Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=

Overview

General Information

Sample URL:http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=
Analysis ID:1467003
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 3620 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=2484,i,15531785429463948178,16661828252351481044,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 2580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.244.127
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid= HTTP/1.1Host: onetag-sys.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: onetag-sys.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid= HTTP/1.1Host: onetag-sys.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: onetag-sys.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundcontent-type: text/htmlcache-control: public, max-age=1800, stale-while-revalidate=43200last-modified: Tue, 2 Jul 2024 16:33:18 GMTvary: accept-encodingetag: "17decccd4e741df9cb47c172277e8261"content-length: 923strict-transport-security: max-age=15552000alt-svc: h3=":443"; ma=900, h3-29=":443"; ma=900connection: close
Source: chromecache_42.2.drString found in binary or memory: http://www.onetag.com/
Source: chromecache_42.2.drString found in binary or memory: http://www.onetag.com/privacy/
Source: chromecache_42.2.drString found in binary or memory: https://onetag-cdn.com/media/1810ab0f-23f9-4cc9-bcf6-3436c65530ed.png
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.244.127:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=2484,i,15531785429463948178,16661828252351481044,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=2484,i,15531785429463948178,16661828252351481044,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.onetag.com/0%Avira URL Cloudsafe
https://onetag-sys.com/favicon.ico0%Avira URL Cloudsafe
http://www.onetag.com/privacy/0%Avira URL Cloudsafe
https://onetag-cdn.com/media/1810ab0f-23f9-4cc9-bcf6-3436c65530ed.png0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
onetag-sys.com
51.89.9.253
truefalse
    unknown
    www.google.com
    172.217.18.4
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=false
          unknown
          https://onetag-sys.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=false
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            http://www.onetag.com/chromecache_42.2.drfalse
            • Avira URL Cloud: safe
            unknown
            http://www.onetag.com/privacy/chromecache_42.2.drfalse
            • Avira URL Cloud: safe
            unknown
            https://onetag-cdn.com/media/1810ab0f-23f9-4cc9-bcf6-3436c65530ed.pngchromecache_42.2.drfalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            51.89.9.253
            onetag-sys.comFrance
            16276OVHFRfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            172.217.18.4
            www.google.comUnited States
            15169GOOGLEUSfalse
            51.75.86.98
            unknownFrance
            16276OVHFRfalse
            142.250.185.100
            unknownUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.6
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1467003
            Start date and time:2024-07-03 16:19:28 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 9s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/4@8/6
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.99, 142.250.185.174, 74.125.71.84, 34.104.35.123, 40.127.169.103, 93.184.221.240, 192.229.221.95, 20.3.187.198, 52.165.164.15, 52.165.165.26, 142.250.185.195, 40.68.123.157
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):923
            Entropy (8bit):4.9586008287250545
            Encrypted:false
            SSDEEP:12:hY8KAVIhXTC/O2A0ZdTdXy1qZSKqJf4xJsu6VeQQANFVIN7cnzhX4/RteOah1FQL:hY8KK4TyRdi1cmJfKhQRfVvnZ4//pee
            MD5:17DECCCD4E741DF9CB47C172277E8261
            SHA1:EA1257C7FE8718D2DDF17C0083667E5F6C13E703
            SHA-256:8636B148F7F30B577172D0BEA8065E399CAD8C51E01AC50E275272D184C2B74B
            SHA-512:BCF4D7D0C96E123DD4D00468FDCEEF141DDEEE1A9DCD2C46EBFF00BCFD7E3BA586056E43CEC1DD60819BB25D954E5CDF9AE8BD7774D33FBCA48E4218D16621F9
            Malicious:false
            Reputation:low
            URL:https://onetag-sys.com/favicon.ico
            Preview:<!DOCTYPE html>.<html>.<head>. <meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no">. <title>OneTag Advertising System</title>. <style>. body {. margin: 0px;. padding: 0px;. font-family: Arial, Helvetica, sans-serif;. text-align: center;. }. h1 {. color: white;. font-size: 36px;. margin: 60px;. }. </style>.</head>.<body>.<div style="background:#04172c; height:400px; width:100%; padding-top: 80px;"><img src="https://onetag-cdn.com/media/1810ab0f-23f9-4cc9-bcf6-3436c65530ed.png" style="height:80px;" alt="OneTag Company Logo">. <h1>This is the OneTag Advertising System</h1>.</div>.<br><br>.<a href="http://www.onetag.com/">Click here for the OneTag homepage</a>.<br><br>.<a href="http://www.onetag.com/privacy/">Click here for our privacy policy</a>.</body>.</html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):2162
            Entropy (8bit):4.655663585165413
            Encrypted:false
            SSDEEP:48:qkCDhll5xuPgTXCeybFuryI7hAu3obFuA8igBQWbz:glCUybFuuI9j3obFuBi/Wbz
            MD5:AA489CAF1E3F2BF852E2C60E6408B067
            SHA1:9960B9D960FD5CA70683AA20C78A4F962C549168
            SHA-256:37A31642AF0A7FE695ED0FD68A06A55AF44E854D083DC7F5D0E70535F0189AE0
            SHA-512:EBFFC578839A404557FAC7B51511D3D5FB1BA7711DABA34480FB89875740FFBB90FBCC98986F2F1F5399B42E9707F851301D740477D877FE471F69A061F49C25
            Malicious:false
            Reputation:low
            URL:https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=
            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <title>Sync Pixels</title>.</head>.<body>..<script>.. var syncPixels = "";. var syncIframes = "";.. var GDPR_APPLIES = "gdpr=";. var GDPR = "gdpr_consent=";. var US_PRIVACY = "us_privacy=";... var params = location.search.substring(1);. var consentString = "";. var usPrivacy = "";. var gdprAppliesValue = "1";.. try {.. var index = params.indexOf(GDPR);. if (index >= 0) {. consentString = params.substring(index + GDPR.length).split("&")[0];. }.. index = params.indexOf(GDPR_APPLIES);. if (index >= 0) {. var tmp = params.substring(index + GDPR_APPLIES.length).split("&")[0];. gdprAppliesValue = (tmp == null || tmp === "" || tmp === "1") ? "1" : "0";. }.. index = params.indexOf(US_PRIVACY);. if (index >= 0) {. usPrivacy = params.substring(index + US_PRIVACY.length).split("&")[0];. }..
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Jul 3, 2024 16:20:13.147952080 CEST49674443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:13.147952080 CEST49673443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:13.477395058 CEST49672443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:21.873497963 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:21.873832941 CEST4970580192.168.2.651.89.9.253
            Jul 3, 2024 16:20:21.879086018 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:21.879096985 CEST804970551.89.9.253192.168.2.6
            Jul 3, 2024 16:20:21.879173040 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:21.879384041 CEST4970580192.168.2.651.89.9.253
            Jul 3, 2024 16:20:21.879389048 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:21.884293079 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:22.079587936 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.079641104 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.079716921 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.079941034 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.079953909 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.510267973 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:22.521683931 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:22.521744013 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:22.521828890 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:22.522136927 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:22.522155046 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:22.554501057 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:22.744441986 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.744744062 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.744796038 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.745810986 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.745903015 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.747046947 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.747138977 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.757076025 CEST49674443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:22.757076025 CEST49673443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:22.788721085 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:22.788758039 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:22.830406904 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:23.083226919 CEST49672443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:23.309500933 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.350337982 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.361669064 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.361681938 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.362981081 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.363065958 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.372827053 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.372997999 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.373181105 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.373189926 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.427496910 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.570969105 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.571022034 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.571062088 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.571079969 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.571094990 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.571126938 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.647284031 CEST49709443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.647315025 CEST4434970951.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.805406094 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.805469036 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:23.805529118 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.806334019 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:23.806351900 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.497085094 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.497584105 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.497616053 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.497997999 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.501632929 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.501746893 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.505752087 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.552503109 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.552586079 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.622478962 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:24.622519016 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:24.622663021 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:24.624888897 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:24.624905109 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:24.778489113 CEST44349698173.222.162.64192.168.2.6
            Jul 3, 2024 16:20:24.778858900 CEST49698443192.168.2.6173.222.162.64
            Jul 3, 2024 16:20:24.790046930 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.790148020 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:24.790949106 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.793653011 CEST49710443192.168.2.651.75.86.98
            Jul 3, 2024 16:20:24.793685913 CEST4434971051.75.86.98192.168.2.6
            Jul 3, 2024 16:20:25.296207905 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.296293020 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.303637028 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.303653002 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.303997993 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.349606991 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.405577898 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.452507973 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.587115049 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.587202072 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.587249994 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.587347031 CEST49711443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.587367058 CEST443497112.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.703699112 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.703757048 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:25.703815937 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.704283953 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:25.704303980 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.330238104 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.330315113 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:26.387295961 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:26.387327909 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.387669086 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.389838934 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:26.436501980 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.603441954 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.603527069 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:26.603801966 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:26.678361893 CEST49712443192.168.2.62.19.244.127
            Jul 3, 2024 16:20:26.678400993 CEST443497122.19.244.127192.168.2.6
            Jul 3, 2024 16:20:32.641946077 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:32.642014027 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:32.647253036 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:34.369330883 CEST49706443192.168.2.6172.217.18.4
            Jul 3, 2024 16:20:34.369354010 CEST44349706172.217.18.4192.168.2.6
            Jul 3, 2024 16:20:37.462765932 CEST804970551.89.9.253192.168.2.6
            Jul 3, 2024 16:20:37.462821960 CEST4970580192.168.2.651.89.9.253
            Jul 3, 2024 16:20:38.256691933 CEST4970580192.168.2.651.89.9.253
            Jul 3, 2024 16:20:38.261653900 CEST804970551.89.9.253192.168.2.6
            Jul 3, 2024 16:20:52.508725882 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:52.508795977 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:54.367286921 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:54.677958012 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:20:55.141175032 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:55.141190052 CEST804970451.89.9.253192.168.2.6
            Jul 3, 2024 16:20:55.147104979 CEST4970480192.168.2.651.89.9.253
            Jul 3, 2024 16:21:22.124371052 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:22.124474049 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.124845982 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:22.124845982 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:22.124943972 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.765842915 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.766695976 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:22.766752958 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.767095089 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.768603086 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:22.768677950 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:22.817707062 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:32.679373026 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:32.679446936 CEST44349721142.250.185.100192.168.2.6
            Jul 3, 2024 16:21:32.679590940 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:32.685282946 CEST49721443192.168.2.6142.250.185.100
            Jul 3, 2024 16:21:32.685306072 CEST44349721142.250.185.100192.168.2.6
            TimestampSource PortDest PortSource IPDest IP
            Jul 3, 2024 16:20:20.212685108 CEST53518901.1.1.1192.168.2.6
            Jul 3, 2024 16:20:20.223223925 CEST53580661.1.1.1192.168.2.6
            Jul 3, 2024 16:20:21.361929893 CEST53522951.1.1.1192.168.2.6
            Jul 3, 2024 16:20:21.861516953 CEST6229553192.168.2.61.1.1.1
            Jul 3, 2024 16:20:21.861661911 CEST5827853192.168.2.61.1.1.1
            Jul 3, 2024 16:20:21.872829914 CEST53622951.1.1.1192.168.2.6
            Jul 3, 2024 16:20:21.872847080 CEST53582781.1.1.1192.168.2.6
            Jul 3, 2024 16:20:22.054240942 CEST5832553192.168.2.61.1.1.1
            Jul 3, 2024 16:20:22.054389000 CEST5229353192.168.2.61.1.1.1
            Jul 3, 2024 16:20:22.078511953 CEST53583251.1.1.1192.168.2.6
            Jul 3, 2024 16:20:22.078531027 CEST53522931.1.1.1192.168.2.6
            Jul 3, 2024 16:20:22.513622999 CEST5386153192.168.2.61.1.1.1
            Jul 3, 2024 16:20:22.513755083 CEST5580853192.168.2.61.1.1.1
            Jul 3, 2024 16:20:22.520917892 CEST53538611.1.1.1192.168.2.6
            Jul 3, 2024 16:20:22.521004915 CEST53558081.1.1.1192.168.2.6
            Jul 3, 2024 16:20:38.264038086 CEST53531271.1.1.1192.168.2.6
            Jul 3, 2024 16:20:57.151889086 CEST53651341.1.1.1192.168.2.6
            Jul 3, 2024 16:21:19.630462885 CEST53653771.1.1.1192.168.2.6
            Jul 3, 2024 16:21:19.842176914 CEST53537021.1.1.1192.168.2.6
            Jul 3, 2024 16:21:22.115832090 CEST6508153192.168.2.61.1.1.1
            Jul 3, 2024 16:21:22.115832090 CEST5981553192.168.2.61.1.1.1
            Jul 3, 2024 16:21:22.122823000 CEST53650811.1.1.1192.168.2.6
            Jul 3, 2024 16:21:22.123585939 CEST53598151.1.1.1192.168.2.6
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jul 3, 2024 16:20:21.861516953 CEST192.168.2.61.1.1.10x55feStandard query (0)onetag-sys.comA (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.861661911 CEST192.168.2.61.1.1.10x9be2Standard query (0)onetag-sys.com65IN (0x0001)false
            Jul 3, 2024 16:20:22.054240942 CEST192.168.2.61.1.1.10x624dStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.054389000 CEST192.168.2.61.1.1.10xd047Standard query (0)www.google.com65IN (0x0001)false
            Jul 3, 2024 16:20:22.513622999 CEST192.168.2.61.1.1.10x4d71Standard query (0)onetag-sys.comA (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.513755083 CEST192.168.2.61.1.1.10x4c5aStandard query (0)onetag-sys.com65IN (0x0001)false
            Jul 3, 2024 16:21:22.115832090 CEST192.168.2.61.1.1.10x151Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Jul 3, 2024 16:21:22.115832090 CEST192.168.2.61.1.1.10xa25fStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.89.9.253A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.89.9.254A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.38.120.206A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.75.86.98A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.89.9.251A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:21.872829914 CEST1.1.1.1192.168.2.60x55feNo error (0)onetag-sys.com51.89.9.252A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.078511953 CEST1.1.1.1192.168.2.60x624dNo error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.078531027 CEST1.1.1.1192.168.2.60xd047No error (0)www.google.com65IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.75.86.98A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.89.9.251A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.38.120.206A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.89.9.254A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.89.9.252A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:22.520917892 CEST1.1.1.1192.168.2.60x4d71No error (0)onetag-sys.com51.89.9.253A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:35.215235949 CEST1.1.1.1192.168.2.60x7351No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 3, 2024 16:20:35.215235949 CEST1.1.1.1192.168.2.60x7351No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Jul 3, 2024 16:20:48.281080961 CEST1.1.1.1192.168.2.60x5a9dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 3, 2024 16:20:48.281080961 CEST1.1.1.1192.168.2.60x5a9dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Jul 3, 2024 16:21:12.206609011 CEST1.1.1.1192.168.2.60x4633No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Jul 3, 2024 16:21:12.206609011 CEST1.1.1.1192.168.2.60x4633No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Jul 3, 2024 16:21:22.122823000 CEST1.1.1.1192.168.2.60x151No error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
            Jul 3, 2024 16:21:22.123585939 CEST1.1.1.1192.168.2.60xa25fNo error (0)www.google.com65IN (0x0001)false
            • onetag-sys.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.64970451.89.9.253803620C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Jul 3, 2024 16:20:21.879389048 CEST527OUTGET /usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid= HTTP/1.1
            Host: onetag-sys.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Jul 3, 2024 16:20:22.510267973 CEST187INHTTP/1.1 308 Permanent Redirect
            content-length: 0
            location: https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.64970951.75.86.984433620C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-07-03 14:20:23 UTC755OUTGET /usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid= HTTP/1.1
            Host: onetag-sys.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-07-03 14:20:23 UTC219INHTTP/1.1 200 OK
            content-type: text/html
            cache-control: no-transform, no-cache
            content-length: 2162
            strict-transport-security: max-age=15552000
            alt-svc: h3=":443"; ma=900, h3-29=":443"; ma=900
            connection: close
            2024-07-03 14:20:23 UTC1343INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 79 6e 63 20 50 69 78 65 6c 73 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 0a 3c 73 63 72 69 70 74 3e 0a 0a 20 20 20 20 76 61 72 20 73 79 6e 63 50 69 78 65 6c 73 20 3d 20 22 22 3b 0a 20 20 20 20 76 61 72 20 73 79 6e 63 49 66 72 61 6d 65 73 20 3d 20 22 22 3b 0a 0a 20 20 20 20 76 61 72 20 47 44 50 52 5f 41 50 50 4c 49 45 53 20 3d 20 22 67 64 70 72 3d 22 3b 0a 20 20 20 20 76 61 72 20 47 44 50 52 20 3d 20 22 67 64 70 72 5f 63 6f 6e 73 65 6e 74 3d 22 3b 0a 20 20 20 20 76 61 72 20 55 53 5f 50 52 49 56
            Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <title>Sync Pixels</title></head><body><script> var syncPixels = ""; var syncIframes = ""; var GDPR_APPLIES = "gdpr="; var GDPR = "gdpr_consent="; var US_PRIV
            2024-07-03 14:20:23 UTC819INData Raw: 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 75 72 6c 20 3d 20 75 72 6c 2e 72 65 70 6c 61 63 65 28 22 24 7b 55 53 5f 50 52 49 56 41 43 59 7d 22 2c 20 75 73 50 72 69 76 61 63 79 29 3b 0a 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6e 65 77 20 49 6d 61 67 65 28 29 2e 73 72 63 20 3d 20 75 72 6c 3b 0a 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 29 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 7d 0a 0a 20 20 20 20 69 66 20 28 73 79 6e 63 49 66 72 61 6d 65 73 29 20 7b 0a 0a 20 20 20 20 20 20 20 20 76 61 72 20 73 79 6e 63 46 20 3d 20 73 79 6e 63 49 66 72 61 6d 65 73 2e 73 70 6c 69 74 28 22 2c 22 29 3b 0a 20 20 20 20 20 20 20 20 69 66 20 28 73 79 6e 63 46 20 21 3d 20 6e 75 6c 6c 29 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 73 79 6e 63 46 2e
            Data Ascii: ); url = url.replace("${US_PRIVACY}", usPrivacy); new Image().src = url; }); } } if (syncIframes) { var syncF = syncIframes.split(","); if (syncF != null) { syncF.


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.64971051.75.86.984433620C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-07-03 14:20:24 UTC682OUTGET /favicon.ico HTTP/1.1
            Host: onetag-sys.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid=
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-07-03 14:20:24 UTC363INHTTP/1.1 404 Not Found
            content-type: text/html
            cache-control: public, max-age=1800, stale-while-revalidate=43200
            last-modified: Tue, 2 Jul 2024 16:33:18 GMT
            vary: accept-encoding
            etag: "17decccd4e741df9cb47c172277e8261"
            content-length: 923
            strict-transport-security: max-age=15552000
            alt-svc: h3=":443"; ma=900, h3-29=":443"; ma=900
            connection: close
            2024-07-03 14:20:24 UTC923INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 4f 6e 65 54 61 67 20 41 64 76 65 72 74 69 73 69 6e 67 20 53 79 73 74 65 6d 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20
            Data Ascii: <!DOCTYPE html><html><head> <meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no"> <title>OneTag Advertising System</title> <style> body { margin: 0px; padding: 0px;


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.6497112.19.244.127443
            TimestampBytes transferredDirectionData
            2024-07-03 14:20:25 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-07-03 14:20:25 UTC466INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=92979
            Date: Wed, 03 Jul 2024 14:20:25 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.6497122.19.244.127443
            TimestampBytes transferredDirectionData
            2024-07-03 14:20:26 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-07-03 14:20:26 UTC534INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=92966
            Date: Wed, 03 Jul 2024 14:20:26 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-07-03 14:20:26 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:10:20:13
            Start date:03/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:10:20:18
            Start date:03/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=2484,i,15531785429463948178,16661828252351481044,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:10:20:20
            Start date:03/07/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://onetag-sys.com/usync/?gdpr=0&gdpr_consent=0&us_privacy=0&redir=https://ps.0cf.io/?onetag=$%7BUSER_TOKEN%7D84&uid="
            Imagebase:0x7ff684c40000
            File size:3'242'272 bytes
            MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly