Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://tb.ldpdljrr.ru/

Overview

General Information

Sample URL:https://tb.ldpdljrr.ru/
Analysis ID:1580467
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 4812 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3452 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2004,i,7304875845637118557,5025004944731129465,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6492 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tb.ldpdljrr.ru/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://tb.ldpdljrr.ru/Avira URL Cloud: detection malicious, Label: phishing
Source: https://tb.ldpdljrr.ru/favicon.icoAvira URL Cloud: Label: phishing
Source: https://tb.ldpdljrr.ru/HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: tb.ldpdljrr.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: tb.ldpdljrr.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://tb.ldpdljrr.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: tb.ldpdljrr.ru
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 385Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 15:39:47 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}alt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=39947&min_rtt=35708&rtt_var=13812&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2826&recv_bytes=1578&delivery_rate=79530&cwnd=226&unsent_bytes=0&cid=e60f635c6cf5eafc&ts=197&x=0"Server: cloudflareCF-RAY: 8f71afa5ac5d43fe-EWRserver-timing: cfL4;desc="?proto=TCP&rtt=2003&min_rtt=1989&rtt_var=775&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2825&recv_bytes=1235&delivery_rate=1386514&cwnd=236&unsent_bytes=0&cid=97a37cd9f1968e0f&ts=868&x=0"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 24 Dec 2024 15:39:48 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeCache-Control: max-age=14400Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=i2kjk0MDg47H1hyMzMAsjVSlFGjPZ4%2BECJCEoryMqTSq%2Fb5BMH5nX%2F4J6pR3SZh0Pvv4wyIed2SzLOoC0EOeeL4hss7euLAKV8CI%2FI2ldREi6AHYdNqb6YjndyG2%2FA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Vary: Accept-Encodingalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=37902&min_rtt=35820&rtt_var=13683&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2824&recv_bytes=1494&delivery_rate=63702&cwnd=251&unsent_bytes=0&cid=5caa8ac139770dfd&ts=68&x=0"CF-Cache-Status: EXPIREDServer: cloudflareCF-RAY: 8f71afaa8a8543bf-EWRserver-timing: cfL4;desc="?proto=TCP&rtt=1744&min_rtt=1732&rtt_var=675&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2824&recv_bytes=1162&delivery_rate=1591280&cwnd=252&unsent_bytes=0&cid=2865fc64825f0b5d&ts=1534&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal56.win@16/2@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2004,i,7304875845637118557,5025004944731129465,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tb.ldpdljrr.ru/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2004,i,7304875845637118557,5025004944731129465,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://tb.ldpdljrr.ru/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://tb.ldpdljrr.ru/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    tb.ldpdljrr.ru
    104.21.30.230
    truefalse
      unknown
      www.google.com
      172.217.21.36
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://tb.ldpdljrr.ru/favicon.icotrue
        • Avira URL Cloud: phishing
        unknown
        https://a.nel.cloudflare.com/report/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3Dfalse
          high
          https://a.nel.cloudflare.com/report/v4?s=i2kjk0MDg47H1hyMzMAsjVSlFGjPZ4%2BECJCEoryMqTSq%2Fb5BMH5nX%2F4J6pR3SZh0Pvv4wyIed2SzLOoC0EOeeL4hss7euLAKV8CI%2FI2ldREi6AHYdNqb6YjndyG2%2FA%3D%3Dfalse
            high
            https://tb.ldpdljrr.ru/true
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              104.21.30.230
              tb.ldpdljrr.ruUnited States
              13335CLOUDFLARENETUSfalse
              172.217.21.36
              www.google.comUnited States
              15169GOOGLEUSfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1580467
              Start date and time:2024-12-24 16:38:44 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 56s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://tb.ldpdljrr.ru/
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal56.win@16/2@6/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.21.35, 172.217.19.238, 64.233.161.84, 172.217.17.46, 2.16.168.117, 192.229.221.95, 172.217.17.35, 142.250.181.142, 23.218.208.109, 20.12.23.50, 13.107.246.63
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
              • Not all processes where analyzed, report is missing behavior information
              • VT rate limit hit for: https://tb.ldpdljrr.ru/
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):548
              Entropy (8bit):4.688532577858027
              Encrypted:false
              SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
              MD5:370E16C3B7DBA286CFF055F93B9A94D8
              SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
              SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
              SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
              Malicious:false
              Reputation:low
              URL:https://tb.ldpdljrr.ru/
              Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Dec 24, 2024 16:39:31.438632965 CET49675443192.168.2.4173.222.162.32
              Dec 24, 2024 16:39:41.046854019 CET49675443192.168.2.4173.222.162.32
              Dec 24, 2024 16:39:43.544822931 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:43.544926882 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:43.545063019 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:43.545321941 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:43.545356035 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:44.678060055 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.678107023 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:44.678165913 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.679270983 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.679321051 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:44.679374933 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.680151939 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.680166960 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:44.680397034 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:44.680412054 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.250675917 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:45.252784967 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:45.252810955 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:45.254307032 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:45.254370928 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:45.260102987 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:45.260236979 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:45.303071976 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:45.303092003 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:45.349405050 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:45.896712065 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.896712065 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.897047043 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.897068024 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.897166967 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.897180080 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.898066998 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.898121119 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.898164988 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.898212910 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.899486065 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.899552107 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.899579048 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.899667025 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.899677038 CET44349740104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.899687052 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.899720907 CET49740443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900027037 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900051117 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.900106907 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900321960 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900335073 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.900463104 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900463104 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900511980 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900527000 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.900676012 CET44349739104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.900722980 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900737047 CET49739443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900734901 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.900815010 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:45.900888920 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.901050091 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:45.901084900 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.166161060 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.166564941 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.207956076 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.207961082 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.293482065 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.293521881 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.293658972 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.293674946 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.294707060 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.294790030 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.294800043 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.294857025 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.296802998 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.296885967 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.300283909 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.300426960 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.300539970 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.300558090 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.345930099 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.345937967 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:47.345938921 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:47.391849995 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.023976088 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.024096966 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.024173975 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.025257111 CET49743443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.025298119 CET44349743104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.080768108 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.127345085 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.166932106 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:48.166965008 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:48.167033911 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:48.167300940 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:48.167318106 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:48.709212065 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.709294081 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:48.709451914 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.710530996 CET49742443192.168.2.4104.21.30.230
              Dec 24, 2024 16:39:48.710551023 CET44349742104.21.30.230192.168.2.4
              Dec 24, 2024 16:39:49.444149017 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.444696903 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.444715023 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.446355104 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.446433067 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.448041916 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.448127031 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.448348045 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.448354959 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.499557018 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.900099039 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.900306940 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.900367975 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.900484085 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.900497913 CET4434974435.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.900506973 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.900552034 CET49744443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.901480913 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.901580095 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:49.901658058 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.901931047 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:49.901979923 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.133419037 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.133773088 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.133807898 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.134932995 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.135370016 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.135504007 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.135516882 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.135550022 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.188043118 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.602545023 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.602897882 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.602941036 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.603004932 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:51.603008032 CET4434974535.190.80.1192.168.2.4
              Dec 24, 2024 16:39:51.603074074 CET49745443192.168.2.435.190.80.1
              Dec 24, 2024 16:39:54.948956966 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:54.949109077 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:54.949174881 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:55.284168959 CET49737443192.168.2.4172.217.21.36
              Dec 24, 2024 16:39:55.284230947 CET44349737172.217.21.36192.168.2.4
              Dec 24, 2024 16:39:59.243307114 CET4972380192.168.2.4199.232.214.172
              Dec 24, 2024 16:39:59.364161968 CET8049723199.232.214.172192.168.2.4
              Dec 24, 2024 16:39:59.364216089 CET4972380192.168.2.4199.232.214.172
              Dec 24, 2024 16:40:43.470637083 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:43.470664024 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:43.470743895 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:43.470993042 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:43.471005917 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:45.168236971 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:45.168582916 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:45.168598890 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:45.169063091 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:45.169354916 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:45.169435024 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:45.220104933 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:46.267216921 CET4972480192.168.2.4199.232.214.172
              Dec 24, 2024 16:40:46.391189098 CET8049724199.232.214.172192.168.2.4
              Dec 24, 2024 16:40:46.391247034 CET4972480192.168.2.4199.232.214.172
              Dec 24, 2024 16:40:48.034109116 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:48.034117937 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:48.034203053 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:48.034432888 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:48.034446001 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.253361940 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.253720045 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.253746033 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.254072905 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.254404068 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.254461050 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.254542112 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.295346975 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.717922926 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.717976093 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.718030930 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.718317032 CET49785443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.718332052 CET4434978535.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.718805075 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.718832016 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:49.718892097 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.719118118 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:49.719130039 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.934091091 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.934617043 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:50.934633017 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.934963942 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.935444117 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:50.935444117 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:50.935461044 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.935507059 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:50.984746933 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:51.396095991 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:51.396153927 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:51.396218061 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:51.396368027 CET49787443192.168.2.435.190.80.1
              Dec 24, 2024 16:40:51.396379948 CET4434978735.190.80.1192.168.2.4
              Dec 24, 2024 16:40:54.873548031 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:54.873703003 CET44349770172.217.21.36192.168.2.4
              Dec 24, 2024 16:40:54.873761892 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:55.284384966 CET49770443192.168.2.4172.217.21.36
              Dec 24, 2024 16:40:55.284408092 CET44349770172.217.21.36192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Dec 24, 2024 16:39:39.227704048 CET53643121.1.1.1192.168.2.4
              Dec 24, 2024 16:39:39.245830059 CET53561091.1.1.1192.168.2.4
              Dec 24, 2024 16:39:41.939737082 CET53530191.1.1.1192.168.2.4
              Dec 24, 2024 16:39:43.406847954 CET5945453192.168.2.41.1.1.1
              Dec 24, 2024 16:39:43.407000065 CET5152553192.168.2.41.1.1.1
              Dec 24, 2024 16:39:43.543731928 CET53594541.1.1.1192.168.2.4
              Dec 24, 2024 16:39:43.543746948 CET53515251.1.1.1192.168.2.4
              Dec 24, 2024 16:39:44.249263048 CET6269953192.168.2.41.1.1.1
              Dec 24, 2024 16:39:44.249407053 CET5590253192.168.2.41.1.1.1
              Dec 24, 2024 16:39:44.620381117 CET53559021.1.1.1192.168.2.4
              Dec 24, 2024 16:39:44.620439053 CET53626991.1.1.1192.168.2.4
              Dec 24, 2024 16:39:48.028081894 CET5029753192.168.2.41.1.1.1
              Dec 24, 2024 16:39:48.028582096 CET6112153192.168.2.41.1.1.1
              Dec 24, 2024 16:39:48.165461063 CET53502971.1.1.1192.168.2.4
              Dec 24, 2024 16:39:48.166441917 CET53611211.1.1.1192.168.2.4
              Dec 24, 2024 16:39:57.837585926 CET138138192.168.2.4192.168.2.255
              Dec 24, 2024 16:39:58.936728001 CET53640051.1.1.1192.168.2.4
              Dec 24, 2024 16:40:17.886077881 CET53531181.1.1.1192.168.2.4
              Dec 24, 2024 16:40:38.828737020 CET53508401.1.1.1192.168.2.4
              Dec 24, 2024 16:40:40.267327070 CET53541711.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Dec 24, 2024 16:39:43.406847954 CET192.168.2.41.1.1.10xa258Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:43.407000065 CET192.168.2.41.1.1.10xc0a4Standard query (0)www.google.com65IN (0x0001)false
              Dec 24, 2024 16:39:44.249263048 CET192.168.2.41.1.1.10x9b2bStandard query (0)tb.ldpdljrr.ruA (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:44.249407053 CET192.168.2.41.1.1.10x3ac3Standard query (0)tb.ldpdljrr.ru65IN (0x0001)false
              Dec 24, 2024 16:39:48.028081894 CET192.168.2.41.1.1.10x1516Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:48.028582096 CET192.168.2.41.1.1.10xb819Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Dec 24, 2024 16:39:43.543731928 CET1.1.1.1192.168.2.40xa258No error (0)www.google.com172.217.21.36A (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:43.543746948 CET1.1.1.1192.168.2.40xc0a4No error (0)www.google.com65IN (0x0001)false
              Dec 24, 2024 16:39:44.620381117 CET1.1.1.1192.168.2.40x3ac3No error (0)tb.ldpdljrr.ru65IN (0x0001)false
              Dec 24, 2024 16:39:44.620439053 CET1.1.1.1192.168.2.40x9b2bNo error (0)tb.ldpdljrr.ru104.21.30.230A (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:44.620439053 CET1.1.1.1192.168.2.40x9b2bNo error (0)tb.ldpdljrr.ru172.67.173.246A (IP address)IN (0x0001)false
              Dec 24, 2024 16:39:48.165461063 CET1.1.1.1192.168.2.40x1516No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              • tb.ldpdljrr.ru
              • https:
              • a.nel.cloudflare.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449743104.21.30.2304433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:39:47 UTC657OUTGET / HTTP/1.1
              Host: tb.ldpdljrr.ru
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:39:48 UTC1019INHTTP/1.1 404 Not Found
              Date: Tue, 24 Dec 2024 15:39:47 GMT
              Content-Type: text/html
              Transfer-Encoding: chunked
              Connection: close
              cf-cache-status: DYNAMIC
              vary: accept-encoding
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=39947&min_rtt=35708&rtt_var=13812&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2826&recv_bytes=1578&delivery_rate=79530&cwnd=226&unsent_bytes=0&cid=e60f635c6cf5eafc&ts=197&x=0"
              Server: cloudflare
              CF-RAY: 8f71afa5ac5d43fe-EWR
              server-timing: cfL4;desc="?proto=TCP&rtt=2003&min_rtt=1989&rtt_var=775&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2825&recv_bytes=1235&delivery_rate=1386514&cwnd=236&unsent_bytes=0&cid=97a37cd9f1968e0f&ts=868&x=0"
              2024-12-24 15:39:48 UTC350INData Raw: 32 32 34 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68
              Data Ascii: 224<html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Ch
              2024-12-24 15:39:48 UTC205INData Raw: 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 0d 0a
              Data Ascii: ... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
              2024-12-24 15:39:48 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449742104.21.30.2304433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:39:48 UTC584OUTGET /favicon.ico HTTP/1.1
              Host: tb.ldpdljrr.ru
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://tb.ldpdljrr.ru/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:39:48 UTC1066INHTTP/1.1 404 Not Found
              Date: Tue, 24 Dec 2024 15:39:48 GMT
              Content-Type: text/html; charset=UTF-8
              Transfer-Encoding: chunked
              Connection: close
              Cache-Control: max-age=14400
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=i2kjk0MDg47H1hyMzMAsjVSlFGjPZ4%2BECJCEoryMqTSq%2Fb5BMH5nX%2F4J6pR3SZh0Pvv4wyIed2SzLOoC0EOeeL4hss7euLAKV8CI%2FI2ldREi6AHYdNqb6YjndyG2%2FA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Vary: Accept-Encoding
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=37902&min_rtt=35820&rtt_var=13683&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2824&recv_bytes=1494&delivery_rate=63702&cwnd=251&unsent_bytes=0&cid=5caa8ac139770dfd&ts=68&x=0"
              CF-Cache-Status: EXPIRED
              Server: cloudflare
              CF-RAY: 8f71afaa8a8543bf-EWR
              server-timing: cfL4;desc="?proto=TCP&rtt=1744&min_rtt=1732&rtt_var=675&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2824&recv_bytes=1162&delivery_rate=1591280&cwnd=252&unsent_bytes=0&cid=2865fc64825f0b5d&ts=1534&x=0"
              2024-12-24 15:39:48 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974435.190.80.14433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:39:49 UTC535OUTOPTIONS /report/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://tb.ldpdljrr.ru
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:39:49 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: POST, OPTIONS
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Tue, 24 Dec 2024 15:39:49 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44974535.190.80.14433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:39:51 UTC478OUTPOST /report/v4?s=wUJOXONTeh92LZ4V4%2BQbpR8%2FnxHMxWsXGChFzlagaU23UxSbseDU0bZparZlaNmsHDfunFkqny7mlN5QiWYUL0yb4GLXBVDJp6A2wh95ShfsjnpSF%2FAVwt1o%2Buz7rA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 385
              Content-Type: application/reports+json
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:39:51 UTC385OUTData Raw: 5b 7b 22 61 67 65 22 3a 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 33 37 36 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 33 30 2e 32 33 30 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 74 62 2e 6c 64 70 64 6c 6a 72 72 2e 72 75 2f
              Data Ascii: [{"age":1,"body":{"elapsed_time":3762,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.30.230","status_code":404,"type":"http.error"},"type":"network-error","url":"https://tb.ldpdljrr.ru/
              2024-12-24 15:39:51 UTC168INHTTP/1.1 200 OK
              Content-Length: 0
              date: Tue, 24 Dec 2024 15:39:51 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.44978535.190.80.14433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:40:49 UTC537OUTOPTIONS /report/v4?s=i2kjk0MDg47H1hyMzMAsjVSlFGjPZ4%2BECJCEoryMqTSq%2Fb5BMH5nX%2F4J6pR3SZh0Pvv4wyIed2SzLOoC0EOeeL4hss7euLAKV8CI%2FI2ldREi6AHYdNqb6YjndyG2%2FA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://tb.ldpdljrr.ru
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:40:49 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: OPTIONS, POST
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Tue, 24 Dec 2024 15:40:49 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.44978735.190.80.14433452C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-12-24 15:40:50 UTC480OUTPOST /report/v4?s=i2kjk0MDg47H1hyMzMAsjVSlFGjPZ4%2BECJCEoryMqTSq%2Fb5BMH5nX%2F4J6pR3SZh0Pvv4wyIed2SzLOoC0EOeeL4hss7euLAKV8CI%2FI2ldREi6AHYdNqb6YjndyG2%2FA%3D%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 422
              Content-Type: application/reports+json
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-12-24 15:40:50 UTC422OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 39 33 32 33 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 36 32 39 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 74 62 2e 6c 64 70 64 6c 6a 72 72 2e 72 75 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 33 30 2e 32 33 30 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c
              Data Ascii: [{"age":59323,"body":{"elapsed_time":629,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://tb.ldpdljrr.ru/","sampling_fraction":1.0,"server_ip":"104.21.30.230","status_code":404,"type":"http.error"},"type":"network-error","url
              2024-12-24 15:40:51 UTC168INHTTP/1.1 200 OK
              Content-Length: 0
              date: Tue, 24 Dec 2024 15:40:51 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:10:39:35
              Start date:24/12/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:10:39:37
              Start date:24/12/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2004,i,7304875845637118557,5025004944731129465,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:10:39:43
              Start date:24/12/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tb.ldpdljrr.ru/"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly