Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://gm.zonimathor.ru/qNd7

Overview

General Information

Sample URL:https://gm.zonimathor.ru/qNd7
Analysis ID:1591235
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 1780 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2300 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1992,i,6076073011183523868,5425779159046062475,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gm.zonimathor.ru/qNd7" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://gm.zonimathor.ru/qNd7Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /qNd7 HTTP/1.1Host: gm.zonimathor.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /qNd7 HTTP/1.1Host: gm.zonimathor.ruConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: gm.zonimathor.ru
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 389Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 14 Jan 2025 19:34:45 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}alt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=5046&min_rtt=4949&rtt_var=1467&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1577&delivery_rate=571428&cwnd=251&unsent_bytes=0&cid=7a95ee1a980b8068&ts=136&x=0"Server: cloudflareCF-RAY: 902010b1dbf5c461-EWRserver-timing: cfL4;desc="?proto=TCP&rtt=1471&min_rtt=1463&rtt_var=566&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2832&recv_bytes=1241&delivery_rate=1904761&cwnd=232&unsent_bytes=0&cid=a4341645315b18a1&ts=461&x=0"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 14 Jan 2025 19:34:58 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=gTemVlxRF1mZruqietnaw26ArLhPCqO4ik68yZxrFEflz2yaO%2BNNivqrIrjzvlbqmrWKZM9JoP1KgBo53chmuy1jrou5QlMJVW1wkzradmzZg%2FH6W%2Bsz27m3UItXWw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}alt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=4972&min_rtt=4897&rtt_var=1426&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1611&delivery_rate=567896&cwnd=251&unsent_bytes=0&cid=960a9acf891b9fc6&ts=109&x=0"Server: cloudflareCF-RAY: 902011054d4943be-EWRserver-timing: cfL4;desc="?proto=TCP&rtt=1569&min_rtt=1563&rtt_var=599&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2831&recv_bytes=1273&delivery_rate=1805813&cwnd=229&unsent_bytes=0&cid=c0f3a62a9a029211&ts=13779&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal48.win@18/0@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1992,i,6076073011183523868,5425779159046062475,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gm.zonimathor.ru/qNd7"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1992,i,6076073011183523868,5425779159046062475,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://gm.zonimathor.ru/qNd7100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    www.google.com
    142.250.185.228
    truefalse
      high
      gm.zonimathor.ru
      104.21.48.1
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://gm.zonimathor.ru/qNd7true
          unknown
          https://a.nel.cloudflare.com/report/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3Dfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            104.21.48.1
            gm.zonimathor.ruUnited States
            13335CLOUDFLARENETUSfalse
            142.250.185.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            35.190.80.1
            a.nel.cloudflare.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1591235
            Start date and time:2025-01-14 20:33:42 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 1s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://gm.zonimathor.ru/qNd7
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@18/0@6/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.35, 66.102.1.84, 142.250.186.78, 142.250.181.238, 217.20.57.36, 2.23.77.188, 172.217.16.206, 142.250.185.238, 2.23.242.162, 52.149.20.212
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://gm.zonimathor.ru/qNd7
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Jan 14, 2025 20:34:37.044646025 CET49675443192.168.2.4173.222.162.32
            Jan 14, 2025 20:34:41.695342064 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:41.695383072 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:41.695785999 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:41.695785999 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:41.695826054 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.346893072 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.347202063 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:42.347214937 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.348844051 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.348925114 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:42.350140095 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:42.350230932 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.402431011 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:42.402462959 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:42.449210882 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:43.626689911 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.626755953 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:43.626941919 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.627821922 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.627856016 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:43.627929926 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.655587912 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.655602932 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:43.656275034 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:43.656301022 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.146094084 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.147984982 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.181257963 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.181329012 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.181381941 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.181411028 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.185132980 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.185204029 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.185244083 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.185270071 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.215370893 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.215481043 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.215481043 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.215821981 CET44349742104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.216046095 CET49742443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.216224909 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.216330051 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.216418028 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.216711998 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.216738939 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.217514992 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.217514992 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.217561007 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.217827082 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.217922926 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.217974901 CET44349741104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.218070030 CET49741443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.218168020 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.218313932 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.218339920 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.687067986 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.687417030 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.687480927 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.689111948 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.689208984 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.693707943 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.693809032 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.693957090 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.693978071 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.696921110 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.697096109 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.697117090 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.700263023 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.700342894 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.704003096 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.704229116 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.746578932 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.747142076 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:44.747208118 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:44.794531107 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:45.131762981 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:45.131860971 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:45.132042885 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:45.132632971 CET49743443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:45.132677078 CET44349743104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:45.148559093 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.148662090 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.148740053 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.156548977 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.156591892 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.628087997 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.628304958 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.628343105 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.629847050 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.629923105 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.630776882 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.630876064 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.630956888 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.630974054 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.684300900 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.756010056 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.756206036 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.756288052 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.756328106 CET4434974535.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.756354094 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.756437063 CET49745443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.756886959 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.756953001 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:45.757029057 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.757215977 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:45.757235050 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.225970030 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.226310968 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.226351976 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.227499962 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.227813005 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.227935076 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.227950096 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.228034973 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.277615070 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.357238054 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.357325077 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:46.357438087 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.357750893 CET49746443192.168.2.435.190.80.1
            Jan 14, 2025 20:34:46.357781887 CET4434974635.190.80.1192.168.2.4
            Jan 14, 2025 20:34:52.242872000 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:52.242937088 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:52.242975950 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:53.560380936 CET49738443192.168.2.4142.250.185.228
            Jan 14, 2025 20:34:53.560405970 CET44349738142.250.185.228192.168.2.4
            Jan 14, 2025 20:34:54.708112001 CET4972380192.168.2.4199.232.210.172
            Jan 14, 2025 20:34:54.713562012 CET8049723199.232.210.172192.168.2.4
            Jan 14, 2025 20:34:54.713641882 CET4972380192.168.2.4199.232.210.172
            Jan 14, 2025 20:34:58.061292887 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.061331987 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.061505079 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.063602924 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.063622952 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.070477009 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.115355015 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.455574989 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.455632925 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.455768108 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.456609964 CET49744443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.456650972 CET44349744104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.537507057 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.537798882 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.537833929 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.541007996 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.541095018 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541439056 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541459084 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541498899 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541527987 CET44349753104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.541593075 CET49753443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541795969 CET49754443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.541855097 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:58.541964054 CET49754443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.542151928 CET49754443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:58.542174101 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:59.103295088 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:59.103872061 CET49754443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:59.103941917 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:59.104438066 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:59.104751110 CET49754443192.168.2.4104.21.48.1
            Jan 14, 2025 20:34:59.104841948 CET44349754104.21.48.1192.168.2.4
            Jan 14, 2025 20:34:59.152848005 CET49754443192.168.2.4104.21.48.1
            TimestampSource PortDest PortSource IPDest IP
            Jan 14, 2025 20:34:38.379291058 CET53495561.1.1.1192.168.2.4
            Jan 14, 2025 20:34:41.684753895 CET6363153192.168.2.41.1.1.1
            Jan 14, 2025 20:34:41.684869051 CET5051853192.168.2.41.1.1.1
            Jan 14, 2025 20:34:41.692430019 CET53636311.1.1.1192.168.2.4
            Jan 14, 2025 20:34:41.692610025 CET53505181.1.1.1192.168.2.4
            Jan 14, 2025 20:34:43.322891951 CET5646853192.168.2.41.1.1.1
            Jan 14, 2025 20:34:43.323647976 CET5039853192.168.2.41.1.1.1
            Jan 14, 2025 20:34:43.372668982 CET53503981.1.1.1192.168.2.4
            Jan 14, 2025 20:34:43.624907017 CET53564681.1.1.1192.168.2.4
            Jan 14, 2025 20:34:45.139019966 CET5907053192.168.2.41.1.1.1
            Jan 14, 2025 20:34:45.140212059 CET5983253192.168.2.41.1.1.1
            Jan 14, 2025 20:34:45.146153927 CET53590701.1.1.1192.168.2.4
            Jan 14, 2025 20:34:45.148035049 CET53598321.1.1.1192.168.2.4
            Jan 14, 2025 20:34:55.023570061 CET138138192.168.2.4192.168.2.255
            Jan 14, 2025 20:34:55.489909887 CET53618311.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jan 14, 2025 20:34:41.684753895 CET192.168.2.41.1.1.10x4260Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:41.684869051 CET192.168.2.41.1.1.10xe76Standard query (0)www.google.com65IN (0x0001)false
            Jan 14, 2025 20:34:43.322891951 CET192.168.2.41.1.1.10x7cfaStandard query (0)gm.zonimathor.ruA (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.323647976 CET192.168.2.41.1.1.10x37ffStandard query (0)gm.zonimathor.ru65IN (0x0001)false
            Jan 14, 2025 20:34:45.139019966 CET192.168.2.41.1.1.10x27cfStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:45.140212059 CET192.168.2.41.1.1.10x6741Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jan 14, 2025 20:34:41.692430019 CET1.1.1.1192.168.2.40x4260No error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:41.692610025 CET1.1.1.1192.168.2.40xe76No error (0)www.google.com65IN (0x0001)false
            Jan 14, 2025 20:34:43.372668982 CET1.1.1.1192.168.2.40x37ffNo error (0)gm.zonimathor.ru65IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.48.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.80.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.112.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.64.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.32.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.16.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:43.624907017 CET1.1.1.1192.168.2.40x7cfaNo error (0)gm.zonimathor.ru104.21.96.1A (IP address)IN (0x0001)false
            Jan 14, 2025 20:34:45.146153927 CET1.1.1.1192.168.2.40x27cfNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
            • gm.zonimathor.ru
            • a.nel.cloudflare.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449743104.21.48.14432300C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-14 19:34:44 UTC663OUTGET /qNd7 HTTP/1.1
            Host: gm.zonimathor.ru
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-14 19:34:45 UTC1034INHTTP/1.1 404 Not Found
            Date: Tue, 14 Jan 2025 19:34:45 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            cf-cache-status: DYNAMIC
            vary: accept-encoding
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            alt-svc: h3=":443"; ma=86400
            server-timing: cfL4;desc="?proto=TCP&rtt=5046&min_rtt=4949&rtt_var=1467&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1577&delivery_rate=571428&cwnd=251&unsent_bytes=0&cid=7a95ee1a980b8068&ts=136&x=0"
            Server: cloudflare
            CF-RAY: 902010b1dbf5c461-EWR
            server-timing: cfL4;desc="?proto=TCP&rtt=1471&min_rtt=1463&rtt_var=566&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2832&recv_bytes=1241&delivery_rate=1904761&cwnd=232&unsent_bytes=0&cid=a4341645315b18a1&ts=461&x=0"
            2025-01-14 19:34:45 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44974535.190.80.14432300C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-14 19:34:45 UTC539OUTOPTIONS /report/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Origin: https://gm.zonimathor.ru
            Access-Control-Request-Method: POST
            Access-Control-Request-Headers: content-type
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-14 19:34:45 UTC336INHTTP/1.1 200 OK
            Content-Length: 0
            access-control-max-age: 86400
            access-control-allow-methods: OPTIONS, POST
            access-control-allow-origin: *
            access-control-allow-headers: content-length, content-type
            date: Tue, 14 Jan 2025 19:34:45 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974635.190.80.14432300C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-14 19:34:46 UTC480OUTPOST /report/v4?s=7ZhW2K1hvRa2JBMUb38i04bxQVvfYLh5Wj5g%2BOFi5XNol%2BRRr4Aa72Ky0RcqtoZ5scTLC0attmlQVM12UHr%2BAhYMXTc2qjfCre114yqxnF9M46c%2BzS%2BVACVnVYUOAA%3D%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Content-Length: 389
            Content-Type: application/reports+json
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-14 19:34:46 UTC389OUTData Raw: 5b 7b 22 61 67 65 22 3a 34 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 37 37 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 34 38 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 67 6d 2e 7a 6f 6e 69 6d 61 74 68 6f 72 2e 72 75 2f
            Data Ascii: [{"age":4,"body":{"elapsed_time":1772,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.48.1","status_code":404,"type":"http.error"},"type":"network-error","url":"https://gm.zonimathor.ru/
            2025-01-14 19:34:46 UTC168INHTTP/1.1 200 OK
            Content-Length: 0
            date: Tue, 14 Jan 2025 19:34:46 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449744104.21.48.14432300C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-14 19:34:58 UTC695OUTGET /qNd7 HTTP/1.1
            Host: gm.zonimathor.ru
            Connection: keep-alive
            Cache-Control: max-age=0
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: cross-site
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-14 19:34:58 UTC1032INHTTP/1.1 404 Not Found
            Date: Tue, 14 Jan 2025 19:34:58 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            cf-cache-status: DYNAMIC
            vary: accept-encoding
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=gTemVlxRF1mZruqietnaw26ArLhPCqO4ik68yZxrFEflz2yaO%2BNNivqrIrjzvlbqmrWKZM9JoP1KgBo53chmuy1jrou5QlMJVW1wkzradmzZg%2FH6W%2Bsz27m3UItXWw%3D%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            alt-svc: h3=":443"; ma=86400
            server-timing: cfL4;desc="?proto=TCP&rtt=4972&min_rtt=4897&rtt_var=1426&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2823&recv_bytes=1611&delivery_rate=567896&cwnd=251&unsent_bytes=0&cid=960a9acf891b9fc6&ts=109&x=0"
            Server: cloudflare
            CF-RAY: 902011054d4943be-EWR
            server-timing: cfL4;desc="?proto=TCP&rtt=1569&min_rtt=1563&rtt_var=599&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2831&recv_bytes=1273&delivery_rate=1805813&cwnd=229&unsent_bytes=0&cid=c0f3a62a9a029211&ts=13779&x=0"
            2025-01-14 19:34:58 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:14:34:33
            Start date:14/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:14:34:36
            Start date:14/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1992,i,6076073011183523868,5425779159046062475,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:14:34:42
            Start date:14/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gm.zonimathor.ru/qNd7"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly