Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://lib.tashop.co

Overview

General Information

Sample URL:http://lib.tashop.co
Analysis ID:1448099
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=2040,i,11875074848457030637,7533766725337186677,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lib.tashop.co" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: lib.tashop.coConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lib.tashop.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://lib.tashop.co/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: lib.tashop.co
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /report/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 382Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 27 May 2024 18:03:07 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closevary: Accept-Encodingvary: Origin, Access-Control-Request-Headers, Access-Control-Request-Methodlast-modified: Tue, 24 Mar 2020 20:51:45 GMTx-rgw-object-type: Normalx-envoy-upstream-healthchecked-cluster: CF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 88a7eb78b94618b1-EWRalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 27 May 2024 18:03:08 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closevary: Accept-Encodingvary: Origin, Access-Control-Request-Headers, Access-Control-Request-Methodlast-modified: Tue, 24 Mar 2020 20:51:45 GMTx-rgw-object-type: Normalx-envoy-upstream-healthchecked-cluster: CF-Cache-Status: EXPIREDReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zDzgGi1qVAaXpvaqpuIbdXVaEnymWWmAnpZEgo9m%2FoPwRN36N21Ad3FEPZjitKH%2FC6MbMNlVwfLvzz7eFRdVRBIc11q6NxmzL%2Bue3aYUIQhU2xmTKJZnVPGqZVYjbDy%2F"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 88a7eb7fad2d7cf6-EWRalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=2040,i,11875074848457030637,7533766725337186677,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lib.tashop.co"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=2040,i,11875074848457030637,7533766725337186677,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://lib.tashop.co0%Avira URL Cloudsafe
http://lib.tashop.co0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://a.nel.cloudflare.com/report/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX0%Avira URL Cloudsafe
https://lib.tashop.co/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    unknown
    lib.tashop.co
    188.114.96.3
    truefalse
      unknown
      www.google.com
      142.250.186.68
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://lib.tashop.co/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://lib.tashop.co/false
            unknown
            https://a.nel.cloudflare.com/report/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oXfalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.186.68
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            188.114.96.3
            lib.tashop.coEuropean Union
            13335CLOUDFLARENETUSfalse
            35.190.80.1
            a.nel.cloudflare.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1448099
            Start date and time:2024-05-27 20:02:13 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 12s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://lib.tashop.co
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/4@8/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.163, 142.250.186.46, 64.233.166.84, 34.104.35.123, 40.68.123.157, 95.101.54.115, 95.101.54.121, 95.101.54.195, 2.16.202.114, 95.101.54.114, 95.101.54.203, 2.16.202.128, 192.229.221.95, 20.3.187.198, 142.250.186.35
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):79
            Entropy (8bit):4.1327709379957485
            Encrypted:false
            SSDEEP:3:qVoB3tGFUvOkoR0WhtoAcMdKKqBcWWGb:q43tSUWPhh0MAK3fGb
            MD5:7080CABF7666E59E5CCB2D1F82EC3FC2
            SHA1:A6C0C2DAE6BAA719151105E90B9155DE1CA2E1A5
            SHA-256:391608B073BE9701DED83082D70D50EA06673185F6C3E0411BE38FD1F5235D20
            SHA-512:45FBA14A2782CBA01BD1F49DE08B8BE985997C898CE9ED7A6C7A1C214988D1C518AAC8F5E88C02717568D829FBCE497E56CEADD8AABA19A4AF7A272BDB9E021B
            Malicious:false
            Reputation:low
            URL:https://lib.tashop.co/
            Preview:<html>..<head>.. <title>TAS</title>....</head>..<body>..Ok..</body>..</html>
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):79
            Entropy (8bit):4.1327709379957485
            Encrypted:false
            SSDEEP:3:qVoB3tGFUvOkoR0WhtoAcMdKKqBcWWGb:q43tSUWPhh0MAK3fGb
            MD5:7080CABF7666E59E5CCB2D1F82EC3FC2
            SHA1:A6C0C2DAE6BAA719151105E90B9155DE1CA2E1A5
            SHA-256:391608B073BE9701DED83082D70D50EA06673185F6C3E0411BE38FD1F5235D20
            SHA-512:45FBA14A2782CBA01BD1F49DE08B8BE985997C898CE9ED7A6C7A1C214988D1C518AAC8F5E88C02717568D829FBCE497E56CEADD8AABA19A4AF7A272BDB9E021B
            Malicious:false
            Reputation:low
            URL:https://lib.tashop.co/favicon.ico
            Preview:<html>..<head>.. <title>TAS</title>....</head>..<body>..Ok..</body>..</html>
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            May 27, 2024 20:02:55.870348930 CEST49678443192.168.2.4104.46.162.224
            May 27, 2024 20:02:56.385955095 CEST49675443192.168.2.4173.222.162.32
            May 27, 2024 20:03:05.993956089 CEST49675443192.168.2.4173.222.162.32
            May 27, 2024 20:03:06.443125963 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.443166018 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.443269014 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.443445921 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.443455935 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.919589996 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.919936895 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.919970036 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.921394110 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.921457052 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.922487974 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.922570944 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.922645092 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:06.922656059 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:06.967930079 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.317184925 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:07.317464113 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:07.317545891 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.325035095 CEST49735443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.325053930 CEST44349735188.114.96.3192.168.2.4
            May 27, 2024 20:03:07.334943056 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.334992886 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.335057020 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.335721016 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.335737944 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.524892092 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.524935007 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:07.524998903 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.525221109 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:07.525233030 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:07.846581936 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.846873045 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.846906900 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.848553896 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.848733902 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.849867105 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.849968910 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.850500107 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.850516081 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.893933058 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.982453108 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.982640028 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.982707977 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.983082056 CEST49737443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.983104944 CEST4434973735.190.80.1192.168.2.4
            May 27, 2024 20:03:07.985580921 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.985672951 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:07.985753059 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.986588001 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:07.986624956 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.014872074 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.024806976 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.024820089 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.026170969 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.027054071 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.027127028 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.027239084 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.072309971 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.212014914 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.212295055 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.212388039 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.249403954 CEST49739443192.168.2.4188.114.96.3
            May 27, 2024 20:03:08.249428034 CEST44349739188.114.96.3192.168.2.4
            May 27, 2024 20:03:08.469875097 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.474982023 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.475044966 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.475562096 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.476006985 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.476098061 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.476135015 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.518503904 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.525445938 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.609926939 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.610109091 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.610198975 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.610574007 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.610620022 CEST4434974035.190.80.1192.168.2.4
            May 27, 2024 20:03:08.610649109 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:08.610677958 CEST49740443192.168.2.435.190.80.1
            May 27, 2024 20:03:09.109901905 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.109992981 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.110074043 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.110624075 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.110658884 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.761665106 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.763844967 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.763859034 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.764945984 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.765000105 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.770065069 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.770122051 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.823379040 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.823399067 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:09.869149923 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:09.911637068 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:09.911719084 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:09.911813974 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:09.914509058 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:09.914568901 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.560518026 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.560739994 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.563823938 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.563851118 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.564275980 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.619259119 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.632024050 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.674500942 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.830661058 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.830832958 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.831191063 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.831393957 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.831418037 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.831434011 CEST49742443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.831442118 CEST44349742184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.899974108 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.900027990 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:10.900093079 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.900630951 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:10.900655985 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.554797888 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.555063963 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.556456089 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.556484938 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.557324886 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.561678886 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.606494904 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.836381912 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.836570024 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.836657047 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.838824034 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.838824034 CEST49743443192.168.2.4184.28.90.27
            May 27, 2024 20:03:11.838867903 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:11.838896036 CEST44349743184.28.90.27192.168.2.4
            May 27, 2024 20:03:19.663563013 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:19.663671970 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:03:19.663717985 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:20.965221882 CEST49741443192.168.2.4142.250.186.68
            May 27, 2024 20:03:20.965245008 CEST44349741142.250.186.68192.168.2.4
            May 27, 2024 20:04:07.339487076 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.339543104 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.339617014 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.339919090 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.339930058 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.824060917 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.824331999 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.824393988 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.825506926 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.825910091 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.826044083 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.826090097 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.869458914 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.954282045 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.954533100 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.954547882 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.954579115 CEST4434975235.190.80.1192.168.2.4
            May 27, 2024 20:04:07.954634905 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.954668045 CEST49752443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.955096006 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.955137014 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:07.955229044 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.955477953 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:07.955507040 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.425327063 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.425713062 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:08.425741911 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.426129103 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.426454067 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:08.426547050 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.426589012 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:08.470558882 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.478846073 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:08.558059931 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.558397055 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:08.558442116 CEST4434975335.190.80.1192.168.2.4
            May 27, 2024 20:04:08.558516979 CEST49753443192.168.2.435.190.80.1
            May 27, 2024 20:04:09.145483017 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:09.145541906 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.145735025 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:09.146161079 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:09.146202087 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.837686062 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.838781118 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:09.838814020 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.839135885 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.839761972 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:09.839827061 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:09.884119987 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:14.806267023 CEST4972380192.168.2.4199.232.214.172
            May 27, 2024 20:04:14.806350946 CEST4972480192.168.2.4199.232.214.172
            May 27, 2024 20:04:14.812077999 CEST8049723199.232.214.172192.168.2.4
            May 27, 2024 20:04:14.812149048 CEST4972380192.168.2.4199.232.214.172
            May 27, 2024 20:04:14.812341928 CEST8049724199.232.214.172192.168.2.4
            May 27, 2024 20:04:14.812403917 CEST4972480192.168.2.4199.232.214.172
            May 27, 2024 20:04:19.742835999 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:19.743012905 CEST44349754142.250.186.68192.168.2.4
            May 27, 2024 20:04:19.743199110 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:20.965333939 CEST49754443192.168.2.4142.250.186.68
            May 27, 2024 20:04:20.965435028 CEST44349754142.250.186.68192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            May 27, 2024 20:03:04.623985052 CEST53505201.1.1.1192.168.2.4
            May 27, 2024 20:03:04.640903950 CEST53502141.1.1.1192.168.2.4
            May 27, 2024 20:03:05.663053989 CEST53523581.1.1.1192.168.2.4
            May 27, 2024 20:03:06.388735056 CEST6175453192.168.2.41.1.1.1
            May 27, 2024 20:03:06.390578032 CEST6290853192.168.2.41.1.1.1
            May 27, 2024 20:03:06.401761055 CEST53617541.1.1.1192.168.2.4
            May 27, 2024 20:03:06.402345896 CEST53629081.1.1.1192.168.2.4
            May 27, 2024 20:03:06.404738903 CEST4980353192.168.2.41.1.1.1
            May 27, 2024 20:03:06.404865980 CEST5433953192.168.2.41.1.1.1
            May 27, 2024 20:03:06.412978888 CEST53543391.1.1.1192.168.2.4
            May 27, 2024 20:03:06.442791939 CEST53498031.1.1.1192.168.2.4
            May 27, 2024 20:03:07.323788881 CEST5960853192.168.2.41.1.1.1
            May 27, 2024 20:03:07.324110985 CEST6022553192.168.2.41.1.1.1
            May 27, 2024 20:03:07.332050085 CEST53602251.1.1.1192.168.2.4
            May 27, 2024 20:03:07.334045887 CEST53596081.1.1.1192.168.2.4
            May 27, 2024 20:03:09.091526985 CEST5064753192.168.2.41.1.1.1
            May 27, 2024 20:03:09.091789007 CEST5934353192.168.2.41.1.1.1
            May 27, 2024 20:03:09.107078075 CEST53593431.1.1.1192.168.2.4
            May 27, 2024 20:03:09.107119083 CEST53506471.1.1.1192.168.2.4
            May 27, 2024 20:03:22.625581980 CEST53551951.1.1.1192.168.2.4
            May 27, 2024 20:03:26.397114038 CEST138138192.168.2.4192.168.2.255
            May 27, 2024 20:03:41.688898087 CEST53546111.1.1.1192.168.2.4
            May 27, 2024 20:04:04.097537994 CEST53600681.1.1.1192.168.2.4
            May 27, 2024 20:04:04.315730095 CEST53528951.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            May 27, 2024 20:03:06.388735056 CEST192.168.2.41.1.1.10xcbbStandard query (0)lib.tashop.coA (IP address)IN (0x0001)false
            May 27, 2024 20:03:06.390578032 CEST192.168.2.41.1.1.10xaf2eStandard query (0)lib.tashop.co65IN (0x0001)false
            May 27, 2024 20:03:06.404738903 CEST192.168.2.41.1.1.10xe68cStandard query (0)lib.tashop.coA (IP address)IN (0x0001)false
            May 27, 2024 20:03:06.404865980 CEST192.168.2.41.1.1.10x47c9Standard query (0)lib.tashop.co65IN (0x0001)false
            May 27, 2024 20:03:07.323788881 CEST192.168.2.41.1.1.10xe4e4Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
            May 27, 2024 20:03:07.324110985 CEST192.168.2.41.1.1.10x755aStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
            May 27, 2024 20:03:09.091526985 CEST192.168.2.41.1.1.10x5622Standard query (0)www.google.comA (IP address)IN (0x0001)false
            May 27, 2024 20:03:09.091789007 CEST192.168.2.41.1.1.10x1471Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            May 27, 2024 20:03:06.401761055 CEST1.1.1.1192.168.2.40xcbbNo error (0)lib.tashop.co188.114.96.3A (IP address)IN (0x0001)false
            May 27, 2024 20:03:06.401761055 CEST1.1.1.1192.168.2.40xcbbNo error (0)lib.tashop.co188.114.97.3A (IP address)IN (0x0001)false
            May 27, 2024 20:03:06.402345896 CEST1.1.1.1192.168.2.40xaf2eNo error (0)lib.tashop.co65IN (0x0001)false
            May 27, 2024 20:03:06.412978888 CEST1.1.1.1192.168.2.40x47c9No error (0)lib.tashop.co65IN (0x0001)false
            May 27, 2024 20:03:06.442791939 CEST1.1.1.1192.168.2.40xe68cNo error (0)lib.tashop.co188.114.96.3A (IP address)IN (0x0001)false
            May 27, 2024 20:03:06.442791939 CEST1.1.1.1192.168.2.40xe68cNo error (0)lib.tashop.co188.114.97.3A (IP address)IN (0x0001)false
            May 27, 2024 20:03:07.334045887 CEST1.1.1.1192.168.2.40xe4e4No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
            May 27, 2024 20:03:09.107078075 CEST1.1.1.1192.168.2.40x1471No error (0)www.google.com65IN (0x0001)false
            May 27, 2024 20:03:09.107119083 CEST1.1.1.1192.168.2.40x5622No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
            May 27, 2024 20:03:20.130968094 CEST1.1.1.1192.168.2.40x5308No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 20:03:20.130968094 CEST1.1.1.1192.168.2.40x5308No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 20:03:33.323012114 CEST1.1.1.1192.168.2.40x254cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 20:03:33.323012114 CEST1.1.1.1192.168.2.40x254cNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 20:03:56.611422062 CEST1.1.1.1192.168.2.40xa892No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 20:03:56.611422062 CEST1.1.1.1192.168.2.40xa892No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 20:04:17.864954948 CEST1.1.1.1192.168.2.40x849eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 20:04:17.864954948 CEST1.1.1.1192.168.2.40x849eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • lib.tashop.co
            • https:
            • a.nel.cloudflare.com
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735188.114.96.34433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:06 UTC656OUTGET / HTTP/1.1
            Host: lib.tashop.co
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:03:07 UTC788INHTTP/1.1 404 Not Found
            Date: Mon, 27 May 2024 18:03:07 GMT
            Content-Type: text/html; charset=utf-8
            Transfer-Encoding: chunked
            Connection: close
            vary: Accept-Encoding
            vary: Origin, Access-Control-Request-Headers, Access-Control-Request-Method
            last-modified: Tue, 24 Mar 2020 20:51:45 GMT
            x-rgw-object-type: Normal
            x-envoy-upstream-healthchecked-cluster:
            CF-Cache-Status: DYNAMIC
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            Server: cloudflare
            CF-RAY: 88a7eb78b94618b1-EWR
            alt-svc: h3=":443"; ma=86400
            2024-05-27 18:03:07 UTC85INData Raw: 34 66 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 41 53 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 4f 6b 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: 4f<html><head> <title>TAS</title></head><body>Ok</body></html>
            2024-05-27 18:03:07 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973735.190.80.14433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:07 UTC526OUTOPTIONS /report/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Origin: https://lib.tashop.co
            Access-Control-Request-Method: POST
            Access-Control-Request-Headers: content-type
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:03:07 UTC336INHTTP/1.1 200 OK
            content-length: 0
            access-control-max-age: 86400
            access-control-allow-methods: OPTIONS, POST
            access-control-allow-origin: *
            access-control-allow-headers: content-type, content-length
            date: Mon, 27 May 2024 18:03:07 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449739188.114.96.34433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:08 UTC582OUTGET /favicon.ico HTTP/1.1
            Host: lib.tashop.co
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://lib.tashop.co/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:03:08 UTC792INHTTP/1.1 404 Not Found
            Date: Mon, 27 May 2024 18:03:08 GMT
            Content-Type: text/html; charset=utf-8
            Transfer-Encoding: chunked
            Connection: close
            vary: Accept-Encoding
            vary: Origin, Access-Control-Request-Headers, Access-Control-Request-Method
            last-modified: Tue, 24 Mar 2020 20:51:45 GMT
            x-rgw-object-type: Normal
            x-envoy-upstream-healthchecked-cluster:
            CF-Cache-Status: EXPIRED
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zDzgGi1qVAaXpvaqpuIbdXVaEnymWWmAnpZEgo9m%2FoPwRN36N21Ad3FEPZjitKH%2FC6MbMNlVwfLvzz7eFRdVRBIc11q6NxmzL%2Bue3aYUIQhU2xmTKJZnVPGqZVYjbDy%2F"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            Server: cloudflare
            CF-RAY: 88a7eb7fad2d7cf6-EWR
            alt-svc: h3=":443"; ma=86400
            2024-05-27 18:03:08 UTC85INData Raw: 34 66 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 41 53 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 4f 6b 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: 4f<html><head> <title>TAS</title></head><body>Ok</body></html>
            2024-05-27 18:03:08 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974035.190.80.14433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:08 UTC470OUTPOST /report/v4?s=sFSnA15erijK0BDQbkxtGSjeHXKn%2FMc6WYGGruaQuu9gG1703gabtTHwfF2YtLRHXyCiHriPyjsVU8FkKAlmYlN5R9ZM9RN3QqC%2BFVJ8NilLSAE16KG69FHyz4vmn5oX HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Content-Length: 382
            Content-Type: application/reports+json
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:03:08 UTC382OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 39 31 37 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 36 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 6c 69 62 2e 74 61 73 68 6f 70 2e 63 6f 2f 22 2c 22
            Data Ascii: [{"age":0,"body":{"elapsed_time":917,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"188.114.96.3","status_code":404,"type":"http.error"},"type":"network-error","url":"https://lib.tashop.co/","
            2024-05-27 18:03:08 UTC168INHTTP/1.1 200 OK
            content-length: 0
            date: Mon, 27 May 2024 18:03:08 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449742184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:10 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-27 18:03:10 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=165964
            Date: Mon, 27 May 2024 18:03:10 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.449743184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-05-27 18:03:11 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-27 18:03:11 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=166046
            Date: Mon, 27 May 2024 18:03:11 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-05-27 18:03:11 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.44975235.190.80.14433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:04:07 UTC530OUTOPTIONS /report/v4?s=zDzgGi1qVAaXpvaqpuIbdXVaEnymWWmAnpZEgo9m%2FoPwRN36N21Ad3FEPZjitKH%2FC6MbMNlVwfLvzz7eFRdVRBIc11q6NxmzL%2Bue3aYUIQhU2xmTKJZnVPGqZVYjbDy%2F HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Origin: https://lib.tashop.co
            Access-Control-Request-Method: POST
            Access-Control-Request-Headers: content-type
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:04:07 UTC336INHTTP/1.1 200 OK
            content-length: 0
            access-control-max-age: 86400
            access-control-allow-methods: POST, OPTIONS
            access-control-allow-origin: *
            access-control-allow-headers: content-type, content-length
            date: Mon, 27 May 2024 18:04:07 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            7192.168.2.44975335.190.80.14433484C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-05-27 18:04:08 UTC474OUTPOST /report/v4?s=zDzgGi1qVAaXpvaqpuIbdXVaEnymWWmAnpZEgo9m%2FoPwRN36N21Ad3FEPZjitKH%2FC6MbMNlVwfLvzz7eFRdVRBIc11q6NxmzL%2Bue3aYUIQhU2xmTKJZnVPGqZVYjbDy%2F HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Content-Length: 419
            Content-Type: application/reports+json
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-05-27 18:04:08 UTC419OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 39 31 32 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 36 39 33 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 6c 69 62 2e 74 61 73 68 6f 70 2e 63 6f 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 36 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a
            Data Ascii: [{"age":59121,"body":{"elapsed_time":693,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://lib.tashop.co/","sampling_fraction":1.0,"server_ip":"188.114.96.3","status_code":404,"type":"http.error"},"type":"network-error","url":
            2024-05-27 18:04:08 UTC168INHTTP/1.1 200 OK
            content-length: 0
            date: Mon, 27 May 2024 18:04:08 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:14:02:58
            Start date:27/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:14:03:02
            Start date:27/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=2040,i,11875074848457030637,7533766725337186677,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:14:03:05
            Start date:27/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lib.tashop.co"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly