Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www771771u.com/

Overview

General Information

Sample URL:http://www771771u.com/
Analysis ID:1486369
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,5811684591503054322,2390703748722237039,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www771771u.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www771771u.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://165975.com/?home=casino&a=xHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /?home=casino&a=x HTTP/1.1Host: 165975.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 165975.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://165975.com/?home=casino&a=xAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 165975.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www771771u.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?home=casino&a=x HTTP/1.1Host: 165975.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www771771u.com
Source: global trafficDNS traffic detected: DNS query: 165975.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Thu, 01 Aug 2024 22:49:32 GMTContent-Type: text/html; charset=utf-8Content-Length: 1446Connection: closeServer: nodeStrict-Transport-Security: max-age=31536000;X-Cache-Status: MISS
Source: chromecache_42.2.drString found in binary or memory: https://2024042700.zbaxjm.com
Source: chromecache_42.2.drString found in binary or memory: https://2024042700.zbaxjm.com/66001/common/favicon.ico
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://cdn.hg66sdt65nfx64.com/66001/meta/logo.png
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://fonts.googleapis.com
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://fonts.googleapis.com/css2?family=Anton&display=swap
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://fonts.googleapis.com/css2?family=Noto
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://fonts.gstatic.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/5@13/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,5811684591503054322,2390703748722237039,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www771771u.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,5811684591503054322,2390703748722237039,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www771771u.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://165975.com/favicon.ico0%Avira URL Cloudsafe
http://165975.com/?home=casino&a=x0%Avira URL Cloudsafe
https://2024042700.zbaxjm.com0%Avira URL Cloudsafe
https://cdn.hg66sdt65nfx64.com/66001/meta/logo.png0%Avira URL Cloudsafe
https://2024042700.zbaxjm.com/66001/common/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    67899.mercuriaLsoLdes.com
    112.213.110.37
    truefalse
      unknown
      www.google.com
      142.250.185.196
      truefalse
        unknown
        3y6qjxu4.n.cdn-sys.com
        165.154.224.149
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            165975.com
            unknown
            unknownfalse
              unknown
              www771771u.com
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://165975.com/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                https://165975.com/?home=casino&a=xfalse
                  unknown
                  http://www771771u.com/true
                    unknown
                    http://165975.com/?home=casino&a=xfalse
                    • Avira URL Cloud: safe
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://cdn.hg66sdt65nfx64.com/66001/meta/logo.pngchromecache_41.2.dr, chromecache_42.2.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://2024042700.zbaxjm.comchromecache_42.2.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://2024042700.zbaxjm.com/66001/common/favicon.icochromecache_42.2.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    165.154.224.21
                    unknownCanada
                    7456INTERHOPCAfalse
                    165.154.224.149
                    3y6qjxu4.n.cdn-sys.comCanada
                    7456INTERHOPCAfalse
                    165.154.224.29
                    unknownCanada
                    7456INTERHOPCAfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.250.185.196
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    112.213.110.37
                    67899.mercuriaLsoLdes.comHong Kong
                    38197SUNHK-DATA-AS-APSunNetworkHongKongLimited-HongKongfalse
                    IP
                    192.168.2.4
                    192.168.2.5
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1486369
                    Start date and time:2024-08-02 00:48:32 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 6s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://www771771u.com/
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal48.win@17/5@13/8
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.184.238, 74.125.71.84, 34.104.35.123, 20.114.59.183, 199.232.210.172, 13.95.31.18, 192.229.221.95, 52.165.164.15, 216.58.206.67
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://www771771u.com/
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:dropped
                    Size (bytes):6427
                    Entropy (8bit):5.132382839222583
                    Encrypted:false
                    SSDEEP:96:vTMl6uxHbVrHzHrH2xJM0fgDMynqeZsuTbxHUP3GHuz5i+ku:7ArHbVLzL2xJM4gDMyqMfbduGOzcPu
                    MD5:D1B09A9B459DE89FC7ADA00A59B6AAB7
                    SHA1:4EB818E55D236CE22801C1C3A84FFA753F118CA5
                    SHA-256:FF11EB70031DF1747E6277731AE1663892580BB52C65F44329EE810B057332EC
                    SHA-512:2585D59413BD3A909F48B9FFA4ED8092314090B9B192C16305DBDF2B618739582C93FA86D6022871818F53CBFC23E682A8C94C577D65D3D0421114EC1AF33746
                    Malicious:false
                    Reputation:low
                    Preview:<!DOCTYPE html>.<html lang="en">..<head>. <link rel="preload" href="css/vue-virtual-scroller-c295a14a.css" as="style">. <link rel="preload" href="css/swiper-66a0bf78.css" as="style">. <link rel="preload" href="css/tailwind-503f4451.css" as="style">. <link rel="preload" href="css/ant-design-vue-1fd217a1.css" as="style">.. <meta charset="UTF-8" />. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta name="viewport". content="width=device-width, height=device-height, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">. <meta name="mobile-web-app-capable" content="yes">. <meta http-equiv="Cache-Control" content="no-cache, no-store, must-revalidate, max-age=0" />. <meta name="apple-mobile-web-app-capable" content="yes">. <meta name="apple-touch-fullscreen" content="yes">. <link rel="preconnect" href="https://fonts.googleapis.com">. <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>. <link rel="preconnect" href="https://2024042700.zbaxjm.com"
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:downloaded
                    Size (bytes):6427
                    Entropy (8bit):5.132382839222583
                    Encrypted:false
                    SSDEEP:96:vTMl6uxHbVrHzHrH2xJM0fgDMynqeZsuTbxHUP3GHuz5i+ku:7ArHbVLzL2xJM4gDMyqMfbduGOzcPu
                    MD5:D1B09A9B459DE89FC7ADA00A59B6AAB7
                    SHA1:4EB818E55D236CE22801C1C3A84FFA753F118CA5
                    SHA-256:FF11EB70031DF1747E6277731AE1663892580BB52C65F44329EE810B057332EC
                    SHA-512:2585D59413BD3A909F48B9FFA4ED8092314090B9B192C16305DBDF2B618739582C93FA86D6022871818F53CBFC23E682A8C94C577D65D3D0421114EC1AF33746
                    Malicious:false
                    Reputation:low
                    URL:https://165975.com/favicon.ico
                    Preview:<!DOCTYPE html>.<html lang="en">..<head>. <link rel="preload" href="css/vue-virtual-scroller-c295a14a.css" as="style">. <link rel="preload" href="css/swiper-66a0bf78.css" as="style">. <link rel="preload" href="css/tailwind-503f4451.css" as="style">. <link rel="preload" href="css/ant-design-vue-1fd217a1.css" as="style">.. <meta charset="UTF-8" />. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta name="viewport". content="width=device-width, height=device-height, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">. <meta name="mobile-web-app-capable" content="yes">. <meta http-equiv="Cache-Control" content="no-cache, no-store, must-revalidate, max-age=0" />. <meta name="apple-mobile-web-app-capable" content="yes">. <meta name="apple-touch-fullscreen" content="yes">. <link rel="preconnect" href="https://fonts.googleapis.com">. <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>. <link rel="preconnect" href="https://2024042700.zbaxjm.com"
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1416), with no line terminators
                    Category:downloaded
                    Size (bytes):1446
                    Entropy (8bit):5.525013509710836
                    Encrypted:false
                    SSDEEP:24:kHVAPdRdJVXVVsmM5e57zUjffflV79ff1Kzfj2WlvnZw+lFBLc3fysr1fva0GxR4:MkpsA5WfffHxffMzfj2WlfDFBo3PgDAt
                    MD5:ECC1810C7525AA15547E69E6D8E2449A
                    SHA1:0A29EEC13A60733A852656882CCF8BA21FEB1B8A
                    SHA-256:F4FC10BCAF4E4A81FBC31B6114DE6BE82658EFF5754A16E735622568FA98D3C2
                    SHA-512:3081F06A108A1FAE6244219BB4FA2B39FADD1C40C939435E17A9BECF4CF0CA71C4F1BD7E1B806F8926521951E45C0835AF65C3DD5837120D4E2E06BA7BDE6608
                    Malicious:false
                    Reputation:low
                    URL:https://165975.com/?home=casino&a=x
                    Preview:<html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-color:rgb(46,46,46);font-family:Arial,sans-serif;font-size:1rem}.container{background-image:linear-gradient(180deg,rgb(239,95,95)0,rgb(149,44,44)100%);border-radius:8px;overflow:hidden;width:720px;box-shadow:0 3px 12px rgb(0,0,0)}.info-block{padding:32.21px 0 30px 24px;color:rgb(255,255,255);display:flex;align-items:flex-start;flex-direction:column}.message-block{background:rgb(255,255,255);color:rgb(153,153,153);text-align:center;padding:6px}.ip-style{font-size:2.5rem;margin-top:6px}.info-pos{position:relative}svg{position:absolute;top:0;right:0}@media screen and(max-width:768px){.container{width:85%}.info-block{font-size:1.25rem}.ip-style{font-size:1.75rem}}</style></head><body><div class="container"><div class="info-pos"><div class="f
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Aug 2, 2024 00:49:18.889338970 CEST49675443192.168.2.4173.222.162.32
                    Aug 2, 2024 00:49:28.499912024 CEST49675443192.168.2.4173.222.162.32
                    Aug 2, 2024 00:49:28.594451904 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:28.594716072 CEST4973680192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:28.600187063 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:49:28.600210905 CEST8049736112.213.110.37192.168.2.4
                    Aug 2, 2024 00:49:28.600470066 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:28.600533009 CEST4973680192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:28.600533009 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:28.605565071 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:49:29.526917934 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:49:29.578284025 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:49:30.186808109 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:30.191863060 CEST8049739165.154.224.149192.168.2.4
                    Aug 2, 2024 00:49:30.191931963 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:30.197884083 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:30.203340054 CEST8049739165.154.224.149192.168.2.4
                    Aug 2, 2024 00:49:30.229170084 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:30.229201078 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:30.229260921 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:30.229655981 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:30.229681015 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:30.942642927 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:30.942909002 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:30.942934036 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:30.943820953 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:30.943878889 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:31.109481096 CEST8049739165.154.224.149192.168.2.4
                    Aug 2, 2024 00:49:31.147979021 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:31.148328066 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:31.153054953 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:31.203903913 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:31.203916073 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:31.246815920 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:31.375422955 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:31.375443935 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:31.375742912 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:31.379201889 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:31.379210949 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:31.440464020 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:31.440526009 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:31.440680981 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:31.441230059 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:31.441263914 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.047565937 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.047699928 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.055191994 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.055201054 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.055593967 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.108202934 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.196679115 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.240540981 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.389532089 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.389662027 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.389723063 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.389834881 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.389846087 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.389941931 CEST49741443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.389946938 CEST44349741184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.428874016 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.428939104 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.429029942 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.429344893 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:32.429375887 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:32.730978966 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.736960888 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:32.737003088 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.738558054 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.738653898 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:32.746272087 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:32.746393919 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.748730898 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:32.748760939 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:32.794074059 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.075542927 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.075597048 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.075745106 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.075748920 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.075803041 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.079176903 CEST49742443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.079210043 CEST44349742165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.137667894 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.137749910 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.272933960 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.272959948 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.273329020 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.277360916 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.324508905 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.593586922 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.593621969 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.593698025 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.600677967 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:33.600691080 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:33.652697086 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.652771950 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.652836084 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.654323101 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.654334068 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:33.654414892 CEST49743443192.168.2.4184.28.90.27
                    Aug 2, 2024 00:49:33.654422045 CEST44349743184.28.90.27192.168.2.4
                    Aug 2, 2024 00:49:34.893131018 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:34.893652916 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:34.893716097 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:34.894898891 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:34.895462990 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:34.895656109 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:34.895749092 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:34.940490007 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:35.256227970 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:35.256293058 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:35.256460905 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:35.256606102 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:35.258876085 CEST49744443192.168.2.4165.154.224.21
                    Aug 2, 2024 00:49:35.258918047 CEST44349744165.154.224.21192.168.2.4
                    Aug 2, 2024 00:49:35.294547081 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:35.294586897 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:35.294689894 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:35.295080900 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:35.295100927 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.532896996 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.533334017 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.533349037 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.534823895 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.534912109 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.535456896 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.535537958 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.535800934 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.535809040 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.590817928 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.851932049 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.851964951 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.851974010 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.852047920 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:36.852054119 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.852130890 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.853930950 CEST49745443192.168.2.4165.154.224.29
                    Aug 2, 2024 00:49:36.853955984 CEST44349745165.154.224.29192.168.2.4
                    Aug 2, 2024 00:49:40.860510111 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:40.860590935 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:40.860896111 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:40.923475027 CEST49740443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:49:40.923528910 CEST44349740142.250.185.196192.168.2.4
                    Aug 2, 2024 00:49:41.108752966 CEST8049739165.154.224.149192.168.2.4
                    Aug 2, 2024 00:49:41.108849049 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:42.924376965 CEST4973980192.168.2.4165.154.224.149
                    Aug 2, 2024 00:49:42.931060076 CEST8049739165.154.224.149192.168.2.4
                    Aug 2, 2024 00:49:45.212642908 CEST4972380192.168.2.493.184.221.240
                    Aug 2, 2024 00:49:45.217808008 CEST804972393.184.221.240192.168.2.4
                    Aug 2, 2024 00:49:45.217866898 CEST4972380192.168.2.493.184.221.240
                    Aug 2, 2024 00:50:13.607713938 CEST4973680192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:13.612709999 CEST8049736112.213.110.37192.168.2.4
                    Aug 2, 2024 00:50:14.529603958 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:14.534533024 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:50:28.965318918 CEST4973680192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:28.971096992 CEST8049736112.213.110.37192.168.2.4
                    Aug 2, 2024 00:50:28.972656965 CEST4973680192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:29.529272079 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:50:29.534080029 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:30.266683102 CEST4973580192.168.2.4112.213.110.37
                    Aug 2, 2024 00:50:30.267420053 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:30.267452002 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.267524004 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:30.268501043 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:30.268513918 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.271596909 CEST8049735112.213.110.37192.168.2.4
                    Aug 2, 2024 00:50:30.918138981 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.918523073 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:30.918564081 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.918982029 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.919503927 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:30.919580936 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:30.966742992 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:33.592060089 CEST4972480192.168.2.493.184.221.240
                    Aug 2, 2024 00:50:33.597950935 CEST804972493.184.221.240192.168.2.4
                    Aug 2, 2024 00:50:33.599225044 CEST4972480192.168.2.493.184.221.240
                    Aug 2, 2024 00:50:40.851861954 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:40.852010012 CEST44349754142.250.185.196192.168.2.4
                    Aug 2, 2024 00:50:40.852264881 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:40.922234058 CEST49754443192.168.2.4142.250.185.196
                    Aug 2, 2024 00:50:40.922251940 CEST44349754142.250.185.196192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Aug 2, 2024 00:49:26.314785004 CEST53639721.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:26.490804911 CEST53545131.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:27.518404007 CEST53531621.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:28.186139107 CEST6433753192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:28.186366081 CEST6194253192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:28.538336992 CEST53619421.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:28.538916111 CEST5611353192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:28.541487932 CEST53643371.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:28.892209053 CEST53561131.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:29.531325102 CEST5120753192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:29.531461000 CEST6125953192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:29.702687979 CEST53612591.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:29.703510046 CEST5371853192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:29.711246967 CEST53537181.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:30.186050892 CEST53512071.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:30.209114075 CEST5746453192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:30.209598064 CEST6258753192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:30.220555067 CEST53574641.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:30.220571041 CEST53625871.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:31.167773008 CEST5579153192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:31.168256998 CEST5801953192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:31.348182917 CEST53580191.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:31.348860979 CEST6083353192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:31.377799988 CEST53557911.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:31.528580904 CEST53608331.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:35.265605927 CEST6475653192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:35.265821934 CEST6187553192.168.2.41.1.1.1
                    Aug 2, 2024 00:49:35.278615952 CEST53647561.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:35.439487934 CEST53618751.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:44.860106945 CEST53654771.1.1.1192.168.2.4
                    Aug 2, 2024 00:49:45.164176941 CEST138138192.168.2.4192.168.2.255
                    Aug 2, 2024 00:50:03.679812908 CEST53561621.1.1.1192.168.2.4
                    Aug 2, 2024 00:50:26.087289095 CEST53512981.1.1.1192.168.2.4
                    Aug 2, 2024 00:50:26.434303045 CEST53554161.1.1.1192.168.2.4
                    TimestampSource IPDest IPChecksumCodeType
                    Aug 2, 2024 00:49:28.892326117 CEST192.168.2.41.1.1.1c1e4(Port unreachable)Destination Unreachable
                    Aug 2, 2024 00:49:31.528672934 CEST192.168.2.41.1.1.1c1e0(Port unreachable)Destination Unreachable
                    Aug 2, 2024 00:49:35.439604998 CEST192.168.2.41.1.1.1c1e0(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Aug 2, 2024 00:49:28.186139107 CEST192.168.2.41.1.1.10xf1aStandard query (0)www771771u.comA (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:28.186366081 CEST192.168.2.41.1.1.10x659cStandard query (0)www771771u.com65IN (0x0001)false
                    Aug 2, 2024 00:49:28.538916111 CEST192.168.2.41.1.1.10x6404Standard query (0)www771771u.com65IN (0x0001)false
                    Aug 2, 2024 00:49:29.531325102 CEST192.168.2.41.1.1.10xbc22Standard query (0)165975.comA (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:29.531461000 CEST192.168.2.41.1.1.10xdfa1Standard query (0)165975.com65IN (0x0001)false
                    Aug 2, 2024 00:49:29.703510046 CEST192.168.2.41.1.1.10xdb7dStandard query (0)165975.com65IN (0x0001)false
                    Aug 2, 2024 00:49:30.209114075 CEST192.168.2.41.1.1.10xe501Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:30.209598064 CEST192.168.2.41.1.1.10xcba4Standard query (0)www.google.com65IN (0x0001)false
                    Aug 2, 2024 00:49:31.167773008 CEST192.168.2.41.1.1.10xfd4Standard query (0)165975.comA (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:31.168256998 CEST192.168.2.41.1.1.10x67eeStandard query (0)165975.com65IN (0x0001)false
                    Aug 2, 2024 00:49:31.348860979 CEST192.168.2.41.1.1.10x75abStandard query (0)165975.com65IN (0x0001)false
                    Aug 2, 2024 00:49:35.265605927 CEST192.168.2.41.1.1.10xc8bdStandard query (0)165975.comA (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:35.265821934 CEST192.168.2.41.1.1.10xac45Standard query (0)165975.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Aug 2, 2024 00:49:28.538336992 CEST1.1.1.1192.168.2.40x659cServer failure (2)www771771u.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:28.541487932 CEST1.1.1.1192.168.2.40xf1aNo error (0)www771771u.com67899.mercuriaLsoLdes.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:28.541487932 CEST1.1.1.1192.168.2.40xf1aNo error (0)67899.mercuriaLsoLdes.com112.213.110.37A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:28.892209053 CEST1.1.1.1192.168.2.40x6404Server failure (2)www771771u.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:29.702687979 CEST1.1.1.1192.168.2.40xdfa1Server failure (2)165975.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:29.711246967 CEST1.1.1.1192.168.2.40xdb7dServer failure (2)165975.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:30.186050892 CEST1.1.1.1192.168.2.40xbc22No error (0)165975.comcytb8e25.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:30.186050892 CEST1.1.1.1192.168.2.40xbc22No error (0)cytb8e25.cdn-sys.com3y6qjxu4.n.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:30.186050892 CEST1.1.1.1192.168.2.40xbc22No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.149A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:30.186050892 CEST1.1.1.1192.168.2.40xbc22No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.29A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:30.186050892 CEST1.1.1.1192.168.2.40xbc22No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.21A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:30.220555067 CEST1.1.1.1192.168.2.40xe501No error (0)www.google.com142.250.185.196A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:30.220571041 CEST1.1.1.1192.168.2.40xcba4No error (0)www.google.com65IN (0x0001)false
                    Aug 2, 2024 00:49:31.348182917 CEST1.1.1.1192.168.2.40x67eeServer failure (2)165975.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:31.377799988 CEST1.1.1.1192.168.2.40xfd4No error (0)165975.comcytb8e25.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:31.377799988 CEST1.1.1.1192.168.2.40xfd4No error (0)cytb8e25.cdn-sys.com3y6qjxu4.n.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:31.377799988 CEST1.1.1.1192.168.2.40xfd4No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.21A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:31.377799988 CEST1.1.1.1192.168.2.40xfd4No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.149A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:31.377799988 CEST1.1.1.1192.168.2.40xfd4No error (0)3y6qjxu4.n.cdn-sys.com165.154.224.29A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:31.528580904 CEST1.1.1.1192.168.2.40x75abServer failure (2)165975.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:35.278615952 CEST1.1.1.1192.168.2.40xc8bdNo error (0)165975.comcytb8e25.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:35.278615952 CEST1.1.1.1192.168.2.40xc8bdNo error (0)cytb8e25.cdn-sys.com3y6qjxu4.n.cdn-sys.comCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:35.278615952 CEST1.1.1.1192.168.2.40xc8bdNo error (0)3y6qjxu4.n.cdn-sys.com165.154.224.29A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:35.278615952 CEST1.1.1.1192.168.2.40xc8bdNo error (0)3y6qjxu4.n.cdn-sys.com165.154.224.21A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:35.278615952 CEST1.1.1.1192.168.2.40xc8bdNo error (0)3y6qjxu4.n.cdn-sys.com165.154.224.149A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:35.439487934 CEST1.1.1.1192.168.2.40xac45Server failure (2)165975.comnonenone65IN (0x0001)false
                    Aug 2, 2024 00:49:42.477653980 CEST1.1.1.1192.168.2.40xcef1No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:42.477653980 CEST1.1.1.1192.168.2.40xcef1No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:44.139545918 CEST1.1.1.1192.168.2.40x52dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:44.139545918 CEST1.1.1.1192.168.2.40x52dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:49:59.962394953 CEST1.1.1.1192.168.2.40xdb1fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:49:59.962394953 CEST1.1.1.1192.168.2.40xdb1fNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:50:18.773027897 CEST1.1.1.1192.168.2.40xaa31No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:50:18.773027897 CEST1.1.1.1192.168.2.40xaa31No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 2, 2024 00:50:39.585486889 CEST1.1.1.1192.168.2.40x845bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 2, 2024 00:50:39.585486889 CEST1.1.1.1192.168.2.40x845bNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    • 165975.com
                    • fs.microsoft.com
                    • https:
                    • www771771u.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449735112.213.110.37803164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Aug 2, 2024 00:49:28.600533009 CEST429OUTGET / HTTP/1.1
                    Host: www771771u.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Aug 2, 2024 00:49:29.526917934 CEST409INHTTP/1.1 301 Moved Permanently
                    Server: nginx
                    Date: Thu, 01 Aug 2024 22:49:29 GMT
                    Content-Type: text/html
                    Content-Length: 162
                    Connection: keep-alive
                    Location: http://165975.com/?home=casino&a=x
                    Strict-Transport-Security: max-age=31536000
                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
                    Aug 2, 2024 00:50:14.529603958 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449739165.154.224.149803164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Aug 2, 2024 00:49:30.197884083 CEST441OUTGET /?home=casino&a=x HTTP/1.1
                    Host: 165975.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Aug 2, 2024 00:49:31.109481096 CEST436INHTTP/1.1 301 Moved Permanently
                    Date: Thu, 01 Aug 2024 22:49:30 GMT
                    Content-Type: text/html
                    Content-Length: 166
                    Connection: keep-alive
                    Location: https://165975.com/?home=casino&a=x
                    Server: node
                    Strict-Transport-Security: max-age=31536000;
                    X-Cache-Status: MISS
                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>openresty</center></body></html>


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449736112.213.110.37803164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Aug 2, 2024 00:50:13.607713938 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449741184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-08-01 22:49:32 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-08-01 22:49:32 UTC468INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/0712)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus2-z1
                    Cache-Control: public, max-age=202441
                    Date: Thu, 01 Aug 2024 22:49:32 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449742165.154.224.214433164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-01 22:49:32 UTC669OUTGET /?home=casino&a=x HTTP/1.1
                    Host: 165975.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-01 22:49:33 UTC226INHTTP/1.1 403 Forbidden
                    Date: Thu, 01 Aug 2024 22:49:32 GMT
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 1446
                    Connection: close
                    Server: node
                    Strict-Transport-Security: max-age=31536000;
                    X-Cache-Status: MISS
                    2024-08-01 22:49:33 UTC1446INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 34 30 33 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 62 6f 64 79 2c 64 69 76 2c 68 74 6d 6c 2c 70 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 3b 62 6f 72 64 65 72 3a 30 7d 62 6f 64 79 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 68 65 69 67 68 74 3a 31 30 30 76 68 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f
                    Data Ascii: <html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-co


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449743184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-08-01 22:49:33 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-08-01 22:49:33 UTC515INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF06)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-weu-z1
                    Cache-Control: public, max-age=202370
                    Date: Thu, 01 Aug 2024 22:49:33 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-08-01 22:49:33 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449744165.154.224.214433164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-01 22:49:34 UTC592OUTGET /favicon.ico HTTP/1.1
                    Host: 165975.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://165975.com/?home=casino&a=x
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-01 22:49:35 UTC403INHTTP/1.1 200 OK
                    Date: Thu, 01 Aug 2024 22:49:35 GMT
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 6427
                    Connection: close
                    Last-Modified: Wed, 24 Jul 2024 18:08:54 GMT
                    ETag: "66a14336-191b"
                    Access-Control-Allow-Origin: *
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Strict-Transport-Security: max-age=31536000;
                    Server: node
                    X-Cache-Status: HIT
                    Accept-Ranges: bytes
                    2024-08-01 22:49:35 UTC6427INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 76 75 65 2d 76 69 72 74 75 61 6c 2d 73 63 72 6f 6c 6c 65 72 2d 63 32 39 35 61 31 34 61 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 73 77 69 70 65 72 2d 36 36 61 30 62 66 37 38 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 74 61 69 6c 77 69 6e 64 2d 35 30 33 66 34 34 35 31 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c
                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <link rel="preload" href="css/vue-virtual-scroller-c295a14a.css" as="style"> <link rel="preload" href="css/swiper-66a0bf78.css" as="style"> <link rel="preload" href="css/tailwind-503f4451.css" as="style"> <


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.449745165.154.224.294433164C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-01 22:49:36 UTC345OUTGET /favicon.ico HTTP/1.1
                    Host: 165975.com
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: */*
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: cors
                    Sec-Fetch-Dest: empty
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-01 22:49:36 UTC403INHTTP/1.1 200 OK
                    Date: Thu, 01 Aug 2024 22:49:36 GMT
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 6427
                    Connection: close
                    Last-Modified: Wed, 24 Jul 2024 18:08:54 GMT
                    ETag: "66a14336-191b"
                    Access-Control-Allow-Origin: *
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Strict-Transport-Security: max-age=31536000;
                    Server: node
                    X-Cache-Status: HIT
                    Accept-Ranges: bytes
                    2024-08-01 22:49:36 UTC6427INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 76 75 65 2d 76 69 72 74 75 61 6c 2d 73 63 72 6f 6c 6c 65 72 2d 63 32 39 35 61 31 34 61 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 73 77 69 70 65 72 2d 36 36 61 30 62 66 37 38 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 6c 6f 61 64 22 20 68 72 65 66 3d 22 63 73 73 2f 74 61 69 6c 77 69 6e 64 2d 35 30 33 66 34 34 35 31 2e 63 73 73 22 20 61 73 3d 22 73 74 79 6c 65 22 3e 0a 20 20 3c
                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <link rel="preload" href="css/vue-virtual-scroller-c295a14a.css" as="style"> <link rel="preload" href="css/swiper-66a0bf78.css" as="style"> <link rel="preload" href="css/tailwind-503f4451.css" as="style"> <


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:18:49:22
                    Start date:01/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:18:49:24
                    Start date:01/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,5811684591503054322,2390703748722237039,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:18:49:27
                    Start date:01/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www771771u.com/"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly