Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://t8kwe.top

Overview

General Information

Sample URL:https://t8kwe.top
Analysis ID:1467860
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 4228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3156 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2476,i,13138223959795890766,7790117090603310861,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6616 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t8kwe.top" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://t8kwe.top/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:58618 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:49398 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.72
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: t8kwe.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: t8kwe.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://t8kwe.top/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: t8kwe.topConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: t8kwe.top
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /report/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 379Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 04 Jul 2024 21:27:39 GMTContent-Length: 20Connection: closeCDN-PullZone: 283898CDN-Uid: 10270df6-3a78-4ee3-9e7e-62f57a8521e8CDN-RequestCountryCode: USCache-Control: no-cacheCDN-ProxyVer: 1.04CDN-RequestPullSuccess: TrueCDN-RequestPullCode: 404CDN-CachedAt: 07/04/2024 21:27:39CDN-EdgeStorageId: 845CDN-Status: 404CDN-RequestId: 4c2d96a0e86c2cc7a3077c238c2b1261CDN-Cache: MISSCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 89e233565d704405-EWRalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49402
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49402 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/5@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2476,i,13138223959795890766,7790117090603310861,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t8kwe.top"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2476,i,13138223959795890766,7790117090603310861,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://t8kwe.top0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://t8kwe.top/favicon.ico0%Avira URL Cloudsafe
https://a.nel.cloudflare.com/report/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      unknown
      t8kwe.top
      188.114.96.3
      truefalse
        unknown
        www.google.com
        142.250.186.164
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://a.nel.cloudflare.com/report/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3Dfalse
            • Avira URL Cloud: safe
            unknown
            https://t8kwe.top/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://t8kwe.top/false
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              188.114.96.3
              t8kwe.topEuropean Union
              13335CLOUDFLARENETUSfalse
              142.250.186.164
              www.google.comUnited States
              15169GOOGLEUSfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1467860
              Start date and time:2024-07-04 23:26:47 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 55s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://t8kwe.top
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@21/5@8/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.181.227, 142.250.184.238, 74.125.206.84, 34.104.35.123, 13.85.23.86, 199.232.214.172, 192.229.221.95, 20.242.39.171, 52.165.164.15, 142.250.184.227
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, d.4.1.9.1.6.7.1.0.0.0.0.0.0.0.0.1.0.0.9.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://t8kwe.top
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):20
              Entropy (8bit):3.3841837197791884
              Encrypted:false
              SSDEEP:3:OHKW3Ae:OqOAe
              MD5:DC5BCBF7F9372CCC9AEDB581FE88EDFE
              SHA1:79097FE77C29B4CA590114BDD0331431A1EFC470
              SHA-256:D872E8E4176213EA84EBC76D8FB621C31B4CA116FD0A51258813E804FE110CA4
              SHA-512:1EA2F632E9647FBDE1DA45DB3F295620E3B8228E48C237134DE7ADCE74121F9F12B0A647D27A574B4172A93A4E86B9C1B5868C24ABA5F48253E6283EAB35F6F0
              Malicious:false
              Reputation:low
              URL:https://t8kwe.top/
              Preview:Nothing to see here.
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):34
              Entropy (8bit):4.594672032363179
              Encrypted:false
              SSDEEP:3:dnHnyD:k
              MD5:1AD7058E90D7DB22A25C7579186C04AD
              SHA1:6CF6D451E28E0A5FF7A8C7A4ACE24D8A0977F0C1
              SHA-256:E1E10747C2374F621AA59FEFEDE6EF99DC6ACDB41B267AB4AF408D5529F89EA8
              SHA-512:17E04CD2B654D710FAAD47F8A7664BB6A136AC9E52C83D3F3C590E9F6C18EAF8C52988E5741AECAAC7D95DAF130AB6C70671E7EA3B107F0AC3A2BB3EDFC5C9E0
              Malicious:false
              Reputation:low
              URL:https://t8kwe.top/favicon.ico
              Preview:data:image/png;base64,iVBORw0KGgo=
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):34
              Entropy (8bit):4.594672032363179
              Encrypted:false
              SSDEEP:3:dnHnyD:k
              MD5:1AD7058E90D7DB22A25C7579186C04AD
              SHA1:6CF6D451E28E0A5FF7A8C7A4ACE24D8A0977F0C1
              SHA-256:E1E10747C2374F621AA59FEFEDE6EF99DC6ACDB41B267AB4AF408D5529F89EA8
              SHA-512:17E04CD2B654D710FAAD47F8A7664BB6A136AC9E52C83D3F3C590E9F6C18EAF8C52988E5741AECAAC7D95DAF130AB6C70671E7EA3B107F0AC3A2BB3EDFC5C9E0
              Malicious:false
              Reputation:low
              Preview:data:image/png;base64,iVBORw0KGgo=
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Jul 4, 2024 23:27:29.220176935 CEST49678443192.168.2.4104.46.162.224
              Jul 4, 2024 23:27:31.001405954 CEST49675443192.168.2.4173.222.162.32
              Jul 4, 2024 23:27:38.684652090 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.684720993 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:38.684808969 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.685091972 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.685115099 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:38.687004089 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.687036991 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:38.687112093 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.688323021 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:38.688350916 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.167383909 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.167619944 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.167659998 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.168529034 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.168602943 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.169608116 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.169673920 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.169754982 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.169770956 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.185198069 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.185434103 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.185467958 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.189008951 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.189132929 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.189604998 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.189668894 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.213126898 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.243995905 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.244016886 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.290994883 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.971272945 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.971345901 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.971415043 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.973681927 CEST49736443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:39.973721981 CEST44349736188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:39.992326975 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:39.992366076 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:39.992438078 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:39.996062994 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:39.996079922 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.061238050 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.104525089 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.179725885 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.179951906 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.180037975 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.181610107 CEST49735443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.181639910 CEST44349735188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.205440998 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.205466986 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.205529928 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.205940962 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.205956936 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.469386101 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.469685078 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.469696999 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.470556974 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.470613003 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.472471952 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.472537994 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.472969055 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.472976923 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.504149914 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:40.504223108 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:40.504291058 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:40.504530907 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:40.504576921 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:40.515424013 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.603183031 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.603379965 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.603425980 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.612829924 CEST49675443192.168.2.4173.222.162.32
              Jul 4, 2024 23:27:40.614044905 CEST49739443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.614063978 CEST4434973935.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.617249012 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.617269993 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.617319107 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.617597103 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:40.617614031 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:40.683792114 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.687290907 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.687310934 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.690690994 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.690742016 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.771284103 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.771450043 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.771507025 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.826584101 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.826605082 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.873451948 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.879236937 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.879481077 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:40.879530907 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.912288904 CEST49740443192.168.2.4188.114.96.3
              Jul 4, 2024 23:27:40.912302971 CEST44349740188.114.96.3192.168.2.4
              Jul 4, 2024 23:27:41.099035978 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.134582996 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:41.134603024 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.134902000 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.140188932 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:41.140247107 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.142441988 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:41.188505888 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.194605112 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:41.194858074 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:41.194900990 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:41.196568012 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:41.196645975 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:41.272636890 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.272927046 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.273053885 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:41.273315907 CEST49742443192.168.2.435.190.80.1
              Jul 4, 2024 23:27:41.273346901 CEST4434974235.190.80.1192.168.2.4
              Jul 4, 2024 23:27:41.280782938 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:41.280805111 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:41.280929089 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:41.282331944 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:41.282344103 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:41.624012947 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:41.624294996 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:41.670523882 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:41.670559883 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:41.717536926 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:41.956276894 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:41.956428051 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.083583117 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.083595991 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.084602118 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.139123917 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.206034899 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.252490997 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.392330885 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.392385960 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.392436981 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.392906904 CEST49745443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.392916918 CEST443497452.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.623935938 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.623951912 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:42.624013901 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.624315977 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:42.624325037 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.273889065 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.274080992 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.277139902 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.277147055 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.278042078 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.281240940 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.328502893 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.545500994 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.545675039 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:43.549272060 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.549272060 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.550395966 CEST49746443192.168.2.42.19.104.72
              Jul 4, 2024 23:27:43.550405979 CEST443497462.19.104.72192.168.2.4
              Jul 4, 2024 23:27:51.109338045 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:51.109424114 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:51.109741926 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:53.096065998 CEST49741443192.168.2.4142.250.186.164
              Jul 4, 2024 23:27:53.096138954 CEST44349741142.250.186.164192.168.2.4
              Jul 4, 2024 23:27:58.898530006 CEST5861853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:58.903403044 CEST53586181.1.1.1192.168.2.4
              Jul 4, 2024 23:27:58.903496027 CEST5861853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:58.903515100 CEST5861853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:58.908385038 CEST53586181.1.1.1192.168.2.4
              Jul 4, 2024 23:27:59.388000011 CEST53586181.1.1.1192.168.2.4
              Jul 4, 2024 23:27:59.388834000 CEST5861853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:59.394220114 CEST53586181.1.1.1192.168.2.4
              Jul 4, 2024 23:27:59.394264936 CEST5861853192.168.2.41.1.1.1
              Jul 4, 2024 23:28:21.632688046 CEST4939853192.168.2.4162.159.36.2
              Jul 4, 2024 23:28:21.637475014 CEST5349398162.159.36.2192.168.2.4
              Jul 4, 2024 23:28:21.637579918 CEST4939853192.168.2.4162.159.36.2
              Jul 4, 2024 23:28:21.637722969 CEST4939853192.168.2.4162.159.36.2
              Jul 4, 2024 23:28:21.642488956 CEST5349398162.159.36.2192.168.2.4
              Jul 4, 2024 23:28:22.134424925 CEST5349398162.159.36.2192.168.2.4
              Jul 4, 2024 23:28:22.137253046 CEST4939853192.168.2.4162.159.36.2
              Jul 4, 2024 23:28:22.142365932 CEST5349398162.159.36.2192.168.2.4
              Jul 4, 2024 23:28:22.142488003 CEST4939853192.168.2.4162.159.36.2
              Jul 4, 2024 23:28:40.551646948 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:40.551688910 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:40.552220106 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:40.552406073 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:40.552422047 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:41.221852064 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:41.222148895 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:41.222166061 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:41.223268032 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:41.223928928 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:41.224100113 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:41.266572952 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:48.172343016 CEST4972380192.168.2.4199.232.210.172
              Jul 4, 2024 23:28:48.172472000 CEST4972480192.168.2.4199.232.210.172
              Jul 4, 2024 23:28:48.178884029 CEST8049723199.232.210.172192.168.2.4
              Jul 4, 2024 23:28:48.178899050 CEST8049724199.232.210.172192.168.2.4
              Jul 4, 2024 23:28:48.178939104 CEST4972380192.168.2.4199.232.210.172
              Jul 4, 2024 23:28:48.178956985 CEST4972480192.168.2.4199.232.210.172
              Jul 4, 2024 23:28:51.132612944 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:51.132810116 CEST44349402142.250.186.164192.168.2.4
              Jul 4, 2024 23:28:51.132992029 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:53.149180889 CEST49402443192.168.2.4142.250.186.164
              Jul 4, 2024 23:28:53.149211884 CEST44349402142.250.186.164192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Jul 4, 2024 23:27:36.722573042 CEST53498381.1.1.1192.168.2.4
              Jul 4, 2024 23:27:36.797141075 CEST53637461.1.1.1192.168.2.4
              Jul 4, 2024 23:27:37.785180092 CEST53565381.1.1.1192.168.2.4
              Jul 4, 2024 23:27:38.666412115 CEST6154053192.168.2.41.1.1.1
              Jul 4, 2024 23:27:38.666960001 CEST5799653192.168.2.41.1.1.1
              Jul 4, 2024 23:27:38.677026033 CEST53615401.1.1.1192.168.2.4
              Jul 4, 2024 23:27:38.678282022 CEST53579961.1.1.1192.168.2.4
              Jul 4, 2024 23:27:39.973009109 CEST6412853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:39.973160982 CEST6168653192.168.2.41.1.1.1
              Jul 4, 2024 23:27:39.979782104 CEST53641281.1.1.1192.168.2.4
              Jul 4, 2024 23:27:39.980119944 CEST53616861.1.1.1192.168.2.4
              Jul 4, 2024 23:27:40.187021017 CEST5448353192.168.2.41.1.1.1
              Jul 4, 2024 23:27:40.187210083 CEST5089753192.168.2.41.1.1.1
              Jul 4, 2024 23:27:40.198021889 CEST53544831.1.1.1192.168.2.4
              Jul 4, 2024 23:27:40.488046885 CEST6283853192.168.2.41.1.1.1
              Jul 4, 2024 23:27:40.488373041 CEST5647553192.168.2.41.1.1.1
              Jul 4, 2024 23:27:40.496489048 CEST53564751.1.1.1192.168.2.4
              Jul 4, 2024 23:27:40.503326893 CEST53628381.1.1.1192.168.2.4
              Jul 4, 2024 23:27:40.717284918 CEST53508971.1.1.1192.168.2.4
              Jul 4, 2024 23:27:54.846983910 CEST53618401.1.1.1192.168.2.4
              Jul 4, 2024 23:27:58.898176908 CEST53616261.1.1.1192.168.2.4
              Jul 4, 2024 23:27:59.754158020 CEST138138192.168.2.4192.168.2.255
              Jul 4, 2024 23:28:21.632153988 CEST5359474162.159.36.2192.168.2.4
              Jul 4, 2024 23:28:23.014498949 CEST53630871.1.1.1192.168.2.4
              Jul 4, 2024 23:28:36.302836895 CEST53551131.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Jul 4, 2024 23:27:40.717355967 CEST192.168.2.41.1.1.1c228(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jul 4, 2024 23:27:38.666412115 CEST192.168.2.41.1.1.10x73adStandard query (0)t8kwe.topA (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:38.666960001 CEST192.168.2.41.1.1.10x9d92Standard query (0)t8kwe.top65IN (0x0001)false
              Jul 4, 2024 23:27:39.973009109 CEST192.168.2.41.1.1.10xddfaStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:39.973160982 CEST192.168.2.41.1.1.10x3d91Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              Jul 4, 2024 23:27:40.187021017 CEST192.168.2.41.1.1.10x439Standard query (0)t8kwe.topA (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.187210083 CEST192.168.2.41.1.1.10xf573Standard query (0)t8kwe.top65IN (0x0001)false
              Jul 4, 2024 23:27:40.488046885 CEST192.168.2.41.1.1.10xd844Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.488373041 CEST192.168.2.41.1.1.10x53f3Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jul 4, 2024 23:27:38.677026033 CEST1.1.1.1192.168.2.40x73adNo error (0)t8kwe.top188.114.96.3A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:38.677026033 CEST1.1.1.1192.168.2.40x73adNo error (0)t8kwe.top188.114.97.3A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:38.678282022 CEST1.1.1.1192.168.2.40x9d92No error (0)t8kwe.top65IN (0x0001)false
              Jul 4, 2024 23:27:39.979782104 CEST1.1.1.1192.168.2.40xddfaNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.198021889 CEST1.1.1.1192.168.2.40x439No error (0)t8kwe.top188.114.96.3A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.198021889 CEST1.1.1.1192.168.2.40x439No error (0)t8kwe.top188.114.97.3A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.496489048 CEST1.1.1.1192.168.2.40x53f3No error (0)www.google.com65IN (0x0001)false
              Jul 4, 2024 23:27:40.503326893 CEST1.1.1.1192.168.2.40xd844No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:40.717284918 CEST1.1.1.1192.168.2.40xf573No error (0)t8kwe.top65IN (0x0001)false
              Jul 4, 2024 23:27:54.060101032 CEST1.1.1.1192.168.2.40xbcf1No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:54.060101032 CEST1.1.1.1192.168.2.40xbcf1No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Jul 4, 2024 23:27:54.564650059 CEST1.1.1.1192.168.2.40xc5a7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jul 4, 2024 23:27:54.564650059 CEST1.1.1.1192.168.2.40xc5a7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • t8kwe.top
              • https:
              • a.nel.cloudflare.com
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449736188.114.96.34433156C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:39 UTC652OUTGET / HTTP/1.1
              Host: t8kwe.top
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-04 21:27:39 UTC867INHTTP/1.1 404 Not Found
              Date: Thu, 04 Jul 2024 21:27:39 GMT
              Content-Length: 20
              Connection: close
              CDN-PullZone: 283898
              CDN-Uid: 10270df6-3a78-4ee3-9e7e-62f57a8521e8
              CDN-RequestCountryCode: US
              Cache-Control: no-cache
              CDN-ProxyVer: 1.04
              CDN-RequestPullSuccess: True
              CDN-RequestPullCode: 404
              CDN-CachedAt: 07/04/2024 21:27:39
              CDN-EdgeStorageId: 845
              CDN-Status: 404
              CDN-RequestId: 4c2d96a0e86c2cc7a3077c238c2b1261
              CDN-Cache: MISS
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 89e233565d704405-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-04 21:27:39 UTC20INData Raw: 4e 6f 74 68 69 6e 67 20 74 6f 20 73 65 65 20 68 65 72 65 2e
              Data Ascii: Nothing to see here.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449735188.114.96.34433156C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:40 UTC574OUTGET /favicon.ico HTTP/1.1
              Host: t8kwe.top
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://t8kwe.top/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-04 21:27:40 UTC990INHTTP/1.1 200 OK
              Date: Thu, 04 Jul 2024 21:27:40 GMT
              Content-Type: text/html
              Transfer-Encoding: chunked
              Connection: close
              CDN-PullZone: 283898
              CDN-Uid: 10270df6-3a78-4ee3-9e7e-62f57a8521e8
              CDN-RequestCountryCode: US
              Cache-Control: public, max-age=31919000
              CDN-ProxyVer: 1.04
              CDN-RequestPullSuccess: True
              CDN-RequestPullCode: 200
              CDN-CachedAt: 05/25/2024 01:29:19
              CDN-EdgeStorageId: 894
              CDN-Status: 200
              CDN-RequestId: 2e8cb456321df90cc2c629ddce5e281c
              CDN-Cache: HIT
              CF-Cache-Status: HIT
              Age: 38480
              Last-Modified: Thu, 04 Jul 2024 10:46:20 GMT
              Accept-Ranges: bytes
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=WG5n5SswkTme%2BLgJyoRCTcIxEyr7EZa66mvHqtFcAEyLjpdH%2BA5rZZb3OeALYPQLgv%2B9j%2BMU3yPbZf1DKttkxQ%2F9LV7A0AKzexljunu3fy%2B%2BDj0fzMHTgQ6ChJc%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 89e2335bbbe57c93-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-04 21:27:40 UTC40INData Raw: 32 32 0d 0a 64 61 74 61 3a 69 6d 61 67 65 2f 70 6e 67 3b 62 61 73 65 36 34 2c 69 56 42 4f 52 77 30 4b 47 67 6f 3d 0d 0a
              Data Ascii: 22data:image/png;base64,iVBORw0KGgo=
              2024-07-04 21:27:40 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44973935.190.80.14433156C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:40 UTC524OUTOPTIONS /report/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://t8kwe.top
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-04 21:27:40 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: OPTIONS, POST
              access-control-allow-origin: *
              access-control-allow-headers: content-length, content-type
              date: Thu, 04 Jul 2024 21:27:40 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449740188.114.96.34433156C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:40 UTC344OUTGET /favicon.ico HTTP/1.1
              Host: t8kwe.top
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-04 21:27:40 UTC990INHTTP/1.1 200 OK
              Date: Thu, 04 Jul 2024 21:27:40 GMT
              Content-Type: text/html
              Transfer-Encoding: chunked
              Connection: close
              CDN-PullZone: 283898
              CDN-Uid: 10270df6-3a78-4ee3-9e7e-62f57a8521e8
              CDN-RequestCountryCode: US
              Cache-Control: public, max-age=31919000
              CDN-ProxyVer: 1.04
              CDN-RequestPullSuccess: True
              CDN-RequestPullCode: 200
              CDN-CachedAt: 05/25/2024 01:29:19
              CDN-EdgeStorageId: 894
              CDN-Status: 200
              CDN-RequestId: 2e8cb456321df90cc2c629ddce5e281c
              CDN-Cache: HIT
              CF-Cache-Status: HIT
              Age: 38480
              Last-Modified: Thu, 04 Jul 2024 10:46:20 GMT
              Accept-Ranges: bytes
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zBGtxPFR6a3eHNbTeDkXQRSrBRefA5wBv%2BX34l32hRB0vqnR50ajFveO1K6NaWrmDHs4SlR%2FVRkbycuwsP482UY8XPdqjZa%2BfJjYu%2FvHs0UyL2i%2BfXyh%2Fjn%2FOUo%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 89e2336028bb8c6c-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-04 21:27:40 UTC40INData Raw: 32 32 0d 0a 64 61 74 61 3a 69 6d 61 67 65 2f 70 6e 67 3b 62 61 73 65 36 34 2c 69 56 42 4f 52 77 30 4b 47 67 6f 3d 0d 0a
              Data Ascii: 22data:image/png;base64,iVBORw0KGgo=
              2024-07-04 21:27:40 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.44974235.190.80.14433156C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:41 UTC472OUTPOST /report/v4?s=19liIVL%2BIWx86KpPYCI5039EThLhr%2FcK74U9%2B4L6sBukaWMsvpUcBPLjgH5HcorfvLb9JIorjfgV%2FlZx2NuH1Rd5IaF8zAFgiJ4KQq1hrYevN5uQJKXOy4kQ9K0%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 379
              Content-Type: application/reports+json
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-07-04 21:27:41 UTC379OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 32 38 37 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 36 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 74 38 6b 77 65 2e 74 6f 70 2f 22 2c 22 75 73 65
              Data Ascii: [{"age":0,"body":{"elapsed_time":1287,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"188.114.96.3","status_code":404,"type":"http.error"},"type":"network-error","url":"https://t8kwe.top/","use
              2024-07-04 21:27:41 UTC168INHTTP/1.1 200 OK
              Content-Length: 0
              date: Thu, 04 Jul 2024 21:27:40 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.4497452.19.104.72443
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:42 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-07-04 21:27:42 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=240118
              Date: Thu, 04 Jul 2024 21:27:42 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.4497462.19.104.72443
              TimestampBytes transferredDirectionData
              2024-07-04 21:27:43 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-07-04 21:27:43 UTC535INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
              Cache-Control: public, max-age=240041
              Date: Thu, 04 Jul 2024 21:27:43 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-07-04 21:27:43 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:17:27:32
              Start date:04/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:17:27:35
              Start date:04/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2476,i,13138223959795890766,7790117090603310861,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:17:27:38
              Start date:04/07/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t8kwe.top"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly