Edit tour

Windows Analysis Report
http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/

Overview

General Information

Sample URL:http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/
Analysis ID:1637970
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3948 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,11247473949130860856,15678733379132640968,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2024 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 4360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/Avira URL Cloud: detection malicious, Label: phishing
Source: global trafficTCP traffic: 192.168.2.6:55599 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.184.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.184.227
Source: global trafficHTTP traffic detected: GET /p/jjnh-trfg/frmkhpcw/ HTTP/1.1Host: s.team-fg.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: s.team-fg.com
Source: global trafficDNS traffic detected: DNS query: beacons.gcp.gvt2.com
Source: global trafficDNS traffic detected: DNS query: beacons.gvt2.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55601 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55609 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 55612 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 55606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55610 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55604 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55611 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55605 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55602 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55609
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55605
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55606
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55601
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55602
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55603
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55604
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55603 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55612
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55610
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55611
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3948_1120419783Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670\ssl_error_assistant.pbJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670\manifest.jsonJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670\_metadata\Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670\_metadata\verified_contents.jsonJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping3948_1954187670\manifest.fingerprintJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3948_1120419783Jump to behavior
Source: classification engineClassification label: mal48.win@30/4@21/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,11247473949130860856,15678733379132640968,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2024 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,11247473949130860856,15678733379132640968,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2024 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1637970 URL: http://s.team-fg.com/p/jjnh... Startdate: 14/03/2025 Architecture: WINDOWS Score: 48 15 beacons6.gvt2.com 2->15 17 beacons.gvt2.com 2->17 19 2 other IPs or domains 2->19 33 Antivirus / Scanner detection for submitted sample 2->33 7 chrome.exe 8 2->7         started        10 chrome.exe 2->10         started        signatures3 process4 dnsIp5 21 192.168.2.13 unknown unknown 7->21 23 192.168.2.23 unknown unknown 7->23 25 2 other IPs or domains 7->25 12 chrome.exe 7->12         started        process6 dnsIp7 27 s.team-fg.com 185.208.156.194, 443, 49714, 49715 SIMPLECARRIERCH Switzerland 12->27 29 www.google.com 142.250.186.164, 443, 49710, 49713 GOOGLEUS United States 12->29 31 3 other IPs or domains 12->31

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
s.team-fg.com
185.208.156.194
truefalse
    unknown
    beacons-handoff.gcp.gvt2.com
    142.250.180.67
    truefalse
      high
      www.google.com
      142.250.186.164
      truefalse
        high
        beacons.gvt2.com
        142.251.143.35
        truefalse
          high
          beacons6.gvt2.com
          142.250.185.67
          truefalse
            high
            beacons.gcp.gvt2.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/true
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.208.156.194
                s.team-fg.comSwitzerland
                42624SIMPLECARRIERCHfalse
                142.250.186.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                192.168.2.6
                192.168.2.13
                192.168.2.23
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1637970
                Start date and time:2025-03-14 01:41:58 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 59s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:17
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@30/4@21/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, TextInputHost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.185.227, 142.250.186.174, 142.250.185.142, 74.125.206.84, 199.232.214.172, 142.250.186.163, 142.250.186.67, 142.250.185.206, 74.125.133.84, 34.104.35.123
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:JSON data
                Category:dropped
                Size (bytes):1765
                Entropy (8bit):6.016932513650603
                Encrypted:false
                SSDEEP:48:p/hKAGj0FnAp7XgNGIaku9E5tPJXaWqkbszesM:R5Gj0FAlsaBmfPsRD3M
                MD5:6D1D175F88B64546105E3E7C31D1129A
                SHA1:75A1B56F55BB62B05365A0FDBFC7941DE77CBFAF
                SHA-256:A0BC246E8E160A9BB32FA60F4E7A04D148A17125F426509466031E07731FDF81
                SHA-512:5C80908331E30C7EAD67F7F6C5AB064B07626FD9C58925A0D2124D66B25C5AE2F218BDACFB68AFCB332E88EB297CFB7E0A7A9E5E1E54C9B7A510FEF095F9B54F
                Malicious:false
                Reputation:low
                Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiJtYW5pZmVzdC5qc29uIiwicm9vdF9oYXNoIjoiSUxrUllPSmhIVEZacllLRmN5UC12SkJrVjNWbWVLdHo4d1hEb2VPWjBZMCJ9LHsicGF0aCI6InNzbF9lcnJvcl9hc3Npc3RhbnQucGIiLCJyb290X2hhc2giOiJyRFZLUnlPcXBQQnI3RGhkM2VTazBKZzYxUlJXOVNzeHFBYU95WDFiWHFjIn1dLCJmb3JtYXQiOiJ0cmVlaGFzaCIsImhhc2hfYmxvY2tfc2l6ZSI6NDA5Nn1dLCJpdGVtX2lkIjoiZ2lla2NtbWxua2xlbmxhb21wcGtwaGtuam1ubnBuZWgiLCJpdGVtX3ZlcnNpb24iOiI3IiwicHJvdG9jb2xfdmVyc2lvbiI6MX0","signatures":[{"header":{"kid":"publisher"},"protected":"eyJhbGciOiJSUzI1NiJ9","signature":"nBdNk-7bgnEftAs4hWaHwF1Lk9pt7Eh6pcqe2gyNsE7VnVRp-H27tm1RFAF4htCUlXNJxX6YY-MUiK2DqJpQ3c73KDaFV8DcnadQfcXO3Lbrw7jLYSUaSdzujPkTyhuFcq_BhK0KWiIJ0aJgh7nVOBfAa5AbE6oFlLKMB2Ls0gmzS1-a5hUIu4rw2h9r9jkr6gLYbein5Jk2hdwW3u-1GNjyki4dftG2iZNAI8VhUf5gnCiF4AHCnYSGJsM0RGkmO_HJIzgwpQpP3RDsG2ioeKgxL-kcHhjXWOj3uVGyxpp1FkyHGkeGuqpFZMAxx3CEBiOtFj7i3iQxkgEW-E3uMKI3yA
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:dropped
                Size (bytes):66
                Entropy (8bit):3.9555383032528804
                Encrypted:false
                SSDEEP:3:SWjBMq9+jigBeQrEj3vWXyDt:SW93KBeQIj+XQ
                MD5:684DA5CCA8ADC8CA59CBE5B082CFE0B5
                SHA1:B8784E02DB81C5F846A7848455A2C6629A88BD64
                SHA-256:F48C9D93CC216AF13BBFAD15DD5E6D1679CD35D318E664029DDF61EFC6E51A5D
                SHA-512:EAEB9B8C51AEF3CC2749F4E6B2C2B58334E53C0BA701DB94F2896C9557B949D392CF4F44B771821C63DD238FAC2B2F869833BED2DFF830AFC4C8743683A75183
                Malicious:false
                Reputation:low
                Preview:1.3eb16d6c28b502ac4cfee8f4a148df05f4d93229fa36a71db8b08d06329ff18a
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:JSON data
                Category:dropped
                Size (bytes):76
                Entropy (8bit):4.169145448714876
                Encrypted:false
                SSDEEP:3:rR6TAulhFphifFY8Wypv/KS1f:F6VlMQyBSS1f
                MD5:4AAA0ED8099ECC1DA778A9BC39393808
                SHA1:0E4A733A5AF337F101CFA6BEA5EBC153380F7B05
                SHA-256:20B91160E2611D3159AD82857323FEBC906457756678AB73F305C3A1E399D18D
                SHA-512:DFA942C35E1E5F62DD8840C97693CDBFD6D71A1FD2F42E26CB75B98BB6A1818395ECDF552D46F07DFF1E9C74F1493A39E05B14E3409963EFF1ADA88897152879
                Malicious:false
                Reputation:low
                Preview:{. "manifest_version": 2,. "name": "sslErrorAssistant",. "version": "7".}
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:dropped
                Size (bytes):2816
                Entropy (8bit):6.108955364911366
                Encrypted:false
                SSDEEP:48:jkbh6AW2Bfc3osI6Hc3+XgU+EVeY55J4gXM/QDH4yq2dxckdfmkM:jkbhM2a3pntgQVb8Ylq2di
                MD5:E2F792C9E2DD86F39E8286B2EAD2FC70
                SHA1:8A32867614D2A23E473ED642056DED8E566687F9
                SHA-256:AC354A4723AAA4F06BEC385DDDE4A4D0983AD51456F52B31A8068EC97D5B5EA7
                SHA-512:6A7AF0CA1EFA65A89A9CA3B8DF0D2E24F21D91673C60CDFEEB02D33647442B01D535497249542F40E66E0D2DD3E9F8ED1F4A201FD97138D07A2B71366737E580
                Malicious:false
                Reputation:low
                Preview:...5.3sha256/fjZPHewEHTrMDX3I1ecEIeoy3WFxHyGplOLv28kIbtI=.5.3sha256/m/nBiLhStttu1YmOz7Y3D2u1iB1dV2CbIfFa3R2YW5M=.5.3sha256/8Iuf4xRbVCmCMQTJn3rxlglIO1IOKoyuSUgmXyfaIKs=.5.3sha256/8IHdrS+r6IWzSMcRcD/GA6mBxk1ECX8tGRW0rtGWILE=.5.3sha256/k/2eeJTznE32mblA/du19wpVDSIReFX44M8wXa2JY30=.5.3sha256/urWd7jMwR6DJgvWhp6xfRHF5b/cba3iG0ggXtTR6AfM=.5.3sha256/IJPCDSE5tM9H3nuD5m6RU2i9KDdPXVn4qmC/ULlcZzc=.5.3sha256/0Gy8RMdbxHNWR2GQJ62QKDXORYf5JmMmnr1FJFPYpzM=.5.3sha256/8tTICtyaxIQrdbYYDdgZhTN0OpM9kYndvoImtw1Ys5E=.5.3sha256/F7HIlsaG0bpJW8CzYekRbtFqLVTTGqwvuwPDqnlLct0=.5.3sha256/zaV2Aw1A742R1+WpXWvL5atsJbGmeSS6dzZOfe6f1Yw=.5.3sha256/UwOkRGMlP0K/mKNJdpQ0sTg2ean9Tje8UTOvFYzt1GE=.5.3sha256/w7KUXE4/BAo1YVZdO3mBsrMpu4IQuN0mhUXUI//agVU=.5.3sha256/JnPvGqEn36FjHQlBXtG1uWwNtdMj1o2ojR/asqyypNk=.5.3sha256/AUSXlKDCf1X30WhWeAWbjToABfBkJrKWPL6KwEi5VH0=.5.3sha256/zSyVjjFJMIeXK0ktVTIjewwr6U5OePRqyY/nEXTI4P8=.5.3sha256/9dcHlrXN2WV/ehbEdMxMZ8IV4qvGejCtNC5r6nfTviM=.5.3sha256/E+0WZLGSIe5nddlVKZ5fYzaNHHCE3hNqi/OWZD3iKgA=.5.3sha2
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 223
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Mar 14, 2025 01:42:50.679930925 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:42:50.991930962 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:42:51.601330042 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:42:52.804465055 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:42:55.211740017 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:42:58.993451118 CET49709443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:58.993510008 CET4434970923.199.214.10192.168.2.6
                Mar 14, 2025 01:42:58.993581057 CET49709443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:58.996330023 CET49709443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:58.996344090 CET4434970923.199.214.10192.168.2.6
                Mar 14, 2025 01:42:58.997051954 CET4434970923.199.214.10192.168.2.6
                Mar 14, 2025 01:42:58.999334097 CET49710443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:58.999377966 CET44349710142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:58.999579906 CET49710443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:58.999905109 CET49710443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:58.999921083 CET44349710142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:59.000355959 CET49711443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.000387907 CET4434971123.199.214.10192.168.2.6
                Mar 14, 2025 01:42:59.000436068 CET49711443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.001054049 CET49711443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.001066923 CET4434971123.199.214.10192.168.2.6
                Mar 14, 2025 01:42:59.001677990 CET4434971123.199.214.10192.168.2.6
                Mar 14, 2025 01:42:59.002773046 CET49712443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.002794027 CET4434971223.199.214.10192.168.2.6
                Mar 14, 2025 01:42:59.002861977 CET49712443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.003696918 CET49712443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.003731012 CET4434971223.199.214.10192.168.2.6
                Mar 14, 2025 01:42:59.003773928 CET49712443192.168.2.623.199.214.10
                Mar 14, 2025 01:42:59.197338104 CET44349710142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:59.198260069 CET49713443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:59.198299885 CET44349713142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:59.198831081 CET49713443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:59.199290991 CET49713443192.168.2.6142.250.186.164
                Mar 14, 2025 01:42:59.199311018 CET44349713142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:59.267832041 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:42:59.397495985 CET44349713142.250.186.164192.168.2.6
                Mar 14, 2025 01:42:59.570935011 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:42:59.980281115 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:42:59.980460882 CET4971580192.168.2.6185.208.156.194
                Mar 14, 2025 01:42:59.984944105 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:42:59.985011101 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:42:59.985061884 CET8049715185.208.156.194192.168.2.6
                Mar 14, 2025 01:42:59.985446930 CET4971580192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.001104116 CET49716443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.001137018 CET44349716185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.001318932 CET49716443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.001621962 CET49716443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.001636982 CET44349716185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.016138077 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:43:00.183371067 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:43:00.201056957 CET44349716185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.201617002 CET49717443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.201658010 CET44349717185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.201733112 CET49717443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.202219009 CET49717443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.202240944 CET44349717185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.401848078 CET44349717185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.405371904 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.410060883 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.712622881 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.715559006 CET49718443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.715616941 CET44349718185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.715691090 CET49718443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.716006994 CET49718443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.716022015 CET44349718185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.761904001 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.913253069 CET44349718185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.913700104 CET49720443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.913748026 CET44349720185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:00.913815022 CET49720443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.914083004 CET49720443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:00.914103031 CET44349720185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:01.113548994 CET44349720185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:01.388715982 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:43:02.173340082 CET49723443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.173388958 CET44349723185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.173453093 CET49723443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.173666000 CET49724443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.173706055 CET44349724185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.173758984 CET49724443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.174283981 CET49724443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.174298048 CET44349724185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.174611092 CET49723443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.174627066 CET44349723185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.373115063 CET44349723185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.373589993 CET44349724185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.374248981 CET49725443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.374291897 CET44349725185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.374355078 CET49725443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.374562979 CET49726443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.374593973 CET44349726185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.374650002 CET49726443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.374905109 CET49725443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.374919891 CET44349725185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.375124931 CET49726443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:02.375137091 CET44349726185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.573085070 CET44349726185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:02.573111057 CET44349725185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:03.452028990 CET49727443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.452100039 CET44349727142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:03.452218056 CET49727443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.452639103 CET49727443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.452661991 CET44349727142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:03.653400898 CET44349727142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:03.654103994 CET49728443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.654165983 CET44349728142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:03.654243946 CET49728443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.654707909 CET49728443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:03.654725075 CET44349728142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:03.789549112 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:43:03.853241920 CET44349728142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:07.616864920 CET49730443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.616946936 CET44349730185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.617062092 CET49730443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.617137909 CET49731443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.617197037 CET44349731185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.617647886 CET49730443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.617669106 CET44349730185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.617706060 CET49731443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.617966890 CET49731443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.617984056 CET44349731185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.817318916 CET44349731185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.817564011 CET44349730185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.818186998 CET49733443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.818222046 CET44349733185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.818294048 CET49733443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.818599939 CET49734443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.818646908 CET44349734185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.818707943 CET49734443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.818995953 CET49733443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.819010019 CET44349733185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.819247961 CET49734443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:07.819264889 CET44349734185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:07.839266062 CET49735443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.839334965 CET4434973520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.839436054 CET49735443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.840779066 CET49735443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.840802908 CET4434973520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.842503071 CET4434973520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.847831964 CET49736443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.847872972 CET4434973620.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.847942114 CET49736443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.848330975 CET49736443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.848345041 CET4434973620.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.849898100 CET4434973620.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.904643059 CET49737443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.904716015 CET4434973720.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.904819965 CET49737443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.905273914 CET49737443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.905291080 CET4434973720.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.905949116 CET4434973720.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.926227093 CET49738443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.926285028 CET4434973820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.926395893 CET49738443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.926850080 CET49738443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.926867962 CET4434973820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.927432060 CET4434973820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.952673912 CET49739443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.952724934 CET4434973920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.952956915 CET49739443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.953583002 CET49739443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.953594923 CET4434973920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.954294920 CET4434973920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.971250057 CET49740443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.971307993 CET4434974020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.971410990 CET49740443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.971784115 CET49740443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:07.971800089 CET4434974020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:07.972384930 CET4434974020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.017601967 CET44349733185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:08.018496990 CET44349734185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:08.037996054 CET49741443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.038073063 CET4434974120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.038172960 CET49741443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.038491964 CET49741443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.038512945 CET4434974120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.039279938 CET4434974120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.066335917 CET49742443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.066385031 CET4434974220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.066504002 CET49742443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.066936970 CET49742443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:08.066953897 CET4434974220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.067672968 CET4434974220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:08.602634907 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:43:09.617427111 CET49672443192.168.2.6204.79.197.203
                Mar 14, 2025 01:43:15.482119083 CET49745443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.482177973 CET44349745185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.482259989 CET49745443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.482494116 CET49746443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.482542992 CET44349746185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.482593060 CET49746443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.483012915 CET49745443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.483028889 CET44349745185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.483367920 CET49746443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.483385086 CET44349746185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.681324959 CET44349745185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.682003975 CET44349746185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.682046890 CET49747443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.682112932 CET44349747185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.682197094 CET49747443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.682400942 CET49748443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.682441950 CET44349748185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.682488918 CET49748443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.682780981 CET49747443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.682797909 CET44349747185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.683060884 CET49748443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:15.683079958 CET44349748185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.881664991 CET44349748185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:15.881983995 CET44349747185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:18.211574078 CET49678443192.168.2.620.42.65.91
                Mar 14, 2025 01:43:27.602533102 CET49751443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.602571964 CET44349751185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.602663040 CET49751443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.602761984 CET49752443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.602816105 CET44349752185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.602880001 CET49752443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.603072882 CET49751443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.603085041 CET44349751185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.603396893 CET49752443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.603410006 CET44349752185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.801542997 CET44349752185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.802249908 CET49753443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.802298069 CET44349753185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.802392960 CET49753443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.802704096 CET49753443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.802719116 CET44349753185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.809298038 CET44349751185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.809766054 CET49754443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.809808969 CET44349754185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:27.809885979 CET49754443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.810153961 CET49754443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:27.810168028 CET44349754185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:28.001111031 CET44349753185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:28.008980989 CET44349754185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:39.069900990 CET804968384.201.210.23192.168.2.6
                Mar 14, 2025 01:43:39.070151091 CET4968380192.168.2.684.201.210.23
                Mar 14, 2025 01:43:39.070259094 CET4968380192.168.2.684.201.210.23
                Mar 14, 2025 01:43:39.074867010 CET804968384.201.210.23192.168.2.6
                Mar 14, 2025 01:43:41.227705956 CET804968784.201.210.23192.168.2.6
                Mar 14, 2025 01:43:41.227969885 CET4968780192.168.2.684.201.210.23
                Mar 14, 2025 01:43:41.227969885 CET4968780192.168.2.684.201.210.23
                Mar 14, 2025 01:43:41.232772112 CET804968784.201.210.23192.168.2.6
                Mar 14, 2025 01:43:41.305269957 CET4968580192.168.2.6142.250.184.227
                Mar 14, 2025 01:43:41.310209990 CET8049685142.250.184.227192.168.2.6
                Mar 14, 2025 01:43:41.310283899 CET4968580192.168.2.6142.250.184.227
                Mar 14, 2025 01:43:41.494565964 CET804968884.201.210.23192.168.2.6
                Mar 14, 2025 01:43:41.494860888 CET4968880192.168.2.684.201.210.23
                Mar 14, 2025 01:43:42.667670965 CET49686443192.168.2.623.15.178.234
                Mar 14, 2025 01:43:42.668318033 CET4968880192.168.2.684.201.210.23
                Mar 14, 2025 01:43:42.668380976 CET4968980192.168.2.62.23.77.188
                Mar 14, 2025 01:43:44.419266939 CET49758443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.419321060 CET4434975820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.419411898 CET49758443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.419794083 CET49758443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.419804096 CET4434975820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.420448065 CET4434975820.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.423882008 CET49759443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.423933983 CET4434975920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.424009085 CET49759443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.425082922 CET49759443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.425096989 CET4434975920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.425565958 CET4434975920.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.450000048 CET49760443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.450010061 CET4434976020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.450078964 CET49760443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.450303078 CET49760443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.450313091 CET4434976020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.450705051 CET4434976020.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.452094078 CET49761443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.452128887 CET4434976120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.452214003 CET49761443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.452406883 CET49761443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.452440977 CET4434976120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.452816963 CET4434976120.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.501802921 CET49762443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.501904964 CET4434976220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.501985073 CET49762443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.502293110 CET49762443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.502320051 CET4434976220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.502863884 CET4434976220.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.505887032 CET49763443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.505929947 CET4434976320.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.505990982 CET49763443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.506283998 CET49763443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.506297112 CET4434976320.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.506694078 CET4434976320.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.542231083 CET49764443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.542244911 CET4434976420.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.542325020 CET49764443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.542625904 CET49764443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.542634964 CET4434976420.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.543075085 CET4434976420.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.560728073 CET49765443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.560766935 CET4434976520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.560828924 CET49765443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.561089039 CET49765443192.168.2.620.12.23.50
                Mar 14, 2025 01:43:44.561095953 CET4434976520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.561454058 CET4434976520.12.23.50192.168.2.6
                Mar 14, 2025 01:43:44.992482901 CET4971580192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:44.997245073 CET8049715185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:45.726958990 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:45.731699944 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:57.031552076 CET5559953192.168.2.61.1.1.1
                Mar 14, 2025 01:43:57.036339998 CET53555991.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.036479950 CET5559953192.168.2.61.1.1.1
                Mar 14, 2025 01:43:57.041285992 CET53555991.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.490672112 CET5559953192.168.2.61.1.1.1
                Mar 14, 2025 01:43:57.495590925 CET53555991.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.495768070 CET5559953192.168.2.61.1.1.1
                Mar 14, 2025 01:43:58.034843922 CET55601443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.034893990 CET44355601185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.034967899 CET55601443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.035121918 CET55602443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.035173893 CET44355602185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.035218000 CET55602443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.035543919 CET55601443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.035557032 CET44355601185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.035818100 CET55602443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.035830975 CET44355602185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.232898951 CET44355601185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.233705997 CET44355602185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.234026909 CET55603443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.234060049 CET44355603185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.234118938 CET55603443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.234673977 CET55604443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.234704018 CET44355604185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.234750986 CET55604443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.235225916 CET55603443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.235240936 CET44355603185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.235905886 CET55604443192.168.2.6185.208.156.194
                Mar 14, 2025 01:43:58.235920906 CET44355604185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.433878899 CET44355604185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:58.433908939 CET44355603185.208.156.194192.168.2.6
                Mar 14, 2025 01:43:59.025584936 CET55605443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.025619030 CET44355605142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:59.025696039 CET55605443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.026081085 CET55605443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.026092052 CET44355605142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:59.225649118 CET44355605142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:59.228854895 CET55606443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.228909016 CET44355606142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:59.228971004 CET55606443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.229990005 CET55606443192.168.2.6142.250.186.164
                Mar 14, 2025 01:43:59.230005980 CET44355606142.250.186.164192.168.2.6
                Mar 14, 2025 01:43:59.429459095 CET44355606142.250.186.164192.168.2.6
                Mar 14, 2025 01:44:00.637892962 CET8049715185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:00.637996912 CET4971580192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:01.622075081 CET4971580192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:01.626986027 CET8049715185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:05.858417988 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:05.858499050 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:07.620290995 CET4971480192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:07.625052929 CET8049714185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.563992977 CET55609443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564043999 CET44355609185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.564127922 CET55609443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564210892 CET55610443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564241886 CET44355610185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.564301968 CET55610443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564547062 CET55609443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564564943 CET44355609185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.564822912 CET55610443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.564838886 CET44355610185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.765582085 CET44355610185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.766355991 CET55611443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.766407013 CET44355611185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.766499043 CET44355609185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.766510010 CET55611443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.766953945 CET55611443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.766972065 CET44355611185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.767158985 CET55612443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.767210960 CET44355612185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.767316103 CET55612443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.767976999 CET55612443192.168.2.6185.208.156.194
                Mar 14, 2025 01:44:08.767999887 CET44355612185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.965681076 CET44355611185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:08.965948105 CET44355612185.208.156.194192.168.2.6
                Mar 14, 2025 01:44:09.537386894 CET443496812.23.227.215192.168.2.6
                Mar 14, 2025 01:44:09.537503004 CET49681443192.168.2.62.23.227.215
                Mar 14, 2025 01:44:09.538249016 CET443496812.23.227.215192.168.2.6
                Mar 14, 2025 01:44:09.538305998 CET49681443192.168.2.62.23.227.215
                TimestampSource PortDest PortSource IPDest IP
                Mar 14, 2025 01:42:54.365869999 CET53517181.1.1.1192.168.2.6
                Mar 14, 2025 01:42:54.399760008 CET53597261.1.1.1192.168.2.6
                Mar 14, 2025 01:42:58.990766048 CET5003653192.168.2.61.1.1.1
                Mar 14, 2025 01:42:58.991383076 CET5206053192.168.2.61.1.1.1
                Mar 14, 2025 01:42:58.997634888 CET53500361.1.1.1192.168.2.6
                Mar 14, 2025 01:42:58.998058081 CET53520601.1.1.1192.168.2.6
                Mar 14, 2025 01:42:59.950376987 CET5986053192.168.2.61.1.1.1
                Mar 14, 2025 01:42:59.960616112 CET5136853192.168.2.61.1.1.1
                Mar 14, 2025 01:42:59.962234974 CET53598601.1.1.1192.168.2.6
                Mar 14, 2025 01:42:59.972851038 CET53513681.1.1.1192.168.2.6
                Mar 14, 2025 01:42:59.984540939 CET5097653192.168.2.61.1.1.1
                Mar 14, 2025 01:42:59.984827995 CET5105653192.168.2.61.1.1.1
                Mar 14, 2025 01:42:59.995209932 CET53510561.1.1.1192.168.2.6
                Mar 14, 2025 01:42:59.998097897 CET53509761.1.1.1192.168.2.6
                Mar 14, 2025 01:43:54.253299952 CET53640411.1.1.1192.168.2.6
                Mar 14, 2025 01:43:54.670835018 CET53553441.1.1.1192.168.2.6
                Mar 14, 2025 01:43:55.628813982 CET53534211.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.030725002 CET53526911.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.342449903 CET138138192.168.2.6192.168.2.255
                Mar 14, 2025 01:43:57.638015032 CET5018553192.168.2.61.1.1.1
                Mar 14, 2025 01:43:57.638339996 CET4938253192.168.2.61.1.1.1
                Mar 14, 2025 01:43:57.644704103 CET53501851.1.1.1192.168.2.6
                Mar 14, 2025 01:43:57.647150993 CET53493821.1.1.1192.168.2.6
                Mar 14, 2025 01:43:58.662455082 CET5190053192.168.2.61.1.1.1
                Mar 14, 2025 01:43:58.671171904 CET53519001.1.1.1192.168.2.6
                Mar 14, 2025 01:43:58.688164949 CET5934353192.168.2.61.1.1.1
                Mar 14, 2025 01:43:58.695075989 CET53593431.1.1.1192.168.2.6
                Mar 14, 2025 01:44:00.698355913 CET6515553192.168.2.61.1.1.1
                Mar 14, 2025 01:44:00.705809116 CET53651551.1.1.1192.168.2.6
                Mar 14, 2025 01:44:01.711595058 CET6515553192.168.2.61.1.1.1
                Mar 14, 2025 01:44:01.718195915 CET53651551.1.1.1192.168.2.6
                Mar 14, 2025 01:44:02.711790085 CET6515553192.168.2.61.1.1.1
                Mar 14, 2025 01:44:02.718415022 CET53651551.1.1.1192.168.2.6
                Mar 14, 2025 01:44:04.727701902 CET6515553192.168.2.61.1.1.1
                Mar 14, 2025 01:44:04.734308958 CET53651551.1.1.1192.168.2.6
                Mar 14, 2025 01:44:08.736987114 CET6515553192.168.2.61.1.1.1
                Mar 14, 2025 01:44:08.745434046 CET53651551.1.1.1192.168.2.6
                Mar 14, 2025 01:44:13.630847931 CET5323653192.168.2.61.1.1.1
                Mar 14, 2025 01:44:13.631021976 CET6485653192.168.2.61.1.1.1
                Mar 14, 2025 01:44:13.637675047 CET53532361.1.1.1192.168.2.6
                Mar 14, 2025 01:44:13.638303041 CET53648561.1.1.1192.168.2.6
                Mar 14, 2025 01:44:14.649234056 CET6218153192.168.2.61.1.1.1
                Mar 14, 2025 01:44:14.655972958 CET53621811.1.1.1192.168.2.6
                Mar 14, 2025 01:44:16.680591106 CET5291453192.168.2.61.1.1.1
                Mar 14, 2025 01:44:16.688138008 CET53529141.1.1.1192.168.2.6
                Mar 14, 2025 01:44:17.680053949 CET5291453192.168.2.61.1.1.1
                Mar 14, 2025 01:44:17.687017918 CET53529141.1.1.1192.168.2.6
                Mar 14, 2025 01:44:18.679996014 CET5291453192.168.2.61.1.1.1
                Mar 14, 2025 01:44:18.686844110 CET53529141.1.1.1192.168.2.6
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 14, 2025 01:42:58.990766048 CET192.168.2.61.1.1.10x4c0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:42:58.991383076 CET192.168.2.61.1.1.10xa517Standard query (0)www.google.com65IN (0x0001)false
                Mar 14, 2025 01:42:59.950376987 CET192.168.2.61.1.1.10xfa64Standard query (0)s.team-fg.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:42:59.960616112 CET192.168.2.61.1.1.10x3fadStandard query (0)s.team-fg.com65IN (0x0001)false
                Mar 14, 2025 01:42:59.984540939 CET192.168.2.61.1.1.10x86e4Standard query (0)s.team-fg.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:42:59.984827995 CET192.168.2.61.1.1.10xac42Standard query (0)s.team-fg.com65IN (0x0001)false
                Mar 14, 2025 01:43:57.638015032 CET192.168.2.61.1.1.10x278bStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:43:57.638339996 CET192.168.2.61.1.1.10x77f5Standard query (0)beacons.gcp.gvt2.com65IN (0x0001)false
                Mar 14, 2025 01:43:58.662455082 CET192.168.2.61.1.1.10x1c15Standard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:43:58.688164949 CET192.168.2.61.1.1.10x628bStandard query (0)beacons.gcp.gvt2.com65IN (0x0001)false
                Mar 14, 2025 01:44:00.698355913 CET192.168.2.61.1.1.10xbe0fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:01.711595058 CET192.168.2.61.1.1.10xbe0fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:02.711790085 CET192.168.2.61.1.1.10xbe0fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:04.727701902 CET192.168.2.61.1.1.10xbe0fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:08.736987114 CET192.168.2.61.1.1.10xbe0fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:13.630847931 CET192.168.2.61.1.1.10x6133Standard query (0)beacons.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:13.631021976 CET192.168.2.61.1.1.10xf1cStandard query (0)beacons.gvt2.com65IN (0x0001)false
                Mar 14, 2025 01:44:14.649234056 CET192.168.2.61.1.1.10x7cd8Standard query (0)beacons.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:16.680591106 CET192.168.2.61.1.1.10xca92Standard query (0)beacons.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:17.680053949 CET192.168.2.61.1.1.10xca92Standard query (0)beacons.gvt2.comA (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:18.679996014 CET192.168.2.61.1.1.10xca92Standard query (0)beacons.gvt2.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 14, 2025 01:42:58.997634888 CET1.1.1.1192.168.2.60x4c0No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                Mar 14, 2025 01:42:58.998058081 CET1.1.1.1192.168.2.60xa517No error (0)www.google.com65IN (0x0001)false
                Mar 14, 2025 01:42:59.962234974 CET1.1.1.1192.168.2.60xfa64No error (0)s.team-fg.com185.208.156.194A (IP address)IN (0x0001)false
                Mar 14, 2025 01:42:59.998097897 CET1.1.1.1192.168.2.60x86e4No error (0)s.team-fg.com185.208.156.194A (IP address)IN (0x0001)false
                Mar 14, 2025 01:43:57.644704103 CET1.1.1.1192.168.2.60x278bNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:43:57.644704103 CET1.1.1.1192.168.2.60x278bNo error (0)beacons-handoff.gcp.gvt2.com142.250.180.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:43:57.647150993 CET1.1.1.1192.168.2.60x77f5No error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:43:58.671171904 CET1.1.1.1192.168.2.60x1c15No error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:43:58.671171904 CET1.1.1.1192.168.2.60x1c15No error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:43:58.695075989 CET1.1.1.1192.168.2.60x628bNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:00.705809116 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:00.705809116 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:01.718195915 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:01.718195915 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:02.718415022 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:02.718415022 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:04.734308958 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:04.734308958 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:08.745434046 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:08.745434046 CET1.1.1.1192.168.2.60xbe0fNo error (0)beacons-handoff.gcp.gvt2.com142.251.143.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:13.637675047 CET1.1.1.1192.168.2.60x6133No error (0)beacons.gvt2.com142.251.143.35A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:14.655972958 CET1.1.1.1192.168.2.60x7cd8No error (0)beacons.gvt2.com142.250.180.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:16.688138008 CET1.1.1.1192.168.2.60xca92No error (0)beacons.gvt2.combeacons6.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:16.688138008 CET1.1.1.1192.168.2.60xca92No error (0)beacons6.gvt2.com142.250.185.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:17.687017918 CET1.1.1.1192.168.2.60xca92No error (0)beacons.gvt2.combeacons6.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:17.687017918 CET1.1.1.1192.168.2.60xca92No error (0)beacons6.gvt2.com142.250.185.67A (IP address)IN (0x0001)false
                Mar 14, 2025 01:44:18.686844110 CET1.1.1.1192.168.2.60xca92No error (0)beacons.gvt2.combeacons6.gvt2.comCNAME (Canonical name)IN (0x0001)false
                Mar 14, 2025 01:44:18.686844110 CET1.1.1.1192.168.2.60xca92No error (0)beacons6.gvt2.com142.250.185.67A (IP address)IN (0x0001)false
                • s.team-fg.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.649714185.208.156.194804116C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Mar 14, 2025 01:43:00.405371904 CET449OUTGET /p/jjnh-trfg/frmkhpcw/ HTTP/1.1
                Host: s.team-fg.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Mar 14, 2025 01:43:00.712622881 CET387INHTTP/1.1 301 Moved Permanently
                Server: nginx/1.26.3
                Date: Fri, 14 Mar 2025 00:43:00 GMT
                Content-Type: text/html
                Content-Length: 169
                Connection: keep-alive
                Location: https://s.team-fg.com/p/jjnh-trfg/frmkhpcw/
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 36 2e 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx/1.26.3</center></body></html>
                Mar 14, 2025 01:43:45.726958990 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.649715185.208.156.194804116C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Mar 14, 2025 01:43:44.992482901 CET6OUTData Raw: 00
                Data Ascii:


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:1
                Start time:20:42:48
                Start date:13/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:4
                Start time:20:42:52
                Start date:13/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,11247473949130860856,15678733379132640968,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2024 /prefetch:3
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:13
                Start time:20:42:58
                Start date:13/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://s.team-fg.com/p/jjnh-trfg/frmkhpcw/"
                Imagebase:0x7ff63b000000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly