Edit tour

Windows Analysis Report
https://tgbot.cyb3r.army/700975049/Instagram.com.html

Overview

General Information

Sample URL:https://tgbot.cyb3r.army/700975049/Instagram.com.html
Analysis ID:1461165
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Detected non-DNS traffic on DNS port
HTTP GET or POST without a user agent

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 4532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2300,i,18393289357452397223,9561592466993645301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 4360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tgbot.cyb3r.army/700975049/Instagram.com.html" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://tgbot.cyb3r.army/700975049/Instagram.com.htmlAvira URL Cloud: detection malicious, Label: phishing
Source: https://tgbot.cyb3r.army/favicon.icoAvira URL Cloud: Label: malware
Source: tgbot.cyb3r.armyVirustotal: Detection: 11%Perma Link
Source: https://tgbot.cyb3r.army/700975049/Instagram.com.htmlVirustotal: Detection: 15%Perma Link
Source: https://tgbot.cyb3r.army/700975049/Instagram.com.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.7:49712 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.7:57532 -> 1.1.1.1:53
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ipinfo.ioConnection: Keep-Alive
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 20.101.57.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ipinfo.ioConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /700975049/Instagram.com.html HTTP/1.1Host: tgbot.cyb3r.armyConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: tgbot.cyb3r.armyConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://tgbot.cyb3r.army/700975049/Instagram.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: tgbot.cyb3r.army
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundkeep-alive: timeout=5, max=100cache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 1251date: Sat, 22 Jun 2024 22:35:33 GMTserver: LiteSpeedx-turbo-charged-by: LiteSpeedconnection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundkeep-alive: timeout=5, max=100cache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 1251date: Sat, 22 Jun 2024 22:35:33 GMTserver: LiteSpeedx-turbo-charged-by: LiteSpeedconnection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57537
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57537 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.7:49712 version: TLS 1.2
Source: classification engineClassification label: mal72.win@21/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2300,i,18393289357452397223,9561592466993645301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tgbot.cyb3r.army/700975049/Instagram.com.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2300,i,18393289357452397223,9561592466993645301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1461165 URL: https://tgbot.cyb3r.army/70... Startdate: 23/06/2024 Architecture: WINDOWS Score: 72 22 Multi AV Scanner detection for domain / URL 2->22 24 Antivirus detection for URL or domain 2->24 26 Antivirus / Scanner detection for submitted sample 2->26 28 Multi AV Scanner detection for submitted file 2->28 6 chrome.exe 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.7, 123, 138, 443 unknown unknown 6->14 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 142.250.185.132, 443, 49710, 57537 GOOGLEUS United States 11->18 20 tgbot.cyb3r.army 66.29.146.75, 443, 49706, 49707 ADVANTAGECOMUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://tgbot.cyb3r.army/700975049/Instagram.com.html100%Avira URL Cloudphishing
https://tgbot.cyb3r.army/700975049/Instagram.com.html16%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
tgbot.cyb3r.army12%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
www.google.com0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://ipinfo.io/0%URL Reputationsafe
https://tgbot.cyb3r.army/favicon.ico100%Avira URL Cloudmalware

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
tgbot.cyb3r.army
66.29.146.75
truefalseunknown
www.google.com
142.250.185.132
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
NameMaliciousAntivirus DetectionReputation
https://tgbot.cyb3r.army/favicon.icofalse
  • Avira URL Cloud: malware
unknown
https://ipinfo.io/false
  • URL Reputation: safe
unknown
https://tgbot.cyb3r.army/700975049/Instagram.com.htmltrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    66.29.146.75
    tgbot.cyb3r.armyUnited States
    19538ADVANTAGECOMUSfalse
    142.250.185.132
    www.google.comUnited States
    15169GOOGLEUSfalse
    IP
    192.168.2.7
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1461165
    Start date and time:2024-06-23 00:34:33 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 10s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:https://tgbot.cyb3r.army/700975049/Instagram.com.html
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:19
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal72.win@21/0@4/4
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 142.250.185.131, 142.250.181.238, 142.251.168.84, 34.104.35.123, 20.12.23.50, 93.184.221.240, 192.229.221.95, 52.165.164.15, 20.166.126.56, 13.85.23.206, 142.250.184.227, 131.107.255.255
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, time.windows.com, wu.azureedge.net, dns.msftncsi.com, clients2.google.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    InputOutput
    URL: https://tgbot.cyb3r.army/700975049/Instagram.com.html Model: Perplexity: mixtral-8x7b-instruct
    {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The title and text of the webpage do not contain a login form, as there are no explicit requests for sensitive information such as passwords, email addresses, usernames, phone numbers, or credit card numbers.","The title and text of the webpage do not create a sense of urgency or interest, as there are no phrases that encourage the user to click a link or view a document.","The title and text of the webpage do not contain a CAPTCHA or any other anti-robot detection mechanism."]}
    Title: 404 Not Found OCR: 404 Not Found The resource requested could not be tound on this server' Proudly 1K)wered by LiteS'Eed Web Server Please advised that LiteSgE-ed Technologies Inc. is not a web hosting cornpany and, as such, has no contr(l over found on this site. 
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    No static file info

    Download Network PCAP: filteredfull

    • Total Packets: 89
    • 443 (HTTPS)
    • 123 undefined
    • 53 (DNS)
    TimestampSource PortDest PortSource IPDest IP
    Jun 23, 2024 00:35:21.108740091 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:21.429658890 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:22.030347109 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:23.233550072 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:23.983443975 CEST49674443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:23.983606100 CEST49675443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:24.077291012 CEST49672443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:25.639682055 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:29.932148933 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:30.365065098 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:30.458265066 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:31.171155930 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:32.349463940 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.349493980 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:32.349546909 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.349728107 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.349817038 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:32.349883080 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.349921942 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.349939108 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:32.350147963 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:32.350188971 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:32.761607885 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:33.023220062 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.023459911 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.023485899 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.024537086 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.024677992 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.025897980 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.025965929 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.026087046 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.026098967 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.030085087 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.030297041 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.030329943 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.031974077 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.032040119 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.032938957 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.033021927 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.170418978 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.170516968 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.170564890 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.248255014 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.248343945 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.248729944 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.250197887 CEST49706443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.250227928 CEST4434970666.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.370361090 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.383840084 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.424500942 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.544578075 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.544749975 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.545039892 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.596290112 CEST49707443192.168.2.766.29.146.75
    Jun 23, 2024 00:35:33.596330881 CEST4434970766.29.146.75192.168.2.7
    Jun 23, 2024 00:35:33.671770096 CEST49674443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:33.671807051 CEST49675443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:33.764143944 CEST49672443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:33.818752050 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:33.818794966 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:33.818864107 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:33.819194078 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:33.819215059 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.455389977 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.455676079 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:34.455707073 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.456975937 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.457050085 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:34.507280111 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:34.507464886 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.561636925 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:34.561680079 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:34.732312918 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:35.342252016 CEST44349698104.98.116.138192.168.2.7
    Jun 23, 2024 00:35:35.342369080 CEST49698443192.168.2.7104.98.116.138
    Jun 23, 2024 00:35:35.732476950 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:35.732537031 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:35.736273050 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:35.738481998 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:35.738498926 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:35.874089956 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:36.550196886 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:36.550296068 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:36.581954956 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:36.581980944 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:36.582353115 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:36.624111891 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:36.755268097 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:36.800510883 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.096396923 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.096607924 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.096678972 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.096744061 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.096765041 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.096802950 CEST49711443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.096808910 CEST443497112.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.164182901 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.164247036 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.164333105 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.165338993 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.165364027 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.798778057 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.798907042 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.801701069 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.801722050 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.802169085 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:37.804088116 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:37.844506979 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:38.064173937 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:38.064291000 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:38.064347982 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:38.065171003 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:38.065186977 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:38.065407991 CEST49712443192.168.2.72.19.244.127
    Jun 23, 2024 00:35:38.065416098 CEST443497122.19.244.127192.168.2.7
    Jun 23, 2024 00:35:40.061546087 CEST49671443192.168.2.7204.79.197.203
    Jun 23, 2024 00:35:41.827162027 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:35:44.354039907 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:44.354123116 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:44.354202032 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:45.058192968 CEST49710443192.168.2.7142.250.185.132
    Jun 23, 2024 00:35:45.058223963 CEST44349710142.250.185.132192.168.2.7
    Jun 23, 2024 00:35:52.742573023 CEST5753253192.168.2.71.1.1.1
    Jun 23, 2024 00:35:52.747313023 CEST53575321.1.1.1192.168.2.7
    Jun 23, 2024 00:35:52.747386932 CEST5753253192.168.2.71.1.1.1
    Jun 23, 2024 00:35:52.748740911 CEST5753253192.168.2.71.1.1.1
    Jun 23, 2024 00:35:52.753468037 CEST53575321.1.1.1192.168.2.7
    Jun 23, 2024 00:35:53.220382929 CEST53575321.1.1.1192.168.2.7
    Jun 23, 2024 00:35:53.221467972 CEST5753253192.168.2.71.1.1.1
    Jun 23, 2024 00:35:53.226494074 CEST53575321.1.1.1192.168.2.7
    Jun 23, 2024 00:35:53.226602077 CEST5753253192.168.2.71.1.1.1
    Jun 23, 2024 00:35:53.734066010 CEST49677443192.168.2.720.50.201.200
    Jun 23, 2024 00:36:33.861231089 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:33.861284971 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:33.861356974 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:33.861792088 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:33.861809015 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:34.500003099 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:34.516158104 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:34.516179085 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:34.517384052 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:34.520757914 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:34.520981073 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:34.562273979 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:44.485165119 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:44.485239983 CEST44357537142.250.185.132192.168.2.7
    Jun 23, 2024 00:36:44.485297918 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:45.510927916 CEST57537443192.168.2.7142.250.185.132
    Jun 23, 2024 00:36:45.510960102 CEST44357537142.250.185.132192.168.2.7
    TimestampSource PortDest PortSource IPDest IP
    Jun 23, 2024 00:35:29.999289036 CEST53626841.1.1.1192.168.2.7
    Jun 23, 2024 00:35:30.582777023 CEST53534021.1.1.1192.168.2.7
    Jun 23, 2024 00:35:31.617805958 CEST53578861.1.1.1192.168.2.7
    Jun 23, 2024 00:35:32.338629007 CEST5860653192.168.2.71.1.1.1
    Jun 23, 2024 00:35:32.338751078 CEST6441653192.168.2.71.1.1.1
    Jun 23, 2024 00:35:32.347763062 CEST53644161.1.1.1192.168.2.7
    Jun 23, 2024 00:35:32.348577976 CEST53586061.1.1.1192.168.2.7
    Jun 23, 2024 00:35:33.804086924 CEST5259053192.168.2.71.1.1.1
    Jun 23, 2024 00:35:33.804349899 CEST5495153192.168.2.71.1.1.1
    Jun 23, 2024 00:35:33.810889006 CEST53525901.1.1.1192.168.2.7
    Jun 23, 2024 00:35:33.811770916 CEST53549511.1.1.1192.168.2.7
    Jun 23, 2024 00:35:35.906558037 CEST123123192.168.2.720.101.57.9
    Jun 23, 2024 00:35:36.077714920 CEST12312320.101.57.9192.168.2.7
    Jun 23, 2024 00:35:48.696064949 CEST53524731.1.1.1192.168.2.7
    Jun 23, 2024 00:35:52.741756916 CEST53626831.1.1.1192.168.2.7
    Jun 23, 2024 00:36:29.574891090 CEST53590641.1.1.1192.168.2.7
    Jun 23, 2024 00:36:30.154280901 CEST138138192.168.2.7192.168.2.255
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jun 23, 2024 00:35:32.338629007 CEST192.168.2.71.1.1.10xdbf7Standard query (0)tgbot.cyb3r.armyA (IP address)IN (0x0001)false
    Jun 23, 2024 00:35:32.338751078 CEST192.168.2.71.1.1.10xcadaStandard query (0)tgbot.cyb3r.army65IN (0x0001)false
    Jun 23, 2024 00:35:33.804086924 CEST192.168.2.71.1.1.10x770aStandard query (0)www.google.comA (IP address)IN (0x0001)false
    Jun 23, 2024 00:35:33.804349899 CEST192.168.2.71.1.1.10x312Standard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jun 23, 2024 00:35:32.348577976 CEST1.1.1.1192.168.2.70xdbf7No error (0)tgbot.cyb3r.army66.29.146.75A (IP address)IN (0x0001)false
    Jun 23, 2024 00:35:33.810889006 CEST1.1.1.1192.168.2.70x770aNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
    Jun 23, 2024 00:35:33.811770916 CEST1.1.1.1192.168.2.70x312No error (0)www.google.com65IN (0x0001)false
    Jun 23, 2024 00:35:45.390578985 CEST1.1.1.1192.168.2.70xf5f6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Jun 23, 2024 00:35:45.390578985 CEST1.1.1.1192.168.2.70xf5f6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
    • ipinfo.io
    • tgbot.cyb3r.army
    • https:
    • fs.microsoft.com
    Session IDSource IPSource PortDestination IPDestination Port
    0192.168.2.74969934.117.186.192443
    TimestampBytes transferredDirectionData
    2024-06-22 22:35:20 UTC59OUTGET / HTTP/1.1
    Host: ipinfo.io
    Connection: Keep-Alive
    2024-06-22 22:35:20 UTC513INHTTP/1.1 200 OK
    server: nginx/1.24.0
    date: Sat, 22 Jun 2024 22:35:20 GMT
    content-type: application/json; charset=utf-8
    Content-Length: 319
    access-control-allow-origin: *
    x-frame-options: SAMEORIGIN
    x-xss-protection: 1; mode=block
    x-content-type-options: nosniff
    referrer-policy: strict-origin-when-cross-origin
    x-envoy-upstream-service-time: 2
    via: 1.1 google
    strict-transport-security: max-age=2592000; includeSubDomains
    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
    Connection: close
    2024-06-22 22:35:20 UTC319INData Raw: 7b 0a 20 20 22 69 70 22 3a 20 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 0a 20 20 22 68 6f 73 74 6e 61 6d 65 22 3a 20 22 73 74 61 74 69 63 2d 63 70 65 2d 38 2d 34 36 2d 31 32 33 2d 33 33 2e 63 65 6e 74 75 72 79 6c 69 6e 6b 2e 63 6f 6d 22 2c 0a 20 20 22 63 69 74 79 22 3a 20 22 4e 65 77 20 59 6f 72 6b 20 43 69 74 79 22 2c 0a 20 20 22 72 65 67 69 6f 6e 22 3a 20 22 4e 65 77 20 59 6f 72 6b 22 2c 0a 20 20 22 63 6f 75 6e 74 72 79 22 3a 20 22 55 53 22 2c 0a 20 20 22 6c 6f 63 22 3a 20 22 34 30 2e 37 31 34 33 2c 2d 37 34 2e 30 30 36 30 22 2c 0a 20 20 22 6f 72 67 22 3a 20 22 41 53 33 33 35 36 20 4c 65 76 65 6c 20 33 20 50 61 72 65 6e 74 2c 20 4c 4c 43 22 2c 0a 20 20 22 70 6f 73 74 61 6c 22 3a 20 22 31 30 30 30 31 22 2c 0a 20 20 22 74 69 6d 65 7a 6f 6e 65 22 3a 20 22
    Data Ascii: { "ip": "8.46.123.33", "hostname": "static-cpe-8-46-123-33.centurylink.com", "city": "New York City", "region": "New York", "country": "US", "loc": "40.7143,-74.0060", "org": "AS3356 Level 3 Parent, LLC", "postal": "10001", "timezone": "


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    1192.168.2.74970666.29.146.754434532C:\Program Files\Google\Chrome\Application\chrome.exe
    TimestampBytes transferredDirectionData
    2024-06-22 22:35:33 UTC687OUTGET /700975049/Instagram.com.html HTTP/1.1
    Host: tgbot.cyb3r.army
    Connection: keep-alive
    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
    sec-ch-ua-mobile: ?0
    sec-ch-ua-platform: "Windows"
    Upgrade-Insecure-Requests: 1
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
    Sec-Fetch-Site: none
    Sec-Fetch-Mode: navigate
    Sec-Fetch-User: ?1
    Sec-Fetch-Dest: document
    Accept-Encoding: gzip, deflate, br
    Accept-Language: en-US,en;q=0.9
    2024-06-22 22:35:33 UTC301INHTTP/1.1 404 Not Found
    keep-alive: timeout=5, max=100
    cache-control: private, no-cache, no-store, must-revalidate, max-age=0
    pragma: no-cache
    content-type: text/html
    content-length: 1251
    date: Sat, 22 Jun 2024 22:35:33 GMT
    server: LiteSpeed
    x-turbo-charged-by: LiteSpeed
    connection: close
    2024-06-22 22:35:33 UTC1251INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79
    Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</sty


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    2192.168.2.74970766.29.146.754434532C:\Program Files\Google\Chrome\Application\chrome.exe
    TimestampBytes transferredDirectionData
    2024-06-22 22:35:33 UTC616OUTGET /favicon.ico HTTP/1.1
    Host: tgbot.cyb3r.army
    Connection: keep-alive
    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
    sec-ch-ua-mobile: ?0
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
    sec-ch-ua-platform: "Windows"
    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
    Sec-Fetch-Site: same-origin
    Sec-Fetch-Mode: no-cors
    Sec-Fetch-Dest: image
    Referer: https://tgbot.cyb3r.army/700975049/Instagram.com.html
    Accept-Encoding: gzip, deflate, br
    Accept-Language: en-US,en;q=0.9
    2024-06-22 22:35:33 UTC301INHTTP/1.1 404 Not Found
    keep-alive: timeout=5, max=100
    cache-control: private, no-cache, no-store, must-revalidate, max-age=0
    pragma: no-cache
    content-type: text/html
    content-length: 1251
    date: Sat, 22 Jun 2024 22:35:33 GMT
    server: LiteSpeed
    x-turbo-charged-by: LiteSpeed
    connection: close
    2024-06-22 22:35:33 UTC1251INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79
    Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</sty


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    3192.168.2.7497112.19.244.127443
    TimestampBytes transferredDirectionData
    2024-06-22 22:35:36 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-06-22 22:35:37 UTC467INHTTP/1.1 200 OK
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    Content-Type: application/octet-stream
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    Server: ECAcc (lpl/EF06)
    X-CID: 11
    X-Ms-ApiVersion: Distribute 1.2
    X-Ms-Region: prod-weu-z1
    Cache-Control: public, max-age=236072
    Date: Sat, 22 Jun 2024 22:35:36 GMT
    Connection: close
    X-CID: 2


    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    4192.168.2.7497122.19.244.127443
    TimestampBytes transferredDirectionData
    2024-06-22 22:35:37 UTC239OUTGET /fs/windows/config.json HTTP/1.1
    Connection: Keep-Alive
    Accept: */*
    Accept-Encoding: identity
    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
    Range: bytes=0-2147483646
    User-Agent: Microsoft BITS/7.8
    Host: fs.microsoft.com
    2024-06-22 22:35:38 UTC535INHTTP/1.1 200 OK
    Content-Type: application/octet-stream
    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
    ApiVersion: Distribute 1.1
    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
    X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
    Cache-Control: public, max-age=235995
    Date: Sat, 22 Jun 2024 22:35:37 GMT
    Content-Length: 55
    Connection: close
    X-CID: 2
    2024-06-22 22:35:38 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


    020406080s020406080100

    Click to jump to process

    020406080s0.0050100MB

    Click to jump to process

    Target ID:0
    Start time:18:35:25
    Start date:22/06/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff6c4390000
    File size:3'242'272 bytes
    MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:2
    Start time:18:35:28
    Start date:22/06/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2300,i,18393289357452397223,9561592466993645301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff6c4390000
    File size:3'242'272 bytes
    MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:11
    Start time:18:35:31
    Start date:22/06/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tgbot.cyb3r.army/700975049/Instagram.com.html"
    Imagebase:0x7ff6c4390000
    File size:3'242'272 bytes
    MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true
    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

    No disassembly