f 4b
            Data Ascii: OK


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735190.115.31.474435900C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-14 16:00:56 UTC620OUTGET /favicon.ico HTTP/1.1
            Host: img.coomer.su
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://img.coomer.su/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: __ddg1_=wRx2pnhc8IugwHWTzys7
            2024-03-14 16:00:56 UTC326INHTTP/1.1 200 OK
            Server: ddos-guard
            Connection: close
            Content-Security-Policy: upgrade-insecure-requests;
            Date: Tue, 12 Mar 2024 16:29:32 GMT
            Content-Type: image/x-icon
            Content-Length: 15086
            Last-Modified: Mon, 10 Oct 2022 21:02:38 GMT
            Accept-Ranges: bytes
            Etag: "6344886e-3aee"
            Age: 171084
            DDG-Cache-Status: HIT
            2024-03-14 16:00:56 UTC15086INData Raw: 00 00 01 00 03 00 30 30 00 00 01 00 20 00 a8 25 00 00 36 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 de 25 00 00 10 10 00 00 01 00 20 00 68 04 00 00 86 36 00 00 28 00 00 00 30 00 00 00 60 00 00 00 01 00 20 00 00 00 00 00 00 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 00 00 45 00 00 00 45 00 00 00 45 00 00 00 45 00 00 00 30 00 00 00 30 00 00 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
            Data Ascii: 00 %6 % h6(0` $EEEE00


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449739190.115.31.474435900C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-14 16:00:57 UTC386OUTGET /favicon.ico HTTP/1.1
            Host: img.coomer.su
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: __ddg1_=wRx2pnhc8IugwHWTzys7
            2024-03-14 16:00:57 UTC326INHTTP/1.1 200 OK
            Server: ddos-guard
            Connection: close
            Content-Security-Policy: upgrade-insecure-requests;
            Date: Tue, 12 Mar 2024 16:29:32 GMT
            Content-Type: image/x-icon
            Content-Length: 15086
            Last-Modified: Mon, 10 Oct 2022 21:02:38 GMT
            Accept-Ranges: bytes
            Etag: "6344886e-3aee"
            Age: 171085
            DDG-Cache-Status: HIT
            2024-03-14 16:00:57 UTC15086INData Raw: 00 00 01 00 03 00 30 30 00 00 01 00 20 00 a8 25 00 00 36 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 de 25 00 00 10 10 00 00 01 00 20 00 68 04 00 00 86 36 00 00 28 00 00 00 30 00 00 00 60 00 00 00 01 00 20 00 00 00 00 00 00 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 00 00 45 00 00 00 45 00 00 00 45 00 00 00 45 00 00 00 30 00 00 00 30 00 00 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
            Data Ascii: 00 %6 % h6(0` $EEEE00


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974223.51.58.94443
            TimestampBytes transferredDirectionData
            2024-03-14 16:00:59 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-14 16:00:59 UTC784INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0778)
            X-CID: 11
            X-CCC: US
            X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
            X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
            Content-Type: application/octet-stream
            X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=25970
            Date: Thu, 14 Mar 2024 16:00:59 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.44974323.51.58.94443
            TimestampBytes transferredDirectionData
            2024-03-14 16:00:59 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-14 16:00:59 UTC455INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0778)
            X-CID: 11
            Cache-Control: public, max-age=25964
            Date: Thu, 14 Mar 2024 16:00:59 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-03-14 16:00:59 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.44974452.165.165.26443
            TimestampBytes transferredDirectionData
            2024-03-14 16:01:08 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=czY+TvggYDdC3WB&MD=6F2LWcDO HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-03-14 16:01:09 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
            MS-CorrelationId: 065a9814-16dd-4a55-8086-d2b7575c95e2
            MS-RequestId: eb7dc19e-d4c1-471a-8190-debf49460b8e
            MS-CV: g6vVX8aUNU6E4tdH.0
            X-Microsoft-SLSClientCache: 2880
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Thu, 14 Mar 2024 16:01:08 GMT
            Connection: close
            Content-Length: 24490
            2024-03-14 16:01:09 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
            Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
            2024-03-14 16:01:09 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
            Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.44975052.165.165.26443
            TimestampBytes transferredDirectionData
            2024-03-14 16:01:46 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=czY+TvggYDdC3WB&MD=6F2LWcDO HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-03-14 16:01:46 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
            MS-CorrelationId: 76e7cc65-ea47-4bb0-a286-03ff6d36ba5d
            MS-RequestId: be75d8c3-4477-4056-9170-8be9b3d9bdac
            MS-CV: iQwKSrLp+kqn5EFD.0
            X-Microsoft-SLSClientCache: 2160
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Thu, 14 Mar 2024 16:01:45 GMT
            Connection: close
            Content-Length: 25457
            2024-03-14 16:01:46 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
            Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
            2024-03-14 16:01:46 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
            Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:0
            Start time:17:00:47
            Start date:14/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:17:00:50
            Start date:14/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2316,i,6034162144704438259,7818471723701003585,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:17:00:54
            Start date:14/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://img.coomer.su
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly