Edit tour

Windows Analysis Report
http://www.greendon.com/

Overview

General Information

Sample URL:http://www.greendon.com/
Analysis ID:1649446
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

AI detected suspicious Javascript
AI detected suspicious URL
Creates files inside the system directory
Deletes files inside the Windows folder
Detected suspicious crossdomain redirect

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2452,i,10469626583534396515,15961310552530522455,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2464 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6772 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.greendon.com/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: 0.0..script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://www.greendon.com/... This script exhibits high-risk behaviors, including the use of obfuscated URLs and potential data exfiltration. The combination of redirecting the user to an unknown domain (greendon.com) and the presence of a suspicious-looking JWT token in the URL suggests this script may be part of a phishing or malicious campaign. The high risk score reflects the potential for user harm and the need for further investigation.
Source: http://www.toroexoclk.comJoe Sandbox AI: The URL 'toroexoclk.com' appears to be a typosquatting attempt on the well-known brand 'Rolex'. The legitimate URL for Rolex is 'rolex.com'. The analyzed URL uses character substitutions and reordering: 'r' is replaced with 't', 'l' is replaced with 'c', and 'k' is added at the end. These changes create a visual similarity to 'rolex.com'. The domain does not suggest a different legitimate purpose and is likely intended to confuse users into thinking it is associated with Rolex. The use of '.com' as the top-level domain further increases the likelihood of user confusion.
Source: http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0HTTP Parser: No favicon
Source: http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.251.40.228:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 95.211.219.66:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.248.224.96:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.94.215.122:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.22.7.178:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: www.greendon.com to http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: www.toroexoclk.com to https://saltandsalad.com/chromet?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.80.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.80.67
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.greendon.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMG82czRyYWQwNjhjMnNnY3MwZXRlMjQiLCJuYmYiOjE3NDMwMTQwODUsInRzIjoxNzQzMDE0MDg1NDYwOTYzfQ.e4qEmZrqAJFR3xACIdhwdOF9e4UC9y_mFiI4U-uelfg&sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e HTTP/1.1Host: www.greendon.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.greendon.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e
Source: global trafficHTTP traffic detected: GET /feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0 HTTP/1.1Host: www.toroexoclk.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chromeT?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1Host: saltandsalad.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chromeT/?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1Host: saltandsalad.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /store/serious-mass.html/?bid={bid}&clickid={conversion}&pubfeed_subid={pubfeed}_{subid}&campaign={campaign}&offer={offer}&carrier={carrier}&os={os}&user_agent={user_agent}&ip={ip}&device_type={device_type}&referrer_domain={referrer_domain}&click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1Host: www.muscleandstrength.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0 HTTP/1.1Host: www.toroexoclk.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.toroexoclk.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.greendon.com
Source: global trafficDNS traffic detected: DNS query: www.toroexoclk.com
Source: global trafficDNS traffic detected: DNS query: saltandsalad.com
Source: global trafficDNS traffic detected: DNS query: www.muscleandstrength.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Wed, 26 Mar 2025 18:34:49 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeaccept-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UAcf-mitigated: challengecritical-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UAcross-origin-embedder-policy: require-corpcross-origin-opener-policy: same-origincross-origin-resource-policy: same-originorigin-agent-cluster: ?1permissions-policy: accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()referrer-policy: same-originserver-timing: chlray;desc="9268be8daaa78cb3"x-content-options: nosniffx-frame-options: SAMEORIGIN
Source: chromecache_52.2.drString found in binary or memory: https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6M
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 142.251.40.228:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 95.211.219.66:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.248.224.96:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.94.215.122:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.22.7.178:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir2420_108159913Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir2420_108159913Jump to behavior
Source: classification engineClassification label: mal48.win@23/2@14/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2452,i,10469626583534396515,15961310552530522455,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2464 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.greendon.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2452,i,10469626583534396515,15961310552530522455,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2464 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1649446 URL: http://www.greendon.com/ Startdate: 26/03/2025 Architecture: WINDOWS Score: 48 24 AI detected suspicious Javascript 2->24 26 AI detected suspicious URL 2->26 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49714 unknown unknown 6->14 16 192.168.2.6 unknown unknown 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.greendon.com 95.211.219.66, 443, 49730, 49731 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 11->18 20 saltandsalad.com 184.94.215.122, 443, 49739, 49740 VXCHNGE-NC01US United States 11->20 22 3 other IPs or domains 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.greendon.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMG82czRyYWQwNjhjMnNnY3MwZXRlMjQiLCJuYmYiOjE3NDMwMTQwODUsInRzIjoxNzQzMDE0MDg1NDYwOTYzfQ.e4qEmZrqAJFR3xACIdhwdOF9e4UC9y_mFiI4U-uelfg&sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e0%Avira URL Cloudsafe
https://saltandsalad.com/chromeT?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&9690%Avira URL Cloudsafe
https://saltandsalad.com/chromeT/?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&9690%Avira URL Cloudsafe
https://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b00%Avira URL Cloudsafe
https://www.greendon.com/0%Avira URL Cloudsafe
http://www.toroexoclk.com/favicon.ico0%Avira URL Cloudsafe
https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6M0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.greendon.com
95.211.219.66
truetrue
    unknown
    www.muscleandstrength.com
    104.22.7.178
    truefalse
      high
      www.google.com
      142.251.40.228
      truefalse
        high
        www.toroexoclk.com
        104.248.224.96
        truefalse
          high
          saltandsalad.com
          184.94.215.122
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://saltandsalad.com/chromeT?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969false
            • Avira URL Cloud: safe
            unknown
            https://www.muscleandstrength.com/store/serious-mass.html/?bid={bid}&clickid={conversion}&pubfeed_subid={pubfeed}_{subid}&campaign={campaign}&offer={offer}&carrier={carrier}&os={os}&user_agent={user_agent}&ip={ip}&device_type={device_type}&referrer_domain={referrer_domain}&click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969false
              high
              https://www.greendon.com/true
              • Avira URL Cloud: safe
              unknown
              https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMG82czRyYWQwNjhjMnNnY3MwZXRlMjQiLCJuYmYiOjE3NDMwMTQwODUsInRzIjoxNzQzMDE0MDg1NDYwOTYzfQ.e4qEmZrqAJFR3xACIdhwdOF9e4UC9y_mFiI4U-uelfg&sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8efalse
              • Avira URL Cloud: safe
              unknown
              https://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0false
              • Avira URL Cloud: safe
              unknown
              https://saltandsalad.com/chromeT/?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969false
              • Avira URL Cloud: safe
              unknown
              http://www.toroexoclk.com/favicon.icotrue
              • Avira URL Cloud: safe
              unknown
              http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0true
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6Mchromecache_52.2.drfalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                184.94.215.122
                saltandsalad.comUnited States
                394896VXCHNGE-NC01USfalse
                104.22.7.178
                www.muscleandstrength.comUnited States
                13335CLOUDFLARENETUSfalse
                104.248.224.96
                www.toroexoclk.comUnited States
                14061DIGITALOCEAN-ASNUSfalse
                95.211.219.66
                www.greendon.comNetherlands
                60781LEASEWEB-NL-AMS-01NetherlandsNLtrue
                142.251.40.228
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                192.168.2.6
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1649446
                Start date and time:2025-03-26 19:33:39 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 5s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://www.greendon.com/
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:20
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@23/2@14/7
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.72.110, 142.250.65.227, 172.253.122.84, 142.250.80.78, 142.250.176.195, 23.9.183.29, 20.12.23.50
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: http://www.greendon.com/
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with very long lines (478), with no line terminators
                Category:downloaded
                Size (bytes):478
                Entropy (8bit):5.831258948220251
                Encrypted:false
                SSDEEP:12:kxvsCk9cE3MJS/XUIfeyJ7cYpxpTWEUdN3ozVEZkYI:kbxs/kIfeEGd9+CI
                MD5:389A6D57D704002440495E20918828BF
                SHA1:778D12BAA52330F7F4048AC27E62DF8F739E00C1
                SHA-256:C321C18B384DB881BF43A73104EF11C59AF9A0A180504EE3291E1E4E2DEB405C
                SHA-512:8F32D02AE0C4041D125FEE7B95E7110981ABD885678FD438892EADDC51BFBC71BC87331B77D064549B18B5DE47AB6F54B5E3636FD570C325E19DED997D52F3CF
                Malicious:false
                Reputation:low
                URL:https://www.greendon.com/
                Preview:<html><head><title>Loading...</title></head><body><script type='text/javascript'>window.location.replace('https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMG82czRyYWQwNjhjMnNnY3MwZXRlMjQiLCJuYmYiOjE3NDMwMTQwODUsInRzIjoxNzQzMDE0MDg1NDYwOTYzfQ.e4qEmZrqAJFR3xACIdhwdOF9e4UC9y_mFiI4U-uelfg&sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e');</script></body></html>
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 132
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Mar 26, 2025 19:34:30.696722031 CET49680443192.168.2.4204.79.197.222
                Mar 26, 2025 19:34:31.743761063 CET4968180192.168.2.42.17.190.73
                Mar 26, 2025 19:34:37.394124031 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:37.696707010 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:38.384227037 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:39.587342024 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:40.306132078 CET49680443192.168.2.4204.79.197.222
                Mar 26, 2025 19:34:41.353032112 CET4968180192.168.2.42.17.190.73
                Mar 26, 2025 19:34:42.065778017 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:43.552155018 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:43.552189112 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:43.552450895 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:43.552614927 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:43.552628040 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:43.755786896 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:43.755894899 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:43.758584023 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:43.758596897 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:43.758938074 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:43.805591106 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:44.778178930 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.778239965 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:44.778357029 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.778564930 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.778580904 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:44.809261084 CET4973180192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.809581041 CET4973280192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.986217022 CET804973295.211.219.66192.168.2.4
                Mar 26, 2025 19:34:44.986293077 CET4973280192.168.2.495.211.219.66
                Mar 26, 2025 19:34:44.987207890 CET804973195.211.219.66192.168.2.4
                Mar 26, 2025 19:34:44.988274097 CET4973180192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.353410006 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.353491068 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.359601021 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.359612942 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.359857082 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.360186100 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.404278994 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.547665119 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.547741890 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.548006058 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.637115002 CET49730443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.637144089 CET4434973095.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.639842033 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.639873981 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.639983892 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.640511990 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.640511990 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.640527010 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.640548944 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:45.640681028 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.640855074 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:45.640863895 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.012224913 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.012494087 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:46.012511015 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.012702942 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:46.012707949 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.017024994 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.017277956 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:46.017297029 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:46.089732885 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:46.389100075 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:46.873917103 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:46.992994070 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:47.051981926 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:47.052057028 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:47.052107096 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:47.052726984 CET49736443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:47.052746058 CET4434973695.211.219.66192.168.2.4
                Mar 26, 2025 19:34:47.157150030 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.157191992 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.157274961 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.157618999 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.157629013 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.347750902 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.347846985 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.349001884 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.349011898 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.349328041 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.349550962 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.349559069 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.599247932 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.599325895 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.599419117 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.623358011 CET49738443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:47.623380899 CET44349738104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:47.733633041 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:47.733681917 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:47.733968019 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:47.735766888 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:47.735783100 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.057631969 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.057763100 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.059073925 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.059083939 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.059323072 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.059669971 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.100275993 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.194760084 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:48.362581015 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.362656116 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.362699986 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.363126040 CET49739443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.363152027 CET44349739184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.365298986 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.365331888 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.365396023 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.365510941 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.365518093 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.680566072 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.681061983 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.681082010 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:48.681555986 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:48.681562901 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:49.353501081 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:49.355716944 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:49.355778933 CET44349740184.94.215.122192.168.2.4
                Mar 26, 2025 19:34:49.355941057 CET49740443192.168.2.4184.94.215.122
                Mar 26, 2025 19:34:49.495043039 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.495076895 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.495316029 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.495316029 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.495343924 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.690954924 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.691049099 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.696912050 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.696934938 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.697171926 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.697757959 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.740264893 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918617010 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918723106 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918761015 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918776035 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.918788910 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918800116 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.918839931 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.919178009 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919209003 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919225931 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.919241905 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919275999 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919291019 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.919300079 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919341087 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.919349909 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919363022 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.919406891 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.920171976 CET49741443192.168.2.4104.22.7.178
                Mar 26, 2025 19:34:49.920186996 CET44349741104.22.7.178192.168.2.4
                Mar 26, 2025 19:34:49.922828913 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:49.922863960 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:49.922930002 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:49.923060894 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:49.923068047 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.112955093 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.113289118 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.113310099 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.154047012 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.166637897 CET804973295.211.219.66192.168.2.4
                Mar 26, 2025 19:34:50.166722059 CET4973280192.168.2.495.211.219.66
                Mar 26, 2025 19:34:50.168934107 CET804973195.211.219.66192.168.2.4
                Mar 26, 2025 19:34:50.168984890 CET4973180192.168.2.495.211.219.66
                Mar 26, 2025 19:34:50.246033907 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.246118069 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.246387005 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.339374065 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.366473913 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.417011023 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.481975079 CET4973280192.168.2.495.211.219.66
                Mar 26, 2025 19:34:50.482013941 CET4973180192.168.2.495.211.219.66
                Mar 26, 2025 19:34:50.482146978 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.577991962 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.578752041 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:50.606841087 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:50.622225046 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:50.662687063 CET804973295.211.219.66192.168.2.4
                Mar 26, 2025 19:34:50.662707090 CET804973195.211.219.66192.168.2.4
                Mar 26, 2025 19:34:51.211442947 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:51.211517096 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:51.211699963 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:51.340795994 CET49735443192.168.2.495.211.219.66
                Mar 26, 2025 19:34:51.340831995 CET4434973595.211.219.66192.168.2.4
                Mar 26, 2025 19:34:53.783415079 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:53.783469915 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:53.783530951 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:55.338931084 CET49729443192.168.2.4142.251.40.228
                Mar 26, 2025 19:34:55.338970900 CET44349729142.251.40.228192.168.2.4
                Mar 26, 2025 19:34:55.415462017 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:34:56.477988958 CET49671443192.168.2.4204.79.197.203
                Mar 26, 2025 19:34:56.578954935 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:34:56.579021931 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:57.338818073 CET4974380192.168.2.4104.248.224.96
                Mar 26, 2025 19:34:57.430485010 CET8049743104.248.224.96192.168.2.4
                Mar 26, 2025 19:35:05.027000904 CET49678443192.168.2.420.189.173.27
                Mar 26, 2025 19:35:23.572760105 CET4971580192.168.2.4142.250.80.67
                Mar 26, 2025 19:35:23.572966099 CET4971480192.168.2.423.210.73.5
                Mar 26, 2025 19:35:23.573029041 CET4971680192.168.2.423.210.73.5
                Mar 26, 2025 19:35:23.663353920 CET8049715142.250.80.67192.168.2.4
                Mar 26, 2025 19:35:23.663417101 CET4971580192.168.2.4142.250.80.67
                Mar 26, 2025 19:35:23.663878918 CET804971423.210.73.5192.168.2.4
                Mar 26, 2025 19:35:23.663928986 CET4971480192.168.2.423.210.73.5
                Mar 26, 2025 19:35:23.664175034 CET804971623.210.73.5192.168.2.4
                Mar 26, 2025 19:35:23.664266109 CET4971680192.168.2.423.210.73.5
                Mar 26, 2025 19:35:35.119354963 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:35:35.119364977 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:35:43.526546001 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:43.526592016 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:43.526665926 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:43.526846886 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:43.526863098 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:43.715437889 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:43.715975046 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:43.716012955 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:51.340183020 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:35:51.340297937 CET44349742104.248.224.96192.168.2.4
                Mar 26, 2025 19:35:51.340383053 CET49742443192.168.2.4104.248.224.96
                Mar 26, 2025 19:35:53.734023094 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:53.734077930 CET44349753142.251.40.228192.168.2.4
                Mar 26, 2025 19:35:53.734143972 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:55.340543032 CET49753443192.168.2.4142.251.40.228
                Mar 26, 2025 19:35:55.340569973 CET44349753142.251.40.228192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Mar 26, 2025 19:34:39.646071911 CET53549101.1.1.1192.168.2.4
                Mar 26, 2025 19:34:39.646389961 CET53497841.1.1.1192.168.2.4
                Mar 26, 2025 19:34:39.867089987 CET53504301.1.1.1192.168.2.4
                Mar 26, 2025 19:34:40.339107037 CET53497491.1.1.1192.168.2.4
                Mar 26, 2025 19:34:43.462835073 CET5577553192.168.2.41.1.1.1
                Mar 26, 2025 19:34:43.463005066 CET6109353192.168.2.41.1.1.1
                Mar 26, 2025 19:34:43.550915956 CET53557751.1.1.1192.168.2.4
                Mar 26, 2025 19:34:43.551023960 CET53610931.1.1.1192.168.2.4
                Mar 26, 2025 19:34:44.586751938 CET5129453192.168.2.41.1.1.1
                Mar 26, 2025 19:34:44.587084055 CET5630153192.168.2.41.1.1.1
                Mar 26, 2025 19:34:44.600795984 CET5579553192.168.2.41.1.1.1
                Mar 26, 2025 19:34:44.601058006 CET5304053192.168.2.41.1.1.1
                Mar 26, 2025 19:34:44.754857063 CET53530401.1.1.1192.168.2.4
                Mar 26, 2025 19:34:44.754873991 CET53563011.1.1.1192.168.2.4
                Mar 26, 2025 19:34:44.777498960 CET53557951.1.1.1192.168.2.4
                Mar 26, 2025 19:34:44.777546883 CET53512941.1.1.1192.168.2.4
                Mar 26, 2025 19:34:47.060152054 CET5975953192.168.2.41.1.1.1
                Mar 26, 2025 19:34:47.060321093 CET6099453192.168.2.41.1.1.1
                Mar 26, 2025 19:34:47.152956009 CET53597591.1.1.1192.168.2.4
                Mar 26, 2025 19:34:47.156748056 CET53609941.1.1.1192.168.2.4
                Mar 26, 2025 19:34:47.626018047 CET5263553192.168.2.41.1.1.1
                Mar 26, 2025 19:34:47.626364946 CET5548953192.168.2.41.1.1.1
                Mar 26, 2025 19:34:47.718230963 CET53554891.1.1.1192.168.2.4
                Mar 26, 2025 19:34:47.723885059 CET53526351.1.1.1192.168.2.4
                Mar 26, 2025 19:34:49.355721951 CET5386653192.168.2.41.1.1.1
                Mar 26, 2025 19:34:49.355824947 CET6472553192.168.2.41.1.1.1
                Mar 26, 2025 19:34:49.489105940 CET53538661.1.1.1192.168.2.4
                Mar 26, 2025 19:34:49.494411945 CET53647251.1.1.1192.168.2.4
                Mar 26, 2025 19:34:50.064982891 CET6286153192.168.2.41.1.1.1
                Mar 26, 2025 19:34:50.065174103 CET6065953192.168.2.41.1.1.1
                Mar 26, 2025 19:34:50.153223991 CET53628611.1.1.1192.168.2.4
                Mar 26, 2025 19:34:50.153357029 CET53606591.1.1.1192.168.2.4
                Mar 26, 2025 19:34:57.426995039 CET53592311.1.1.1192.168.2.4
                Mar 26, 2025 19:35:16.181325912 CET53568031.1.1.1192.168.2.4
                Mar 26, 2025 19:35:17.583950996 CET5358845162.159.36.2192.168.2.4
                Mar 26, 2025 19:35:38.870840073 CET53570541.1.1.1192.168.2.4
                Mar 26, 2025 19:35:39.021372080 CET53539581.1.1.1192.168.2.4
                Mar 26, 2025 19:35:45.734808922 CET138138192.168.2.4192.168.2.255
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 26, 2025 19:34:43.462835073 CET192.168.2.41.1.1.10x543fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:43.463005066 CET192.168.2.41.1.1.10xcd3cStandard query (0)www.google.com65IN (0x0001)false
                Mar 26, 2025 19:34:44.586751938 CET192.168.2.41.1.1.10xc06eStandard query (0)www.greendon.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:44.587084055 CET192.168.2.41.1.1.10x1795Standard query (0)www.greendon.com65IN (0x0001)false
                Mar 26, 2025 19:34:44.600795984 CET192.168.2.41.1.1.10x8d0aStandard query (0)www.greendon.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:44.601058006 CET192.168.2.41.1.1.10xd38dStandard query (0)www.greendon.com65IN (0x0001)false
                Mar 26, 2025 19:34:47.060152054 CET192.168.2.41.1.1.10xabdfStandard query (0)www.toroexoclk.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:47.060321093 CET192.168.2.41.1.1.10x8a2eStandard query (0)www.toroexoclk.com65IN (0x0001)false
                Mar 26, 2025 19:34:47.626018047 CET192.168.2.41.1.1.10x7cfbStandard query (0)saltandsalad.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:47.626364946 CET192.168.2.41.1.1.10x1730Standard query (0)saltandsalad.com65IN (0x0001)false
                Mar 26, 2025 19:34:49.355721951 CET192.168.2.41.1.1.10xc890Standard query (0)www.muscleandstrength.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:49.355824947 CET192.168.2.41.1.1.10xcbc2Standard query (0)www.muscleandstrength.com65IN (0x0001)false
                Mar 26, 2025 19:34:50.064982891 CET192.168.2.41.1.1.10xabacStandard query (0)www.toroexoclk.comA (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:50.065174103 CET192.168.2.41.1.1.10xa474Standard query (0)www.toroexoclk.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 26, 2025 19:34:43.550915956 CET1.1.1.1192.168.2.40x543fNo error (0)www.google.com142.251.40.228A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:43.551023960 CET1.1.1.1192.168.2.40xcd3cNo error (0)www.google.com65IN (0x0001)false
                Mar 26, 2025 19:34:44.777498960 CET1.1.1.1192.168.2.40x8d0aNo error (0)www.greendon.com95.211.219.66A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:44.777546883 CET1.1.1.1192.168.2.40xc06eNo error (0)www.greendon.com95.211.219.66A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:47.152956009 CET1.1.1.1192.168.2.40xabdfNo error (0)www.toroexoclk.com104.248.224.96A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:47.723885059 CET1.1.1.1192.168.2.40x7cfbNo error (0)saltandsalad.com184.94.215.122A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:49.489105940 CET1.1.1.1192.168.2.40xc890No error (0)www.muscleandstrength.com104.22.7.178A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:49.489105940 CET1.1.1.1192.168.2.40xc890No error (0)www.muscleandstrength.com104.22.6.178A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:49.489105940 CET1.1.1.1192.168.2.40xc890No error (0)www.muscleandstrength.com172.67.41.162A (IP address)IN (0x0001)false
                Mar 26, 2025 19:34:49.494411945 CET1.1.1.1192.168.2.40xcbc2No error (0)www.muscleandstrength.com65IN (0x0001)false
                Mar 26, 2025 19:34:50.153223991 CET1.1.1.1192.168.2.40xabacNo error (0)www.toroexoclk.com104.248.224.96A (IP address)IN (0x0001)false
                • www.greendon.com
                • www.toroexoclk.com
                • saltandsalad.com
                • www.muscleandstrength.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449743104.248.224.9680508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Mar 26, 2025 19:34:50.246387005 CET1258OUTGET /feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0 HTTP/1.1
                Host: www.toroexoclk.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Mar 26, 2025 19:34:50.366473913 CET390INHTTP/1.1 200 OK
                X-Powered-By: Express
                Surrogate-Control: no-store
                Cache-Control: no-store, no-cache, must-revalidate, proxy-revalidate
                Expires: 0
                Content-Type: application/json; charset=utf-8
                Content-Length: 44
                ETag: W/"2c-sKPmGdwIt2Xn7xpcBifIJ+li8ek"
                Date: Wed, 26 Mar 2025 18:34:50 GMT
                Connection: keep-alive
                Keep-Alive: timeout=5
                Data Raw: 7b 22 73 75 63 63 65 73 73 22 3a 74 72 75 65 2c 22 6d 73 67 22 3a 22 4d 69 73 73 69 6e 67 20 42 61 63 6b 66 69 6c 20 55 52 4c 22 7d
                Data Ascii: {"success":true,"msg":"Missing Backfil URL"}
                Mar 26, 2025 19:34:50.482146978 CET1205OUTGET /favicon.ico HTTP/1.1
                Host: www.toroexoclk.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Referer: http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Mar 26, 2025 19:34:50.578752041 CET175INHTTP/1.1 204 No Content
                X-Powered-By: Express
                ETag: W/"d-A4eKEZqmfsOK9abdwMiQ/JAgGMY"
                Date: Wed, 26 Mar 2025 18:34:50 GMT
                Connection: keep-alive
                Keep-Alive: timeout=5


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44973095.211.219.66443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:45 UTC666OUTGET / HTTP/1.1
                Host: www.greendon.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-03-26 18:34:45 UTC453INHTTP/1.1 200 OK
                accept-ch: Sec-CH-UA, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version, Sec-CH-UA-Mobile
                cache-control: max-age=0, private, must-revalidate
                connection: close
                content-length: 478
                content-type: text/html; charset=utf-8
                date: Wed, 26 Mar 2025 18:34:45 GMT
                server: Cowboy
                set-cookie: sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e; path=/; domain=.greendon.com; expires=Mon, 13 Apr 2093 21:48:52 GMT; max-age=2147483647; secure; HttpOnly
                2025-03-26 18:34:45 UTC478INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4c 6f 61 64 69 6e 67 2e 2e 2e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 73 63 72 69 70 74 20 74 79 70 65 3d 27 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 27 3e 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 72 65 70 6c 61 63 65 28 27 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 72 65 65 6e 64 6f 6e 2e 63 6f 6d 2f 3f 63 68 3d 31 26 6a 73 3d 65 79 4a 68 62 47 63 69 4f 69 4a 49 55 7a 49 31 4e 69 49 73 49 6e 52 35 63 43 49 36 49 6b 70 58 56 43 4a 39 2e 65 79 4a 68 64 57 51 69 4f 69 4a 4b 62 32 74 6c 62 69 49 73 49 6d 56 34 63 43 49 36 4d 54 63 30 4d 7a 41 79 4d 54 49 34 4e 53 77 69 61 57 46 30 49 6a 6f 78 4e 7a 51 7a 4d 44 45 30 4d 44 67 31 4c 43 4a 70 63 33 4d 69 4f 69 4a 4b 62 32
                Data Ascii: <html><head><title>Loading...</title></head><body><script type='text/javascript'>window.location.replace('https://www.greendon.com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44973695.211.219.66443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:46 UTC1098OUTGET /?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MzAyMTI4NSwiaWF0IjoxNzQzMDE0MDg1LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMG82czRyYWQwNjhjMnNnY3MwZXRlMjQiLCJuYmYiOjE3NDMwMTQwODUsInRzIjoxNzQzMDE0MDg1NDYwOTYzfQ.e4qEmZrqAJFR3xACIdhwdOF9e4UC9y_mFiI4U-uelfg&sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e HTTP/1.1
                Host: www.greendon.com
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                sec-ch-ua-platform-version: "10.0.0"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                Referer: https://www.greendon.com/
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                Cookie: sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e
                2025-03-26 18:34:47 UTC1190INHTTP/1.1 302 Found
                cache-control: max-age=0, private, must-revalidate
                connection: close
                content-length: 11
                date: Wed, 26 Mar 2025 18:34:46 GMT
                location: http://www.toroexoclk.com/feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0
                server: Cowboy
                set-cookie: sid=fd86f1d9-0a70-11f0-8a48-08aa9d3a9e8e; path=/; domain=.greendon.com; expires=Mon, 13 Apr 2093 21:48:53 GMT; max-age=2147483647; secure; HttpOnly
                2025-03-26 18:34:47 UTC11INData Raw: 52 65 64 69 72 65 63 74 69 6e 67
                Data Ascii: Redirecting


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449738104.248.224.96443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:47 UTC1479OUTGET /feed/click/?t1=128&tid=870&uid=26&subid=greendon.com&id=a5b9d4efdb3954009d859a24cc8deec9:932eb97e4f31ef69bb4895491b7fa944644518e6de058a3ac0a31fff635a63a9727060081e8aa7a2045d8e5e8fdc93daf7505a305c9496ab0ecc52c1e2660f9ec71d5fa3c41876dfac0a7d759a478cc51e8b10235a4285c268689ec49c240ed7b36e2c7a283d051c2b073dbddd3693b9be3093f0f086732e110de6dbdbc2a6a58ba4bc37278dc5bf3d98724db2316155d2ee28f43c1852fb024d4af3e2b7e93e66dba943e2ac2b9f5551e3bf72c18d03b1586b330dafc055f4742c1261ad67bdf2e1cdc1439b8078c879b343071055daf302ae8bd8ceb5a760415b08f49d8271365c7b75a94dce3c1774b1abba2ef860f2023c3af12fad4bd2e057abced0f56e4205eb475b5c75622606395775eb1b0fa4e7b30c1924a5032890318b1fd671dc4b49728f7715e9f10784c3fbc9bf1e27f2750efc0e53f2b744b98fb260eb3b262164542675ab5a97693ef4d7400437d459306876ddd5b2c06251491efd1fc87aec062b20c08a0fc3d881e06f5f5af3b0 HTTP/1.1
                Host: www.toroexoclk.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-03-26 18:34:47 UTC406INHTTP/1.1 302 Found
                X-Powered-By: Express
                Surrogate-Control: no-store
                Cache-Control: no-store, no-cache, must-revalidate, proxy-revalidate
                Expires: 0
                Location: https://saltandsalad.com/chromeT?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969
                Vary: Accept
                Content-Type: text/html; charset=utf-8
                Content-Length: 152
                Date: Wed, 26 Mar 2025 18:34:47 GMT
                Connection: close
                2025-03-26 18:34:47 UTC152INData Raw: 3c 70 3e 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 73 3a 2f 2f 73 61 6c 74 61 6e 64 73 61 6c 61 64 2e 63 6f 6d 2f 63 68 72 6f 6d 65 54 3f 63 6c 69 63 6b 5f 69 64 3d 32 69 73 71 73 65 33 74 62 6d 38 71 39 6c 31 65 31 26 61 6d 70 3b 74 69 64 3d 38 37 30 26 61 6d 70 3b 73 75 62 69 64 3d 67 72 65 65 6e 64 6f 6e 2e 63 6f 6d 26 61 6d 70 3b 72 65 66 3d 67 72 65 65 6e 64 6f 6e 2e 63 6f 6d 26 61 6d 70 3b 39 36 39 3c 2f 70 3e
                Data Ascii: <p>Found. Redirecting to https://saltandsalad.com/chromeT?click_id=2isqse3tbm8q9l1e1&amp;tid=870&amp;subid=greendon.com&amp;ref=greendon.com&amp;969</p>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.449739184.94.215.122443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:48 UTC734OUTGET /chromeT?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1
                Host: saltandsalad.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-03-26 18:34:48 UTC292INHTTP/1.1 301 Moved Permanently
                Date: Wed, 26 Mar 2025 18:34:48 GMT
                Server: Apache
                Location: https://saltandsalad.com/chromeT/?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969
                Content-Length: 332
                Connection: close
                Content-Type: text/html; charset=iso-8859-1
                2025-03-26 18:34:48 UTC332INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 73 61 6c 74 61 6e 64 73 61 6c 61 64 2e 63 6f 6d 2f 63 68 72 6f 6d 65 54 2f 3f 63 6c 69 63 6b 5f 69 64 3d 32 69 73 71 73 65 33 74 62 6d 38 71 39 6c 31 65 31 26 61 6d 70 3b 74 69 64 3d 38 37 30 26 61 6d 70 3b 73
                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://saltandsalad.com/chromeT/?click_id=2isqse3tbm8q9l1e1&amp;tid=870&amp;s


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.449740184.94.215.122443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:48 UTC735OUTGET /chromeT/?click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1
                Host: saltandsalad.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-03-26 18:34:49 UTC620INHTTP/1.1 301 Moved Permanently
                Date: Wed, 26 Mar 2025 18:34:48 GMT
                Server: Apache
                Cache-Control: no-store, no-cache, must-revalidate, max-age=0
                location: https://www.muscleandstrength.com/store/serious-mass.html/?bid={bid}&clickid={conversion}&pubfeed_subid={pubfeed}_{subid}&campaign={campaign}&offer={offer}&carrier={carrier}&os={os}&user_agent={user_agent}&ip={ip}&device_type={device_type}&referrer_domain={referrer_domain}&click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.449741104.22.7.178443508C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-03-26 18:34:49 UTC975OUTGET /store/serious-mass.html/?bid={bid}&clickid={conversion}&pubfeed_subid={pubfeed}_{subid}&campaign={campaign}&offer={offer}&carrier={carrier}&os={os}&user_agent={user_agent}&ip={ip}&device_type={device_type}&referrer_domain={referrer_domain}&click_id=2isqse3tbm8q9l1e1&tid=870&subid=greendon.com&ref=greendon.com&969 HTTP/1.1
                Host: www.muscleandstrength.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-03-26 18:34:49 UTC1332INHTTP/1.1 403 Forbidden
                Date: Wed, 26 Mar 2025 18:34:49 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                accept-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                cf-mitigated: challenge
                critical-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                cross-origin-embedder-policy: require-corp
                cross-origin-opener-policy: same-origin
                cross-origin-resource-policy: same-origin
                origin-agent-cluster: ?1
                permissions-policy: accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
                referrer-policy: same-origin
                server-timing: chlray;desc="9268be8daaa78cb3"
                x-content-options: nosniff
                x-frame-options: SAMEORIGIN
                2025-03-26 18:34:49 UTC466INData Raw: 63 66 2d 63 68 6c 2d 6f 75 74 3a 20 6a 35 44 6b 5a 53 45 31 37 4d 6d 6a 62 64 73 46 44 31 42 57 48 6d 36 5a 79 78 59 73 30 69 45 31 34 6c 62 51 71 6f 56 7a 50 2f 41 2f 73 49 34 4e 59 39 33 4a 50 37 54 63 64 64 65 55 34 35 6b 75 79 6f 41 4e 76 4d 51 75 7a 41 4f 63 2f 4e 43 59 35 6a 75 77 4b 69 6d 4b 67 46 66 36 75 75 70 79 7a 71 35 6c 63 31 63 73 45 56 65 2b 69 4d 79 4e 33 4d 77 72 4c 34 33 2f 2f 70 31 51 71 6a 75 62 63 36 74 34 69 46 7a 6f 2b 31 41 4e 76 53 77 49 78 62 47 54 53 51 3d 3d 24 59 2f 71 6b 73 68 45 50 42 2f 36 73 44 46 6c 59 4f 35 55 37 76 51 3d 3d 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c 3a 20 70 72 69 76 61 74 65 2c 20 6d 61 78 2d 61 67 65 3d 30 2c 20 6e 6f 2d 73 74 6f 72 65 2c 20 6e 6f 2d 63 61 63 68 65 2c 20 6d 75 73 74 2d 72 65 76 61
                Data Ascii: cf-chl-out: j5DkZSE17MmjbdsFD1BWHm6ZyxYs0iE14lbQqoVzP/A/sI4NY93JP7TcddeU45kuyoANvMQuzAOc/NCY5juwKimKgFf6uupyzq5lc1csEVe+iMyN3MwrL43//p1Qqjubc6t4iFzo+1ANvSwIxbGTSQ==$Y/qkshEPB/6sDFlYO5U7vQ==Cache-Control: private, max-age=0, no-store, no-cache, must-reva
                2025-03-26 18:34:49 UTC1369INData Raw: 32 36 62 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4a 75 73 74 20 61 20 6d 6f 6d 65 6e 74 2e 2e 2e 3c 2f 74 69 74 6c 65 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 45 64 67 65 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d
                Data Ascii: 26b2<!DOCTYPE html><html lang="en-US"><head><title>Just a moment...</title><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=Edge"><meta name="robots" content="noindex,nofollow"><meta name=
                2025-03-26 18:34:49 UTC1369INData Raw: 75 4d 7a 67 34 4c 6a 51 77 4e 79 34 7a 4f 44 6b 75 4e 44 41 33 4c 6a 6b 35 4e 43 41 77 49 43 34 31 4f 54 59 74 4c 6a 51 77 4e 79 34 35 4f 44 51 74 4c 6a 4d 35 4e 79 34 7a 4f 53 30 78 4c 6a 41 31 4e 79 34 7a 4f 44 6b 74 4c 6a 59 31 49 44 41 74 4d 53 34 77 4e 54 59 74 4c 6a 4d 34 4f 53 30 75 4d 7a 6b 34 4c 53 34 7a 4f 44 6b 74 4c 6a 4d 35 4f 43 30 75 4f 54 67 30 49 44 41 74 4c 6a 55 35 4e 79 34 7a 4f 54 67 74 4c 6a 6b 34 4e 53 34 30 4d 44 59 74 4c 6a 4d 35 4e 79 41 78 4c 6a 41 31 4e 69 30 75 4d 7a 6b 33 49 69 38 2b 50 43 39 7a 64 6d 63 2b 29 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 72 65 70 65 61 74 3a 6e 6f 2d 72 65 70 65 61 74 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 73 69 7a 65 3a 63 6f 6e 74 61 69 6e 3b 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 33 34 70 78 7d 40 6d
                Data Ascii: uMzg4LjQwNy4zODkuNDA3Ljk5NCAwIC41OTYtLjQwNy45ODQtLjM5Ny4zOS0xLjA1Ny4zODktLjY1IDAtMS4wNTYtLjM4OS0uMzk4LS4zODktLjM5OC0uOTg0IDAtLjU5Ny4zOTgtLjk4NS40MDYtLjM5NyAxLjA1Ni0uMzk3Ii8+PC9zdmc+);background-repeat:no-repeat;background-size:contain;padding-left:34px}@m
                2025-03-26 18:34:49 UTC1369INData Raw: 6d 65 4d 73 3a 20 27 33 39 30 30 30 30 27 2c 63 54 70 6c 43 3a 20 30 2c 63 54 70 6c 56 3a 20 35 2c 63 54 70 6c 42 3a 20 27 63 66 27 2c 63 4b 3a 20 22 22 2c 66 61 3a 20 22 5c 2f 73 74 6f 72 65 5c 2f 73 65 72 69 6f 75 73 2d 6d 61 73 73 2e 68 74 6d 6c 5c 2f 3f 62 69 64 3d 7b 62 69 64 7d 26 63 6c 69 63 6b 69 64 3d 7b 63 6f 6e 76 65 72 73 69 6f 6e 7d 26 70 75 62 66 65 65 64 5f 73 75 62 69 64 3d 7b 70 75 62 66 65 65 64 7d 5f 7b 73 75 62 69 64 7d 26 63 61 6d 70 61 69 67 6e 3d 7b 63 61 6d 70 61 69 67 6e 7d 26 6f 66 66 65 72 3d 7b 6f 66 66 65 72 7d 26 63 61 72 72 69 65 72 3d 7b 63 61 72 72 69 65 72 7d 26 6f 73 3d 7b 6f 73 7d 26 75 73 65 72 5f 61 67 65 6e 74 3d 7b 75 73 65 72 5f 61 67 65 6e 74 7d 26 69 70 3d 7b 69 70 7d 26 64 65 76 69 63 65 5f 74 79 70 65 3d 7b 64
                Data Ascii: meMs: '390000',cTplC: 0,cTplV: 5,cTplB: 'cf',cK: "",fa: "\/store\/serious-mass.html\/?bid={bid}&clickid={conversion}&pubfeed_subid={pubfeed}_{subid}&campaign={campaign}&offer={offer}&carrier={carrier}&os={os}&user_agent={user_agent}&ip={ip}&device_type={d
                2025-03-26 18:34:49 UTC1369INData Raw: 6e 36 70 46 59 46 50 37 35 63 5f 69 62 76 7a 57 4a 74 49 58 2e 47 48 63 35 66 68 6c 74 2e 30 56 41 47 42 69 46 4f 4d 49 47 6a 7a 54 46 49 51 6e 34 4f 49 39 35 5a 6f 5a 7a 35 79 66 53 69 39 49 76 69 68 38 46 30 77 62 4a 64 68 67 56 46 45 39 79 30 4b 44 33 48 44 4f 39 4e 52 44 45 6b 77 74 46 4f 4a 4a 59 57 6c 31 66 70 4f 4e 69 75 73 61 4d 74 45 4e 66 44 47 46 5a 6c 35 79 4e 56 57 42 46 5a 70 47 44 4f 50 38 32 30 52 57 6e 64 39 51 6e 4f 37 46 65 49 62 4b 54 45 42 44 50 79 37 5a 36 6b 4c 64 64 33 68 69 42 4d 2e 46 78 34 65 6f 4f 77 36 6f 54 55 57 46 6b 4b 41 55 43 4a 32 4b 76 6e 59 5f 4a 50 79 6b 4f 37 44 6a 33 5a 34 41 49 75 39 63 45 4b 4a 49 6f 51 2e 6a 78 66 76 56 41 37 6f 6b 65 54 6f 31 33 70 6d 65 6e 36 43 72 6e 6e 53 79 4a 39 61 36 73 46 48 32 63 46 4b
                Data Ascii: n6pFYFP75c_ibvzWJtIX.GHc5fhlt.0VAGBiFOMIGjzTFIQn4OI95ZoZz5yfSi9Ivih8F0wbJdhgVFE9y0KD3HDO9NRDEkwtFOJJYWl1fpONiusaMtENfDGFZl5yNVWBFZpGDOP820RWnd9QnO7FeIbKTEBDPy7Z6kLdd3hiBM.Fx4eoOw6oTUWFkKAUCJ2KvnY_JPykO7Dj3Z4AIu9cEKJIoQ.jxfvVA7okeTo13pmen6CrnnSyJ9a6sFH2cFK
                2025-03-26 18:34:49 UTC1369INData Raw: 6e 53 66 49 37 6c 36 53 31 56 6c 6b 36 76 6f 69 6b 76 41 78 35 4f 77 69 5a 78 72 66 62 64 35 4c 76 58 59 72 32 69 50 66 68 41 47 35 36 66 6b 4d 62 68 31 59 74 6f 35 31 4f 33 52 69 68 6f 50 56 69 6c 34 4e 39 77 73 5f 51 69 52 33 64 50 6d 58 35 67 51 4e 4c 59 79 55 68 6c 5f 54 62 4c 53 53 67 5f 56 58 78 61 4d 57 36 33 35 6b 5f 77 53 63 68 4a 4b 6c 49 53 54 71 49 70 30 57 69 77 6f 70 76 37 5f 6d 57 35 4c 66 5f 5a 76 36 6b 45 33 71 78 61 74 58 51 79 49 71 5a 4c 5f 47 56 49 5a 37 35 6f 31 6c 51 41 36 6f 4d 62 30 67 34 62 32 44 70 69 57 71 54 30 75 65 49 62 59 4e 2e 66 34 47 6e 52 75 72 70 58 5a 63 76 50 69 37 4d 37 38 56 71 46 2e 67 6b 63 50 52 52 31 62 6a 32 42 37 64 66 4b 71 4a 38 41 78 39 2e 67 73 6a 56 36 4b 59 70 52 6f 50 54 41 74 44 36 67 79 33 52 5a 61
                Data Ascii: nSfI7l6S1Vlk6voikvAx5OwiZxrfbd5LvXYr2iPfhAG56fkMbh1Yto51O3RihoPVil4N9ws_QiR3dPmX5gQNLYyUhl_TbLSSg_VXxaMW635k_wSchJKlISTqIp0Wiwopv7_mW5Lf_Zv6kE3qxatXQyIqZL_GVIZ75o1lQA6oMb0g4b2DpiWqT0ueIbYN.f4GnRurpXZcvPi7M78VqF.gkcPRR1bj2B7dfKqJ8Ax9.gsjV6KYpRoPTAtD6gy3RZa
                2025-03-26 18:34:49 UTC1369INData Raw: 4a 70 6a 61 63 53 57 57 65 4f 4d 32 48 75 61 59 39 30 33 5a 50 63 6e 72 69 77 42 37 55 59 4f 35 31 74 53 53 46 45 61 72 67 62 43 4a 6e 59 4e 68 2e 4e 46 74 4f 62 71 77 33 7a 59 51 41 56 53 69 53 30 6b 7a 70 47 65 6e 55 44 38 74 45 6f 6f 59 4a 32 62 6e 4c 49 77 79 75 4c 78 49 6a 44 57 76 41 52 6b 52 71 38 67 49 55 76 70 74 5f 4b 53 56 30 72 4f 34 4f 66 45 55 6b 72 46 2e 57 33 31 45 34 63 6f 68 56 69 33 6f 53 48 58 44 6c 68 53 57 52 78 4d 78 6f 43 37 6d 73 70 6f 2e 32 63 4a 4a 4d 57 30 47 63 38 58 57 34 4d 4a 58 59 53 67 30 6d 75 6c 7a 51 54 64 6b 56 69 71 56 59 37 49 66 68 6f 31 59 45 45 71 53 39 30 6e 75 65 59 39 62 35 31 53 42 74 4e 74 35 30 4f 58 57 42 5f 33 6f 65 73 7a 74 65 6c 4c 6c 69 37 51 65 75 6d 63 50 75 79 53 51 72 69 73 4c 61 38 65 5a 6f 52 43
                Data Ascii: JpjacSWWeOM2HuaY903ZPcnriwB7UYO51tSSFEargbCJnYNh.NFtObqw3zYQAVSiS0kzpGenUD8tEooYJ2bnLIwyuLxIjDWvARkRq8gIUvpt_KSV0rO4OfEUkrF.W31E4cohVi3oSHXDlhSWRxMxoC7mspo.2cJJMW0Gc8XW4MJXYSg0mulzQTdkViqVY7Ifho1YEEqS90nueY9b51SBtNt50OXWB_3oesztelLli7QeumcPuySQrisLa8eZoRC
                2025-03-26 18:34:49 UTC1369INData Raw: 6b 53 71 66 56 22 7d 3b 76 61 72 20 63 70 6f 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 27 73 63 72 69 70 74 27 29 3b 63 70 6f 2e 73 72 63 20 3d 20 27 2f 63 64 6e 2d 63 67 69 2f 63 68 61 6c 6c 65 6e 67 65 2d 70 6c 61 74 66 6f 72 6d 2f 68 2f 62 2f 6f 72 63 68 65 73 74 72 61 74 65 2f 63 68 6c 5f 70 61 67 65 2f 76 31 3f 72 61 79 3d 39 32 36 38 62 65 38 64 61 61 61 37 38 63 62 33 27 3b 77 69 6e 64 6f 77 2e 5f 63 66 5f 63 68 6c 5f 6f 70 74 2e 63 4f 67 55 48 61 73 68 20 3d 20 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 20 3d 3d 3d 20 27 27 20 26 26 20 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 2e 69 6e 64 65 78 4f 66 28 27 23 27 29 20 21 3d 3d 20 2d 31 20 3f 20 27 23 27 20 3a 20 6c 6f 63 61 74 69 6f 6e 2e 68 61 73 68 3b 77 69 6e 64 6f
                Data Ascii: kSqfV"};var cpo = document.createElement('script');cpo.src = '/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=9268be8daaa78cb3';window._cf_chl_opt.cOgUHash = location.hash === '' && location.href.indexOf('#') !== -1 ? '#' : location.hash;windo
                2025-03-26 18:34:49 UTC331INData Raw: 54 49 30 64 4b 42 48 71 39 4d 64 32 39 6e 6e 61 45 49 50 6c 6b 66 38 34 72 6e 61 45 52 6e 71 36 7a 76 57 76 50 55 71 72 32 66 74 38 4d 31 61 53 32 38 6f 4e 37 32 50 64 72 43 7a 53 6a 59 34 55 36 56 61 41 77 31 45 51 3d 3d 22 20 64 61 74 61 2d 63 66 2d 62 65 61 63 6f 6e 3d 27 7b 22 72 61 79 49 64 22 3a 22 39 32 36 38 62 65 38 64 61 61 61 37 38 63 62 33 22 2c 22 73 65 72 76 65 72 54 69 6d 69 6e 67 22 3a 7b 22 6e 61 6d 65 22 3a 7b 22 63 66 45 78 74 50 72 69 22 3a 74 72 75 65 2c 22 63 66 4c 34 22 3a 74 72 75 65 2c 22 63 66 53 70 65 65 64 42 72 61 69 6e 22 3a 74 72 75 65 2c 22 63 66 43 61 63 68 65 53 74 61 74 75 73 22 3a 74 72 75 65 7d 7d 2c 22 76 65 72 73 69 6f 6e 22 3a 22 32 30 32 35 2e 31 2e 30 22 2c 22 74 6f 6b 65 6e 22 3a 22 34 62 31 31 63 62 61 32 31 34
                Data Ascii: TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"rayId":"9268be8daaa78cb3","serverTiming":{"name":{"cfExtPri":true,"cfL4":true,"cfSpeedBrain":true,"cfCacheStatus":true}},"version":"2025.1.0","token":"4b11cba214
                2025-03-26 18:34:49 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:1
                Start time:14:34:34
                Start date:26/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:14:34:37
                Start date:26/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2452,i,10469626583534396515,15961310552530522455,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2464 /prefetch:3
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:4
                Start time:14:34:43
                Start date:26/03/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.greendon.com/"
                Imagebase:0x7ff786830000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly