Edit tour

Windows Analysis Report
https://tony.anka.cloudns.ch/

Overview

General Information

Sample URL:https://tony.anka.cloudns.ch/
Analysis ID:1516689
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4828 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1996,i,268182234977717537,5996108067324731132,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tony.anka.cloudns.ch/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://tony.anka.cloudns.ch/Avira URL Cloud: detection malicious, Label: phishing
Source: https://tony.anka.cloudns.ch/favicon.icoAvira URL Cloud: Label: phishing
Source: https://tony.anka.cloudns.ch/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:59690 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:57689 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: tony.anka.cloudns.chConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: tony.anka.cloudns.chConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://tony.anka.cloudns.ch/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: tony.anka.cloudns.chConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: tony.anka.cloudns.ch
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 390Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Tue, 24 Sep 2024 12:35:58 GMTContent-Type: text/plain;charset=UTF-8Content-Length: 44Connection: closeReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c82d13b6cfc8c53-EWR
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57693
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engineClassification label: mal56.win@21/5@8/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1996,i,268182234977717537,5996108067324731132,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tony.anka.cloudns.ch/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1996,i,268182234977717537,5996108067324731132,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1516689 URL: https://tony.anka.cloudns.ch/ Startdate: 24/09/2024 Architecture: WINDOWS Score: 56 26 Antivirus detection for URL or domain 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 6 chrome.exe 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49723 unknown unknown 6->14 16 192.168.2.5 unknown unknown 6->16 18 3 other IPs or domains 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 142.250.186.132, 443, 49741, 57693 GOOGLEUS United States 11->20 22 a.nel.cloudflare.com 35.190.80.1, 443, 49742, 49744 GOOGLEUS United States 11->22 24 2 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://tony.anka.cloudns.ch/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://tony.anka.cloudns.ch/favicon.ico100%Avira URL Cloudphishing
https://a.nel.cloudflare.com/report/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    unknown
    www.google.com
    142.250.186.132
    truefalse
      unknown
      anka-9vi.pages.dev
      172.66.47.81
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          tony.anka.cloudns.ch
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://tony.anka.cloudns.ch/favicon.icotrue
            • Avira URL Cloud: phishing
            unknown
            https://a.nel.cloudflare.com/report/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3Dfalse
            • Avira URL Cloud: safe
            unknown
            https://tony.anka.cloudns.ch/true
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.66.47.81
              anka-9vi.pages.devUnited States
              13335CLOUDFLARENETUSfalse
              142.250.186.132
              www.google.comUnited States
              15169GOOGLEUSfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.8
              192.168.2.7
              192.168.2.4
              192.168.2.5
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1516689
              Start date and time:2024-09-24 14:34:58 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 7s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://tony.anka.cloudns.ch/
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal56.win@21/5@8/8
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.185.206, 108.177.15.84, 142.250.185.227, 34.104.35.123, 13.85.23.86, 93.184.221.240, 13.95.31.18, 192.229.221.95, 142.250.185.131
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://tony.anka.cloudns.ch/
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 152 x 152, 8-bit colormap, non-interlaced
              Category:downloaded
              Size (bytes):6755
              Entropy (8bit):7.943115818179426
              Encrypted:false
              SSDEEP:96:JkBFJQh0YvZiy/G2XovJnx1dcFOBv+194cfd1eEwtD/8R1GeJrYcNmbTZgI46N57:JozlYvZiy/G2eNdPICcGHSdekmxNsKJB
              MD5:9CEF637DDFBA594AC6DEE7FD68E85A95
              SHA1:2481A8461CFEEDFE82BC5F7257848B12140E30B4
              SHA-256:698FC7056302AC9EA260AAD79C23B0F2428ED78A2434F2148D4EA4606BA00084
              SHA-512:12C0561E62CFC78D98E0D8650C90C5E8B560CA6D3EDB2D61BD7FC0E7E210B6E47E98DE5157B20A0F30C54E6F8C64B12F661ED26768DE55D9E6A241A7B42150C7
              Malicious:false
              Reputation:low
              URL:https://tony.anka.cloudns.ch/favicon.ico
              Preview:.PNG........IHDR............./.......PLTE...( 1.. ..!..!!.(..!........"........"..... .. .. ..!..$....." ....".....#.....#.....".....#.....".....)!.!..#..!..'!.!..#... .....".... '..#..%.......... ...%....O)..*..$..(..+..,...."&..,...../..".......!*..0..2..3......E~..5............H. 4....Md.&...&..... ...9p..ZN..D..;.....%.#......"(+................zx..S..H.CE..0...J.....X..0......nl..E#03l.)(..-.....L...............:v.#g..K$;;..:3.......................ee.UV..D..7..7u.,@.!U. :........n.......................x..f..X..G..*k..a..I..A..@..3O.#<. ........."........W...................<.............R..2q..nDDF..BI09=..5........s..........................*..K...........m..\........Y..IK..?..>M., . ...N.....=.....7....j..y....R............a..j~.Lz.:q.Hp.*f.%e..K..E].*\."D..8sS....)tRNS...MC..........mR...........rrhh....''..4.Y....IDATx...n.Q...ck-#H...EQ.Q .Ql#......@tH. .D....'..........x.:f...]_C...7Y..3..u......^q...:...&..:...O.N...t....g...N...........x`:.8.J..
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows icon resource - 1 icon, 16x16, 16 colors
              Category:dropped
              Size (bytes):318
              Entropy (8bit):2.918342372066458
              Encrypted:false
              SSDEEP:3:PFErXllvlNl/AXll/lFl/Ft/HtAiotuZt/k7vnck2sLC1GDER9RrmvRSjJSEJlbA:k9ij1k7/D+1tSSd3rbD4qM/
              MD5:A14E5365CC2B27EC57E1AB7866C6A228
              SHA1:37FC3645C16A1CBD74D8A6B7EF8756BBF0A3E857
              SHA-256:43C6594EB74940C6E0FB38D55C634425860093660F4EB0CB89334608DD9947EB
              SHA-512:C00B830BEEB9666EF83401919B1B5B564BC5FFE81073BB8B9094450DB1C838D9AB6A47E6C3F33730420F6B9F2151542F66E12F58B76E93F8840E0D0BECD7B862
              Malicious:false
              Reputation:low
              Preview:..............(.......(....... .......................................................................................................................................................................................................................................g...s...;.......c.......................G.............
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):44
              Entropy (8bit):3.9905863803852366
              Encrypted:false
              SSDEEP:3:0MXAGkthjQMjLSABLn:0MQ95j39n
              MD5:9BA3C1B0D129DD5D647F87E2B04F125D
              SHA1:37C3571ED505E7505D256E2BA689DE5D1F91F5D4
              SHA-256:15A3FACCCE6D4759E2426C91C6D1AE5E93AEEB49CB7B6CB5DEA76311EE45CDB2
              SHA-512:09CA7B4DE67FF5C197F4B4367A3DCC264A46D789DE805CD2B6BD76D4D79AE93B0ADF65B6DF1D41F3896462F19E0DF762DA663A92B37C33DC76F092E26F2129A4
              Malicious:false
              Reputation:low
              URL:https://tony.anka.cloudns.ch/
              Preview:Redirects to www.aliyun.com are not allowed.
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 140
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Sep 24, 2024 14:35:55.054474115 CEST49675443192.168.2.4173.222.162.32
              Sep 24, 2024 14:35:56.331732988 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.331794024 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.331932068 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.332169056 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.332277060 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.332353115 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.332490921 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.332504988 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.332729101 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.332766056 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.806169033 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.806612968 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.806652069 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.807724953 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.807806015 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809154987 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809154987 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809267998 CEST44349735172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.809281111 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809410095 CEST49735443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809565067 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809614897 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.809685946 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809875965 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.809890985 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.810180902 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.810405970 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.810439110 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.811479092 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.811539888 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812494040 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812522888 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812551975 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812578917 CEST44349736172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.812623024 CEST49736443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812803030 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.812840939 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:56.812906027 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.813080072 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:56.813097954 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.271568060 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.271929979 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.272000074 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.273027897 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.273127079 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.274498940 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.274575949 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.274837971 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.274857998 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.285024881 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.285260916 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.285317898 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.286375046 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.286546946 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.286765099 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.286835909 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.321327925 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.337263107 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:57.337299109 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:57.385134935 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:58.151976109 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.152031898 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.152118921 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.153085947 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.153104067 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.419562101 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:58.419641972 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:58.419698000 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:58.425349951 CEST49738443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:58.425368071 CEST44349738172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:58.445554972 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.445615053 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.445679903 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.449647903 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.449675083 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.550115108 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:35:58.591434002 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:35:58.786361933 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.787492990 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.787528992 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.789002895 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.789074898 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.792932987 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.793064117 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.837940931 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.837986946 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:35:58.882184029 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:35:58.928546906 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.930023909 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.930042028 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.931180000 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.931262016 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.941688061 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.941848993 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.942476034 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:58.942487001 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:58.991544008 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.070377111 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.070458889 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.070511103 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.071013927 CEST49742443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.071042061 CEST4434974235.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.071997881 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.072050095 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.072118044 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.072505951 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.072524071 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.124157906 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:35:59.124212027 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:35:59.124295950 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:35:59.139586926 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:35:59.139631033 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:35:59.528110981 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.528677940 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.528714895 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.529078007 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.532834053 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.533066988 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.533126116 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.575408936 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.586572886 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.658725977 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.658889055 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.659363031 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.661247969 CEST49744443192.168.2.435.190.80.1
              Sep 24, 2024 14:35:59.661278009 CEST4434974435.190.80.1192.168.2.4
              Sep 24, 2024 14:35:59.812299013 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:35:59.812422991 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:35:59.818783998 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:35:59.818800926 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:35:59.819113970 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:35:59.867834091 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.228766918 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.271404028 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:00.419420004 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:00.419960022 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:00.420160055 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.440361977 CEST49745443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.440387964 CEST44349745184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:00.580413103 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.580471992 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:00.580544949 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.582947969 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:00.582967043 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.220901966 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.221023083 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:01.222372055 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:01.222408056 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.222688913 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.224440098 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:01.267401934 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.496860981 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.496928930 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.497160912 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:01.499027014 CEST49746443192.168.2.4184.28.90.27
              Sep 24, 2024 14:36:01.499042988 CEST44349746184.28.90.27192.168.2.4
              Sep 24, 2024 14:36:01.542675018 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542745113 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542783022 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542824984 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542850018 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.542860985 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542927980 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.542964935 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.542989016 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.543004036 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.543081999 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.543139935 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.669053078 CEST49739443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.669105053 CEST44349739172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.743144035 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.743213892 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:01.743290901 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.744272947 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:01.744307041 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.207093000 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.207442999 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.207487106 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.216725111 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.216813087 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.218684912 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.218751907 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.218841076 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.218864918 CEST44349747172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.218926907 CEST49747443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.219584942 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.219630003 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.219796896 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.220124006 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.220136881 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.681297064 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.683897972 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.683936119 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.684990883 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.685066938 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.685511112 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.685753107 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.685754061 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.726351023 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:02.726389885 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:02.773247004 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:03.779537916 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:03.779639006 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:03.779697895 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:03.780723095 CEST49748443192.168.2.4172.66.47.81
              Sep 24, 2024 14:36:03.780750036 CEST44349748172.66.47.81192.168.2.4
              Sep 24, 2024 14:36:08.697587013 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:08.697674036 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:08.697837114 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:10.620075941 CEST49741443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:10.620121002 CEST44349741142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:10.781414032 CEST4972380192.168.2.4199.232.210.172
              Sep 24, 2024 14:36:11.086323977 CEST4972380192.168.2.4199.232.210.172
              Sep 24, 2024 14:36:11.109435081 CEST8049723199.232.210.172192.168.2.4
              Sep 24, 2024 14:36:11.109519005 CEST4972380192.168.2.4199.232.210.172
              Sep 24, 2024 14:36:11.110049963 CEST8049723199.232.210.172192.168.2.4
              Sep 24, 2024 14:36:35.312793016 CEST5768953192.168.2.41.1.1.1
              Sep 24, 2024 14:36:35.317750931 CEST53576891.1.1.1192.168.2.4
              Sep 24, 2024 14:36:35.317838907 CEST5768953192.168.2.41.1.1.1
              Sep 24, 2024 14:36:35.317944050 CEST5768953192.168.2.41.1.1.1
              Sep 24, 2024 14:36:35.322758913 CEST53576891.1.1.1192.168.2.4
              Sep 24, 2024 14:36:35.776264906 CEST53576891.1.1.1192.168.2.4
              Sep 24, 2024 14:36:35.783030033 CEST5768953192.168.2.41.1.1.1
              Sep 24, 2024 14:36:35.788271904 CEST53576891.1.1.1192.168.2.4
              Sep 24, 2024 14:36:35.788330078 CEST5768953192.168.2.41.1.1.1
              Sep 24, 2024 14:36:58.166934013 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:58.166987896 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.167124033 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:58.167375088 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:58.167391062 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.831763029 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.832154989 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:58.832181931 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.832655907 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.833370924 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:36:58.833456039 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:36:58.885341883 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:37:00.073561907 CEST4972480192.168.2.4199.232.210.172
              Sep 24, 2024 14:37:00.078784943 CEST8049724199.232.210.172192.168.2.4
              Sep 24, 2024 14:37:00.078876019 CEST4972480192.168.2.4199.232.210.172
              Sep 24, 2024 14:37:07.396910906 CEST5969053192.168.2.41.1.1.1
              Sep 24, 2024 14:37:07.401786089 CEST53596901.1.1.1192.168.2.4
              Sep 24, 2024 14:37:07.401858091 CEST5969053192.168.2.41.1.1.1
              Sep 24, 2024 14:37:07.401999950 CEST5969053192.168.2.41.1.1.1
              Sep 24, 2024 14:37:07.407011986 CEST53596901.1.1.1192.168.2.4
              Sep 24, 2024 14:37:07.845948935 CEST53596901.1.1.1192.168.2.4
              Sep 24, 2024 14:37:07.846307993 CEST5969053192.168.2.41.1.1.1
              Sep 24, 2024 14:37:07.851475954 CEST53596901.1.1.1192.168.2.4
              Sep 24, 2024 14:37:07.851530075 CEST5969053192.168.2.41.1.1.1
              Sep 24, 2024 14:37:08.737499952 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:37:08.737576962 CEST44357693142.250.186.132192.168.2.4
              Sep 24, 2024 14:37:08.737642050 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:37:10.606934071 CEST57693443192.168.2.4142.250.186.132
              Sep 24, 2024 14:37:10.606965065 CEST44357693142.250.186.132192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Sep 24, 2024 14:35:54.369360924 CEST53618101.1.1.1192.168.2.4
              Sep 24, 2024 14:35:54.369458914 CEST53547051.1.1.1192.168.2.4
              Sep 24, 2024 14:35:55.447381973 CEST53639531.1.1.1192.168.2.4
              Sep 24, 2024 14:35:56.070605993 CEST6553553192.168.2.41.1.1.1
              Sep 24, 2024 14:35:56.070761919 CEST6378153192.168.2.41.1.1.1
              Sep 24, 2024 14:35:56.330543995 CEST53655351.1.1.1192.168.2.4
              Sep 24, 2024 14:35:56.330595970 CEST53637811.1.1.1192.168.2.4
              Sep 24, 2024 14:35:58.110553980 CEST5126953192.168.2.41.1.1.1
              Sep 24, 2024 14:35:58.111002922 CEST6496853192.168.2.41.1.1.1
              Sep 24, 2024 14:35:58.117940903 CEST53512691.1.1.1192.168.2.4
              Sep 24, 2024 14:35:58.118130922 CEST53649681.1.1.1192.168.2.4
              Sep 24, 2024 14:35:58.423533916 CEST5245153192.168.2.41.1.1.1
              Sep 24, 2024 14:35:58.424088001 CEST5504753192.168.2.41.1.1.1
              Sep 24, 2024 14:35:58.430587053 CEST53524511.1.1.1192.168.2.4
              Sep 24, 2024 14:35:58.431921005 CEST53550471.1.1.1192.168.2.4
              Sep 24, 2024 14:36:01.686959982 CEST5149153192.168.2.41.1.1.1
              Sep 24, 2024 14:36:01.687294960 CEST5660853192.168.2.41.1.1.1
              Sep 24, 2024 14:36:01.728408098 CEST53514911.1.1.1192.168.2.4
              Sep 24, 2024 14:36:01.742491007 CEST53566081.1.1.1192.168.2.4
              Sep 24, 2024 14:36:11.734477043 CEST138138192.168.2.4192.168.2.255
              Sep 24, 2024 14:36:12.517271042 CEST53601391.1.1.1192.168.2.4
              Sep 24, 2024 14:36:31.268397093 CEST53503591.1.1.1192.168.2.4
              Sep 24, 2024 14:36:35.312321901 CEST53555481.1.1.1192.168.2.4
              Sep 24, 2024 14:36:54.211942911 CEST53649021.1.1.1192.168.2.4
              Sep 24, 2024 14:37:07.394593954 CEST53533671.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 24, 2024 14:35:56.070605993 CEST192.168.2.41.1.1.10xde87Standard query (0)tony.anka.cloudns.chA (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:56.070761919 CEST192.168.2.41.1.1.10x9c0fStandard query (0)tony.anka.cloudns.ch65IN (0x0001)false
              Sep 24, 2024 14:35:58.110553980 CEST192.168.2.41.1.1.10xbbfbStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:58.111002922 CEST192.168.2.41.1.1.10x6090Standard query (0)www.google.com65IN (0x0001)false
              Sep 24, 2024 14:35:58.423533916 CEST192.168.2.41.1.1.10x232aStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:58.424088001 CEST192.168.2.41.1.1.10xe0f3Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              Sep 24, 2024 14:36:01.686959982 CEST192.168.2.41.1.1.10xb9dcStandard query (0)tony.anka.cloudns.chA (IP address)IN (0x0001)false
              Sep 24, 2024 14:36:01.687294960 CEST192.168.2.41.1.1.10xf2c6Standard query (0)tony.anka.cloudns.ch65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 24, 2024 14:35:56.330543995 CEST1.1.1.1192.168.2.40xde87No error (0)tony.anka.cloudns.chanka-9vi.pages.devCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:35:56.330543995 CEST1.1.1.1192.168.2.40xde87No error (0)anka-9vi.pages.dev172.66.47.81A (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:56.330543995 CEST1.1.1.1192.168.2.40xde87No error (0)anka-9vi.pages.dev172.66.44.175A (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:56.330595970 CEST1.1.1.1192.168.2.40x9c0fNo error (0)tony.anka.cloudns.chanka-9vi.pages.devCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:35:56.330595970 CEST1.1.1.1192.168.2.40x9c0fNo error (0)anka-9vi.pages.dev65IN (0x0001)false
              Sep 24, 2024 14:35:58.117940903 CEST1.1.1.1192.168.2.40xbbfbNo error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
              Sep 24, 2024 14:35:58.118130922 CEST1.1.1.1192.168.2.40x6090No error (0)www.google.com65IN (0x0001)false
              Sep 24, 2024 14:35:58.430587053 CEST1.1.1.1192.168.2.40x232aNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              Sep 24, 2024 14:36:01.728408098 CEST1.1.1.1192.168.2.40xb9dcNo error (0)tony.anka.cloudns.chanka-9vi.pages.devCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:36:01.728408098 CEST1.1.1.1192.168.2.40xb9dcNo error (0)anka-9vi.pages.dev172.66.47.81A (IP address)IN (0x0001)false
              Sep 24, 2024 14:36:01.728408098 CEST1.1.1.1192.168.2.40xb9dcNo error (0)anka-9vi.pages.dev172.66.44.175A (IP address)IN (0x0001)false
              Sep 24, 2024 14:36:01.742491007 CEST1.1.1.1192.168.2.40xf2c6No error (0)tony.anka.cloudns.chanka-9vi.pages.devCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:36:01.742491007 CEST1.1.1.1192.168.2.40xf2c6No error (0)anka-9vi.pages.dev65IN (0x0001)false
              Sep 24, 2024 14:36:12.446031094 CEST1.1.1.1192.168.2.40x3b5cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:36:12.446031094 CEST1.1.1.1192.168.2.40x3b5cNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 24, 2024 14:36:27.594063997 CEST1.1.1.1192.168.2.40x930dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 24, 2024 14:36:27.594063997 CEST1.1.1.1192.168.2.40x930dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • tony.anka.cloudns.ch
              • https:
              • a.nel.cloudflare.com
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449738172.66.47.814434828C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 12:35:57 UTC663OUTGET / HTTP/1.1
              Host: tony.anka.cloudns.ch
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 12:35:58 UTC529INHTTP/1.1 403 Forbidden
              Date: Tue, 24 Sep 2024 12:35:58 GMT
              Content-Type: text/plain;charset=UTF-8
              Content-Length: 44
              Connection: close
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c82d13b6cfc8c53-EWR
              2024-09-24 12:35:58 UTC44INData Raw: 52 65 64 69 72 65 63 74 73 20 74 6f 20 77 77 77 2e 61 6c 69 79 75 6e 2e 63 6f 6d 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 2e
              Data Ascii: Redirects to www.aliyun.com are not allowed.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449739172.66.47.814434828C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 12:35:58 UTC596OUTGET /favicon.ico HTTP/1.1
              Host: tony.anka.cloudns.ch
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://tony.anka.cloudns.ch/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 12:36:01 UTC1336INHTTP/1.1 200 OK
              Date: Tue, 24 Sep 2024 12:36:01 GMT
              Content-Type: image/x-icon
              Transfer-Encoding: chunked
              Connection: close
              CF-Ray: 8c82d1433e540f85-EWR
              CF-Cache-Status: MISS
              ETag: W/"66d02615-1a63"
              Last-Modified: Thu, 29 Aug 2024 07:41:09 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Vary: Accept-Encoding
              server-timing: cdn-cache; desc=HIT, edge; dur=0, origin; dur=0
              server-timing: inner; dur=4
              x-akamai-request-id: 3c6b15d5
              x-cache: TCP_MEM_HIT from a23-62-227-19.deploy.akamaitechnologies.com (AkamaiGHost/11.6.3-f27d542afa37241d2fddd9371d528b09) (-)
              x-tt-logid: 20240913155143EB0A8BB50CAAD609863D
              x-tt-trace-host: 0181d58b6b7e2a28c20c76a519c63fea518bd919969b21331e11050585697295a1f11d770bb1aceeb279ade4b5117adccb1dabf3f061352680eedf82fb6b4e091ccaee8424da84a919c0b17b57c89ad5dc3a6b580a3a34eb02e41f659c89485e36
              x-tt-trace-id: 00-240913155143EB0A8BB50CAAD609863D-289BC1B738D27CCF-00
              x-tt-trace-tag: id=16;cdn-cache=hit;type=static
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=f987dmOlU%2BZl7jOIE0J2lTtvkNUfthI7pfXXgPlzrnxNcFQ7C4u%2Bo6a1yIpRmn9ztxpeGusfo3PghVCTGG7P7g%2BU23Z%2BRTCivFyui3t4%2FLPIDUHopjB01MpbN8r7PALjdIbWpfbglA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              2024-09-24 12:36:01 UTC33INData Raw: 31 61 36 33 0d 0a 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 98 00 00 00 98 08 03 00
              Data Ascii: 1a63PNGIHDR
              2024-09-24 12:36:01 UTC1369INData Raw: 00 00 2f 1c d0 13 00 00 02 f1 50 4c 54 45 00 00 00 28 20 31 1b 17 20 1c 17 21 1d 19 21 21 1a 28 18 18 21 1e 16 1e 1e 16 1e 17 17 22 1e 15 1e 1c 17 1e 18 17 22 1c 16 1f 1b 17 20 1c 16 20 1c 16 20 1c 18 21 1f 1b 24 ff ff ff 1a 18 22 20 16 1d 17 17 22 1e 15 1e 18 18 23 1d 15 1e 18 18 23 1e 16 1f 18 18 22 1e 17 1e 19 19 23 1e 16 1e 18 18 22 1e 16 1f 19 19 29 21 19 21 17 18 23 19 17 21 1a 1a 27 21 1a 21 17 17 23 ff ff ff 20 14 1b 1e 15 1d 22 14 1a 1b 16 20 27 12 17 23 13 19 25 12 18 1f 14 1c 00 f8 ef 19 17 20 1d 15 1e 25 13 19 ff 00 4f 29 11 15 2a 12 16 24 14 1a 28 11 16 2b 11 15 2c 10 12 18 17 22 26 12 16 2c 10 14 1b 15 1e 2f 0f 11 22 13 1a 2e 0f 12 17 17 21 2a 10 14 30 0e 10 32 0e 0f 33 0e 0e 19 16 1f ff 45 7e a2 06 35 02 ea e1 06 f8 ef 02 ec e3 02 eb e2 48
              Data Ascii: /PLTE( 1 !!!(!"" !$" "##"#")!!#!'!!# " '#% %O)*$(+,"&,/".!*023E~5H
              2024-09-24 12:36:01 UTC1369INData Raw: da 21 a0 95 54 8f 59 a6 6c 09 d9 46 cf ba bd 32 37 0c 39 a1 95 45 42 bd 31 91 3c e2 d2 06 89 75 23 38 17 70 9a 68 3c a3 c4 b5 3c 9c bd ee 86 7a dc fb 8d 5d 1c 47 2b 45 01 43 04 25 88 7f 12 82 6a 6c 62 9a 75 c0 f5 b1 ee 05 30 d9 cb 6b b3 9d f9 15 86 c1 ac 24 82 9c 55 a7 72 21 a0 49 b2 49 f3 50 36 a9 4f 0f 26 49 c9 da 59 5f dd 90 5f b1 6f 55 a8 45 a9 31 f6 60 23 c4 6d b9 71 34 e0 bc 06 f8 ae 30 05 f2 da 54 5d 58 9b 43 fd 84 6b 9c 04 d2 f7 2d 1d 86 2c e4 b7 f3 f0 c3 9a dd be 8d 4f f8 bd c9 e6 dd 03 96 a1 a5 6d 24 9b f4 9b d3 69 3f 6b 60 3a 1e 57 88 63 74 2e 0a 61 8a c5 3c fc cc f4 96 77 02 9c b9 71 28 50 62 83 67 1c 4e 54 27 c8 b2 34 db 6f ec 13 13 07 4b d7 09 ba 2a 2b 47 73 2b a0 c4 20 f0 4c a7 7c f0 0b 0b 78 f2 f5 a8 83 b4 08 86 3e 9f 72 b2 c9 64 2b a9 c8
              Data Ascii: !TYlF279EB1<u#8ph<<z]G+EC%jlbu0k$Ur!IIP6O&IY__oUE1`#mq40T]XCk-,Om$i?k`:Wct.a<wq(PbgNT'4oK*+Gs+ L|x>rd+
              2024-09-24 12:36:01 UTC1369INData Raw: ea 8e e1 93 3c c0 ea 4b 35 b0 b4 e9 fb f8 8e a5 a2 c4 82 c0 c5 0a b0 ac c3 77 b9 9e 6d 34 95 c1 44 fa a7 24 23 b0 6c 18 17 25 cb 9e 45 68 14 d2 5b 7b 58 67 85 5d e0 32 0d 76 b0 ac e9 b7 51 99 51 98 3d b5 65 f8 5a 86 4e 16 8e d5 bb 6b 5c 5a bd 26 61 18 5a 2b c9 e3 58 52 f5 e7 5f 0c 36 11 1c 59 0f af cf 5a b2 6b 1e 69 e3 b2 c9 76 af b5 87 79 77 9d e4 0a 12 a1 8c dc 97 b3 66 17 5d 2c ac 57 48 45 76 95 fd 1e 5c 44 06 ac 00 eb 4f df 00 6b 4a 36 a1 b3 a9 0b 5a 99 8e 25 bb 97 85 63 a8 ca fa 04 67 5f f5 86 e2 ef 0f e9 d8 7d 8b 92 fc d5 30 a2 62 01 ac b9 9e 0c 51 b0 c9 45 92 61 27 43 59 36 0b 25 de 20 68 16 d1 c6 74 dd b1 25 cc b9 44 41 95 c1 b2 1e 4f 04 d8 34 6f fe 5d fc b9 54 db af 53 28 7b eb 91 0e 86 c1 b2 62 3f 14 ac 32 92 f0 4b 35 20 81 65 9d 95 78 2e eb 56
              Data Ascii: <K5wm4D$#l%Eh[{Xg]2vQQ=eZNk\Z&aZ+XR_6YZkivywf],WHEv\DOkJ6Z%cg_}0bQEa'CY6% ht%DAO4o]TS({b?2K5 ex.V
              2024-09-24 12:36:01 UTC1369INData Raw: 90 ac 98 8f df 1a 3c 89 83 85 b6 23 f4 23 03 8b db 46 12 ff 56 30 56 a9 23 2b ed f1 c9 0d e7 01 18 8f b9 6a c0 d8 8d 5e c3 c2 fa 85 78 32 0b 31 80 a1 8f e7 f3 ca f1 2a d8 ca 22 b1 e7 24 57 04 23 93 3e 1f c0 3a 73 ad b0 2d a4 30 af 8c d3 67 e6 82 62 64 7f 9e 57 5e d5 0e 99 66 e4 d6 2a d7 81 75 d3 17 36 0a d6 c3 6f f8 75 5e 8f 41 12 6a 05 b6 55 e0 ca b0 d8 a3 82 f9 d7 e5 dc 50 5a 4f 2c 68 60 ea 7f 70 c2 24 39 d3 dc 9a b1 89 8f 83 35 8a e9 12 d2 9f a6 95 be ef 8f 9c 14 2c 80 a1 f6 e3 1c db 8e a3 6c 84 a6 64 da ba df 35 70 2d 9e c4 45 dd 8d 08 05 6c 78 0d 98 2e 1f 21 c2 b0 ef df 2d e9 df 0d 64 4d da 66 64 d6 c8 6d 02 b7 46 c0 be 14 b0 b3 8e 35 6e a3 0d c6 31 56 15 b0 81 01 8c b0 ac 84 79 05 ab 2c ab 74 c4 80 cb b1 00 86 1a eb 8a e9 da c5 18 01 7b 5a c0 f6 19
              Data Ascii: <##FV0V#+j^x21*"$W#>:s-0gbdW^f*u6ou^AjUPZO,h`p$95,ld5p-Elx.!-dMfdmF5n1Vy,t{Z
              2024-09-24 12:36:01 UTC1254INData Raw: 9c eb ef de cb fd 06 ee cf 7f fd d7 da fb f8 be b3 bf de d9 1d a1 e8 be f0 15 5d 25 45 47 34 5a 7c 3f 12 ac 18 30 c0 46 a3 94 aa de 20 25 e2 0f 99 ae 4d c4 ec dc fb 0d 9d 44 c0 44 d7 ca 80 e0 a6 fa b1 f3 8b 89 8f 06 bd 79 c9 c8 98 1a a0 61 da 89 0f 47 27 e1 3a 6f 57 9f cf 2c f3 98 05 15 65 84 4c 00 ac 7c 29 cd eb cd 34 b0 11 5c 02 86 69 4e f6 a2 03 0f db 30 d5 cd ec 15 33 82 f3 2e d8 49 53 c7 5c 2d 92 9f 35 b3 b7 50 b8 d2 f4 69 86 67 b4 c0 be ab 5d b1 ce dc 35 ae eb be 2c 8e 4b d7 34 2c 11 75 4c 42 b6 b0 37 3b 89 1c 6d 33 3b 6d c0 4c 7b be 75 e3 ba 7d c1 b8 9e 6c 29 f7 4f 4e 4d d4 90 7a 93 61 01 a6 40 b3 7b 73 d6 1a 99 89 6a c6 72 be dd df 85 eb c0 43 e3 3a 74 99 99 f5 27 2e 0a e9 8e 8d 0a d7 da 7c ef ff a0 38 e6 31 13 cf 84 2c ba f6 e6 e5 3f b1 f6 9e 3f
              Data Ascii: ]%EG4Z|?0F %MDDyaG':oW,eL|)4\iN03.IS\-5Pig]5,K4,uLB7;m3;mL{u}l)ONMza@{sjrC:t'.|81,??
              2024-09-24 12:36:01 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974235.190.80.14434828C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 12:35:58 UTC553OUTOPTIONS /report/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://tony.anka.cloudns.ch
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 12:35:59 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: POST, OPTIONS
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Tue, 24 Sep 2024 12:35:58 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44974435.190.80.14434828C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 12:35:59 UTC490OUTPOST /report/v4?s=eaoeWdkcKmmzqRR03VEFRBXFqr9Hzbq5piDapu%2Bq40uCTZXEId7a48iUGLtC8ucvatFqBH1zGcPEJWZ%2FIGX%2FCMO3FcUAWeONG%2FS7851dLTpY47OSosVyvADy3JJNeTl9qYV7h0hCxg%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 390
              Content-Type: application/reports+json
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 12:35:59 UTC390OUTData Raw: 5b 7b 22 61 67 65 22 3a 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 32 33 34 33 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 36 2e 34 37 2e 38 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 74 6f 6e 79 2e 61 6e 6b 61 2e 63 6c 6f 75 64 6e
              Data Ascii: [{"age":1,"body":{"elapsed_time":2343,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"172.66.47.81","status_code":403,"type":"http.error"},"type":"network-error","url":"https://tony.anka.cloudn
              2024-09-24 12:35:59 UTC168INHTTP/1.1 200 OK
              Content-Length: 0
              date: Tue, 24 Sep 2024 12:35:59 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.449745184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-24 12:36:00 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-24 12:36:00 UTC494INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-neu-z1
              Cache-Control: public, max-age=26016
              Date: Tue, 24 Sep 2024 12:36:00 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.449746184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-24 12:36:01 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-24 12:36:01 UTC514INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=25941
              Date: Tue, 24 Sep 2024 12:36:01 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-24 12:36:01 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.449748172.66.47.814434828C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-24 12:36:02 UTC355OUTGET /favicon.ico HTTP/1.1
              Host: tony.anka.cloudns.ch
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-24 12:36:03 UTC1235INHTTP/1.1 200 OK
              Date: Tue, 24 Sep 2024 12:36:03 GMT
              Content-Type: image/x-icon
              Content-Length: 318
              Connection: close
              CF-Ray: 8c82d15d4cf272c2-EWR
              CF-Cache-Status: MISS
              Accept-Ranges: bytes
              Cache-Control: no-cache
              Expires: Tue, 24 Sep 2024 12:38:03 GMT
              Last-Modified: Thu, 05 May 2022 08:04:32 GMT
              Vary: special-area, Accept-Encoding
              Via: cache32.l2nu20-8[91,91,200-0,M], cache26.l2nu20-8[93,0], cache6.l2hk3[122,121,200-0,M], cache8.l2hk3[123,0], cache40.l2us2[294,293,200-0,M], cache37.l2us2[295,0], ens-cache16.us18[367,497,200-0,C], ens-cache13.us18[499,0]
              ali-swift-global-savetime: 1727181363
              cdn-ip: 47.246.24.243
              cdn-source: Ali
              cdn-user-ip: 172.70.111.116
              eagleid: 2ff618a117271813632263521e
              timing-allow-origin: *
              x-cache: MISS TCP_MISS dirn:-2:-2
              x-cache-remote: MISS
              x-swift-cachetime: 0
              x-swift-savetime: Tue, 24 Sep 2024 12:36:03 GMT
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=oU1ahUmf2l%2FjC6qTZll%2BB6LSy%2B3SrxGn%2BTGPirYikPm%2FPsjz4XOBtKPeEz1RqR4Z1wmdVF7v2CccgY1%2FoXhhBtiO612QO4TBkSosJkhovEDwFgn6V9Tp%2BaHy4SWvx0vwpEKmiiisXw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              2024-09-24 12:36:03 UTC134INData Raw: 00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00 00 00 00 00 00 00
              Data Ascii: ((
              2024-09-24 12:36:03 UTC184INData Raw: 00 09 99 00 09 99 00 00 00 00 09 90 90 09 90 00 00 99 00 09 90 00 99 00 00 09 99 00 99 00 09 00 00 00 00 90 00 90 09 00 00 99 90 09 90 09 99 00 00 00 09 90 99 99 90 00 00 00 99 99 99 99 00 00 00 09 99 90 00 99 90 00 00 09 99 09 99 99 90 00 00 09 99 00 00 99 90 00 00 09 99 09 90 99 90 00 00 00 99 90 09 99 00 00 00 00 09 99 99 90 00 00 00 00 00 00 00 00 00 00 ff ff 0f 0f e3 8f 0f 0f f9 67 00 00 ce 73 00 00 e3 3b 0f 0f fd db 0f 00 c6 63 00 0f f9 07 00 00 f0 0f 0f 0f e1 c7 0f 00 e2 07 0f 00 e3 c7 00 00 e2 47 0f 0f f1 8f 0f 00 f8 1f 0f 0f ff ff 00 00
              Data Ascii: gs;cG


              020406080s020406080100

              Click to jump to process

              020406080s0.0050100MB

              Click to jump to process

              Target ID:0
              Start time:08:35:50
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:08:35:52
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1996,i,268182234977717537,5996108067324731132,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:08:35:55
              Start date:24/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tony.anka.cloudns.ch/"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly