Edit tour

Windows Analysis Report
http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es

Overview

General Information

Sample URL:http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es
Analysis ID:1652661
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder
URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3952 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1732,i,16455052471638053670,1639732912571325463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2588 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7032 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.esSample URL: PII: adelias@estrellagalicia.es
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 203.170.84.9:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.72.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.72.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.72.99
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.201.40
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.25
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es HTTP/1.1Host: redrx7.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJKhywEInP7MAQiFoM0BCL7VzgEIgdbOAQjI3M4BCIrgzgEI8ePOAQiu5M4BCIXlzgEIi+XOAQ==Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es HTTP/1.1Host: redrx7.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: redrx7.com
Source: global trafficDNS traffic detected: DNS query: wfmrtebyt4.spitegagos.shop
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 203.170.84.9:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3952_770549468Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3952_770549468Jump to behavior
Source: classification engineClassification label: clean1.win@27/2@37/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1732,i,16455052471638053670,1639732912571325463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2588 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1732,i,16455052471638053670,1639732912571325463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2588 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1652661 URL: http://redrx7.com/.rnureo/7... Startdate: 31/03/2025 Architecture: WINDOWS Score: 1 14 wfmrtebyt4.spitegagos.shop 2->14 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.4, 138, 443, 49670 unknown unknown 6->16 18 192.168.2.5 unknown unknown 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 www.google.com 142.251.35.164, 443, 49729, 49747 GOOGLEUS United States 11->20 22 redrx7.com 203.170.84.9, 443, 49731, 49732 DREAMSCAPE-AS-APDreamscapeNetworksLimitedAU Australia 11->22 24 2 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
redrx7.com
203.170.84.9
truefalse
    unknown
    google.com
    142.250.65.206
    truefalse
      high
      www.google.com
      142.251.35.164
      truefalse
        high
        wfmrtebyt4.spitegagos.shop
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.esfalse
          • Avira URL Cloud: safe
          unknown
          http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.esfalse
            unknown
            https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              203.170.84.9
              redrx7.comAustralia
              38719DREAMSCAPE-AS-APDreamscapeNetworksLimitedAUfalse
              142.251.35.164
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              192.168.2.5
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1652661
              Start date and time:2025-03-31 11:18:31 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 3s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:20
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean1.win@27/2@37/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 23.203.176.221, 172.217.165.142, 142.250.65.163, 142.251.16.84, 142.251.40.174, 142.251.40.99, 23.204.23.20, 131.253.33.254, 4.245.163.56
              • Excluded domains from analysis (whitelisted): a-ring-fallback.msedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, redirector.gvt1.com, update.googleapis.com, crl3.digicert.com, clients.l.google.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenFile calls found.
              • VT rate limit hit for: http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with very long lines (850)
              Category:downloaded
              Size (bytes):855
              Entropy (8bit):5.1664619251976
              Encrypted:false
              SSDEEP:24:xmlwYr033SRO6bNDBHslgT1d1uawBATL8uoBN2t2t2t2t2t2t2tomffffffo:qdY3SRO2NDKlgJXwBAv8uSNYYYYYYYo9
              MD5:6B8996F546719F210E9F61A8CDCEB060
              SHA1:48EC16FC5FBE4C8597CC5C5711CD63543FF67B60
              SHA-256:632B827B94B286BFFB6B09EED53AB977A6585317ECC95E94A7ED4F9F4C27C2A5
              SHA-512:2C76D24513E895EF8B8567289DAA0FB8D881EA14E6166A10856FB1625B9DAFE3159724D5776B77A338B3F97C13F597189EF17E7A84119F46D727458487812D69
              Malicious:false
              Reputation:low
              URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
              Preview:)]}'.["",["alabama duke basketball game","kelsey grammer cottage","earthquakes caribbean","nintendo switch pre order","coffee recalled","weather storms tornadoes","danzig merch","detroit pistons minnesota timberwolves"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggesteventid":"2657938597359326391","google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 111
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Mar 31, 2025 11:19:30.789489985 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:31.234090090 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:31.911529064 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:33.182312012 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:33.522922039 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.524972916 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.528126001 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.620557070 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.622788906 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.625319958 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.625349998 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.638931036 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.639131069 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.645977020 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.646030903 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.646085978 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.646197081 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.646223068 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.667188883 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.667203903 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:33.667257071 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:19:33.793800116 CEST4434971323.44.201.40192.168.2.4
              Mar 31, 2025 11:19:35.764574051 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:36.388272047 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:36.388326883 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:36.388397932 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:36.388571024 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:36.388592005 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:36.924562931 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:36.924645901 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:36.925826073 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:36.925839901 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:36.926265001 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:36.979190111 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:38.423049927 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.423155069 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:38.423245907 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.423954010 CEST4973280192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.424156904 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.424448013 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.424484015 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:38.725542068 CEST8049732203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:38.725604057 CEST8049733203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:38.725649118 CEST4973280192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:38.725696087 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:39.043839931 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:39.043929100 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:39.050287008 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:39.050327063 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:39.050817966 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:39.051213980 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:39.096271992 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:39.236044884 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:39.546055079 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:39.749629974 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:39.800635099 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:40.154645920 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:40.227646112 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:40.227875948 CEST44349731203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:40.227972984 CEST49731443192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:40.455459118 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:40.576297045 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:40.756907940 CEST8049733203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:40.831043959 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:40.876275063 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:40.958142996 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:40.961998940 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:40.962064981 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:40.962903023 CEST49729443192.168.2.4142.251.35.164
              Mar 31, 2025 11:19:40.962918043 CEST44349729142.251.35.164192.168.2.4
              Mar 31, 2025 11:19:41.357824087 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:41.415966034 CEST8049733203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:41.466763973 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:43.758177042 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:48.558285952 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:19:49.032856941 CEST8049732203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:49.032946110 CEST4973280192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:49.063177109 CEST4973280192.168.2.4203.170.84.9
              Mar 31, 2025 11:19:49.364753962 CEST8049732203.170.84.9192.168.2.4
              Mar 31, 2025 11:19:50.186342001 CEST49671443192.168.2.4204.79.197.203
              Mar 31, 2025 11:19:58.161813021 CEST49678443192.168.2.420.189.173.27
              Mar 31, 2025 11:20:16.348886967 CEST8049710208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:16.349097013 CEST4971080192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:16.349194050 CEST4971080192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:16.460896969 CEST8049710208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:17.323456049 CEST8049714208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:17.323652983 CEST4971480192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:17.323760033 CEST4971480192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:17.519320965 CEST8049715208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:17.519458055 CEST4971580192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:17.636296988 CEST4971480192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:18.245590925 CEST4971480192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:18.352807999 CEST8049714208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:19.012643099 CEST8049716208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:19.012793064 CEST4971680192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:19.012862921 CEST4971680192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:19.231106997 CEST4971280192.168.2.4142.250.72.99
              Mar 31, 2025 11:20:19.339832067 CEST4971680192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:19.542841911 CEST4971280192.168.2.4142.250.72.99
              Mar 31, 2025 11:20:19.638108015 CEST8049712142.250.72.99192.168.2.4
              Mar 31, 2025 11:20:19.638185024 CEST4971280192.168.2.4142.250.72.99
              Mar 31, 2025 11:20:19.642168045 CEST8049712142.250.72.99192.168.2.4
              Mar 31, 2025 11:20:19.980366945 CEST4971680192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:20.090744972 CEST8049716208.89.73.25192.168.2.4
              Mar 31, 2025 11:20:26.417124033 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:20:33.764926910 CEST49713443192.168.2.423.44.201.40
              Mar 31, 2025 11:20:33.765288115 CEST4971580192.168.2.4208.89.73.25
              Mar 31, 2025 11:20:36.341309071 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:36.341346025 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:36.341415882 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:36.341789961 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:36.341806889 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:36.865864038 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:36.866416931 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:36.866441965 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:46.565713882 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:46.565854073 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:46.565937996 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:46.732189894 CEST49747443192.168.2.4142.251.35.164
              Mar 31, 2025 11:20:46.732218027 CEST44349747142.251.35.164192.168.2.4
              Mar 31, 2025 11:20:47.329703093 CEST8049733203.170.84.9192.168.2.4
              Mar 31, 2025 11:20:47.329777956 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:20:48.732325077 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:20:49.479661942 CEST4973380192.168.2.4203.170.84.9
              Mar 31, 2025 11:20:49.782718897 CEST8049733203.170.84.9192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Mar 31, 2025 11:19:32.791944981 CEST53578141.1.1.1192.168.2.4
              Mar 31, 2025 11:19:32.850830078 CEST53569901.1.1.1192.168.2.4
              Mar 31, 2025 11:19:33.595520020 CEST53525291.1.1.1192.168.2.4
              Mar 31, 2025 11:19:34.018439054 CEST53596631.1.1.1192.168.2.4
              Mar 31, 2025 11:19:36.282603979 CEST6367353192.168.2.41.1.1.1
              Mar 31, 2025 11:19:36.282763958 CEST5159853192.168.2.41.1.1.1
              Mar 31, 2025 11:19:36.387284040 CEST53636731.1.1.1192.168.2.4
              Mar 31, 2025 11:19:36.387348890 CEST53515981.1.1.1192.168.2.4
              Mar 31, 2025 11:19:38.113285065 CEST5609553192.168.2.41.1.1.1
              Mar 31, 2025 11:19:38.113650084 CEST5335653192.168.2.41.1.1.1
              Mar 31, 2025 11:19:38.129694939 CEST4972953192.168.2.41.1.1.1
              Mar 31, 2025 11:19:38.129862070 CEST5264553192.168.2.41.1.1.1
              Mar 31, 2025 11:19:38.418957949 CEST53526451.1.1.1192.168.2.4
              Mar 31, 2025 11:19:38.419002056 CEST53533561.1.1.1192.168.2.4
              Mar 31, 2025 11:19:38.422233105 CEST53497291.1.1.1192.168.2.4
              Mar 31, 2025 11:19:38.422492981 CEST53560951.1.1.1192.168.2.4
              Mar 31, 2025 11:19:40.245007038 CEST6075253192.168.2.41.1.1.1
              Mar 31, 2025 11:19:40.245265007 CEST6273253192.168.2.41.1.1.1
              Mar 31, 2025 11:19:40.345900059 CEST53607521.1.1.1192.168.2.4
              Mar 31, 2025 11:19:40.345972061 CEST53627321.1.1.1192.168.2.4
              Mar 31, 2025 11:19:40.347088099 CEST6305253192.168.2.41.1.1.1
              Mar 31, 2025 11:19:40.448678017 CEST53630521.1.1.1192.168.2.4
              Mar 31, 2025 11:19:41.419228077 CEST5194453192.168.2.41.1.1.1
              Mar 31, 2025 11:19:41.419486046 CEST5799453192.168.2.41.1.1.1
              Mar 31, 2025 11:19:41.519582987 CEST53519441.1.1.1192.168.2.4
              Mar 31, 2025 11:19:41.593321085 CEST5229953192.168.2.48.8.8.8
              Mar 31, 2025 11:19:41.593746901 CEST5462453192.168.2.41.1.1.1
              Mar 31, 2025 11:19:41.694921970 CEST53546241.1.1.1192.168.2.4
              Mar 31, 2025 11:19:42.806129932 CEST5107553192.168.2.48.8.4.4
              Mar 31, 2025 11:19:42.808810949 CEST5607153192.168.2.41.1.1.1
              Mar 31, 2025 11:19:42.809223890 CEST6170553192.168.2.41.1.1.1
              Mar 31, 2025 11:19:42.912919044 CEST53617051.1.1.1192.168.2.4
              Mar 31, 2025 11:19:43.825365067 CEST5917153192.168.2.41.1.1.1
              Mar 31, 2025 11:19:43.927109003 CEST53591711.1.1.1192.168.2.4
              Mar 31, 2025 11:19:48.999901056 CEST6226153192.168.2.41.1.1.1
              Mar 31, 2025 11:19:49.000134945 CEST5659053192.168.2.41.1.1.1
              Mar 31, 2025 11:19:50.018580914 CEST5349853192.168.2.41.1.1.1
              Mar 31, 2025 11:19:50.018830061 CEST5555353192.168.2.41.1.1.1
              Mar 31, 2025 11:19:50.116702080 CEST53534981.1.1.1192.168.2.4
              Mar 31, 2025 11:19:50.116750002 CEST53555531.1.1.1192.168.2.4
              Mar 31, 2025 11:19:50.142298937 CEST5871553192.168.2.41.1.1.1
              Mar 31, 2025 11:19:50.238575935 CEST53587151.1.1.1192.168.2.4
              Mar 31, 2025 11:19:51.154006958 CEST53593401.1.1.1192.168.2.4
              Mar 31, 2025 11:19:53.339807987 CEST6364053192.168.2.41.1.1.1
              Mar 31, 2025 11:19:53.339963913 CEST5493553192.168.2.41.1.1.1
              Mar 31, 2025 11:19:53.439709902 CEST53636401.1.1.1192.168.2.4
              Mar 31, 2025 11:19:53.439758062 CEST53549351.1.1.1192.168.2.4
              Mar 31, 2025 11:20:02.612945080 CEST5780653192.168.2.41.1.1.1
              Mar 31, 2025 11:20:03.621052027 CEST5780653192.168.2.41.1.1.1
              Mar 31, 2025 11:20:03.726308107 CEST53578061.1.1.1192.168.2.4
              Mar 31, 2025 11:20:04.333745003 CEST6552753192.168.2.41.1.1.1
              Mar 31, 2025 11:20:04.333899021 CEST5523853192.168.2.41.1.1.1
              Mar 31, 2025 11:20:04.436491013 CEST53655271.1.1.1192.168.2.4
              Mar 31, 2025 11:20:04.469183922 CEST6406153192.168.2.41.1.1.1
              Mar 31, 2025 11:20:04.571888924 CEST53640611.1.1.1192.168.2.4
              Mar 31, 2025 11:20:04.586893082 CEST6462753192.168.2.41.1.1.1
              Mar 31, 2025 11:20:04.587158918 CEST5307753192.168.2.48.8.8.8
              Mar 31, 2025 11:20:04.687808037 CEST53646271.1.1.1192.168.2.4
              Mar 31, 2025 11:20:04.687856913 CEST53530778.8.8.8192.168.2.4
              Mar 31, 2025 11:20:09.980784893 CEST53530871.1.1.1192.168.2.4
              Mar 31, 2025 11:20:15.766005039 CEST5362674162.159.36.2192.168.2.4
              Mar 31, 2025 11:20:24.981647015 CEST5300453192.168.2.41.1.1.1
              Mar 31, 2025 11:20:25.081602097 CEST53530041.1.1.1192.168.2.4
              Mar 31, 2025 11:20:32.042572021 CEST53566851.1.1.1192.168.2.4
              Mar 31, 2025 11:20:34.605057001 CEST4967053192.168.2.41.1.1.1
              Mar 31, 2025 11:20:34.605307102 CEST6068653192.168.2.41.1.1.1
              Mar 31, 2025 11:20:34.707441092 CEST53496701.1.1.1192.168.2.4
              Mar 31, 2025 11:20:34.708518028 CEST53606861.1.1.1192.168.2.4
              Mar 31, 2025 11:20:34.709362030 CEST5618353192.168.2.41.1.1.1
              Mar 31, 2025 11:20:34.810210943 CEST53561831.1.1.1192.168.2.4
              Mar 31, 2025 11:20:38.721108913 CEST138138192.168.2.4192.168.2.255
              Mar 31, 2025 11:20:47.402148962 CEST5205753192.168.2.41.1.1.1
              Mar 31, 2025 11:20:48.417346954 CEST5205753192.168.2.41.1.1.1
              Mar 31, 2025 11:20:48.516437054 CEST53520571.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 31, 2025 11:19:36.282603979 CEST192.168.2.41.1.1.10xf710Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:36.282763958 CEST192.168.2.41.1.1.10x7f1dStandard query (0)www.google.com65IN (0x0001)false
              Mar 31, 2025 11:19:38.113285065 CEST192.168.2.41.1.1.10x324bStandard query (0)redrx7.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:38.113650084 CEST192.168.2.41.1.1.10xf3ebStandard query (0)redrx7.com65IN (0x0001)false
              Mar 31, 2025 11:19:38.129694939 CEST192.168.2.41.1.1.10x9e83Standard query (0)redrx7.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:38.129862070 CEST192.168.2.41.1.1.10x3c73Standard query (0)redrx7.com65IN (0x0001)false
              Mar 31, 2025 11:19:40.245007038 CEST192.168.2.41.1.1.10xdec4Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:40.245265007 CEST192.168.2.41.1.1.10xbfd3Standard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:19:40.347088099 CEST192.168.2.41.1.1.10xf437Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:41.419228077 CEST192.168.2.41.1.1.10xfd56Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:41.419486046 CEST192.168.2.41.1.1.10x64d5Standard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:19:41.593321085 CEST192.168.2.48.8.8.80x5689Standard query (0)google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:41.593746901 CEST192.168.2.41.1.1.10xeef4Standard query (0)google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:42.806129932 CEST192.168.2.48.8.4.40x4ca6Standard query (0)google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:42.808810949 CEST192.168.2.41.1.1.10x48d4Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:42.809223890 CEST192.168.2.41.1.1.10xe915Standard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:19:43.825365067 CEST192.168.2.41.1.1.10x4eafStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:48.999901056 CEST192.168.2.41.1.1.10xaeb6Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:49.000134945 CEST192.168.2.41.1.1.10xf78fStandard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:19:50.018580914 CEST192.168.2.41.1.1.10x7d5dStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:50.018830061 CEST192.168.2.41.1.1.10x57eeStandard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:19:50.142298937 CEST192.168.2.41.1.1.10xc14dStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:53.339807987 CEST192.168.2.41.1.1.10x813eStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:53.339963913 CEST192.168.2.41.1.1.10xbe8aStandard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:20:02.612945080 CEST192.168.2.41.1.1.10xfc14Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:03.621052027 CEST192.168.2.41.1.1.10xfc14Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.333745003 CEST192.168.2.41.1.1.10x4ce1Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.333899021 CEST192.168.2.41.1.1.10x1968Standard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:20:04.469183922 CEST192.168.2.41.1.1.10x6028Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.586893082 CEST192.168.2.41.1.1.10xa3a5Standard query (0)google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.587158918 CEST192.168.2.48.8.8.80x2a8Standard query (0)google.comA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:24.981647015 CEST192.168.2.41.1.1.10x42fbStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:34.605057001 CEST192.168.2.41.1.1.10xf58aStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:34.605307102 CEST192.168.2.41.1.1.10xe176Standard query (0)wfmrtebyt4.spitegagos.shop65IN (0x0001)false
              Mar 31, 2025 11:20:34.709362030 CEST192.168.2.41.1.1.10xda87Standard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:47.402148962 CEST192.168.2.41.1.1.10xbb3aStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:48.417346954 CEST192.168.2.41.1.1.10xbb3aStandard query (0)wfmrtebyt4.spitegagos.shopA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 31, 2025 11:19:36.387284040 CEST1.1.1.1192.168.2.40xf710No error (0)www.google.com142.251.35.164A (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:36.387348890 CEST1.1.1.1192.168.2.40x7f1dNo error (0)www.google.com65IN (0x0001)false
              Mar 31, 2025 11:19:38.422233105 CEST1.1.1.1192.168.2.40x9e83No error (0)redrx7.com203.170.84.9A (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:38.422492981 CEST1.1.1.1192.168.2.40x324bNo error (0)redrx7.com203.170.84.9A (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:40.345900059 CEST1.1.1.1192.168.2.40xdec4Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:40.345972061 CEST1.1.1.1192.168.2.40xbfd3Name error (3)wfmrtebyt4.spitegagos.shopnonenone65IN (0x0001)false
              Mar 31, 2025 11:19:40.448678017 CEST1.1.1.1192.168.2.40xf437Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:41.519582987 CEST1.1.1.1192.168.2.40xfd56Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:41.694921970 CEST1.1.1.1192.168.2.40xeef4No error (0)google.com142.250.65.206A (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:42.912919044 CEST1.1.1.1192.168.2.40xe915Name error (3)wfmrtebyt4.spitegagos.shopnonenone65IN (0x0001)false
              Mar 31, 2025 11:19:43.927109003 CEST1.1.1.1192.168.2.40x4eafName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:50.116702080 CEST1.1.1.1192.168.2.40x7d5dName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:50.116750002 CEST1.1.1.1192.168.2.40x57eeName error (3)wfmrtebyt4.spitegagos.shopnonenone65IN (0x0001)false
              Mar 31, 2025 11:19:50.238575935 CEST1.1.1.1192.168.2.40xc14dName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:53.439709902 CEST1.1.1.1192.168.2.40x813eName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:19:53.439758062 CEST1.1.1.1192.168.2.40xbe8aName error (3)wfmrtebyt4.spitegagos.shopnonenone65IN (0x0001)false
              Mar 31, 2025 11:20:03.726308107 CEST1.1.1.1192.168.2.40xfc14Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.436491013 CEST1.1.1.1192.168.2.40x4ce1Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.571888924 CEST1.1.1.1192.168.2.40x6028Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.687808037 CEST1.1.1.1192.168.2.40xa3a5No error (0)google.com142.250.65.206A (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:04.687856913 CEST8.8.8.8192.168.2.40x2a8No error (0)google.com142.250.65.206A (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:25.081602097 CEST1.1.1.1192.168.2.40x42fbName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:34.707441092 CEST1.1.1.1192.168.2.40xf58aName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:34.708518028 CEST1.1.1.1192.168.2.40xe176Name error (3)wfmrtebyt4.spitegagos.shopnonenone65IN (0x0001)false
              Mar 31, 2025 11:20:34.810210943 CEST1.1.1.1192.168.2.40xda87Name error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              Mar 31, 2025 11:20:48.516437054 CEST1.1.1.1192.168.2.40xbb3aName error (3)wfmrtebyt4.spitegagos.shopnonenoneA (IP address)IN (0x0001)false
              • redrx7.com
              • www.google.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449733203.170.84.9805504C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Mar 31, 2025 11:19:40.455459118 CEST476OUTGET /.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es HTTP/1.1
              Host: redrx7.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Mar 31, 2025 11:19:41.415966034 CEST292INHTTP/1.1 302 Moved Temporarily
              Server: nginx
              Date: Mon, 31 Mar 2025 09:19:40 GMT
              Content-Type: text/html; charset=UTF-8
              Content-Length: 0
              Connection: keep-alive
              X-Powered-By: PHP/8.2.26
              Upgrade: h2,h2c
              Location: https://wfmrtebyt4.spitegagos.shop/?email=adelias@estrellagalicia.es
              Mar 31, 2025 11:20:26.417124033 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449731203.170.84.94435504C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-31 09:19:39 UTC711OUTGET /.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es HTTP/1.1
              Host: redrx7.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-31 09:19:39 UTC297INHTTP/1.1 302 Moved Temporarily
              Date: Mon, 31 Mar 2025 09:19:39 GMT
              Server: Apache
              X-Powered-By: PHP/8.2.26
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Location: https://wfmrtebyt4.spitegagos.shop/?email=adelias@estrellagalicia.es
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449729142.251.35.1644435504C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-31 09:19:40 UTC595OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
              Host: www.google.com
              Connection: keep-alive
              X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJKhywEInP7MAQiFoM0BCL7VzgEIgdbOAQjI3M4BCIrgzgEI8ePOAQiu5M4BCIXlzgEIi+XOAQ==
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-31 09:19:40 UTC1303INHTTP/1.1 200 OK
              Date: Mon, 31 Mar 2025 09:19:40 GMT
              Pragma: no-cache
              Expires: -1
              Cache-Control: no-cache, must-revalidate
              Content-Type: text/javascript; charset=UTF-8
              Strict-Transport-Security: max-age=31536000
              Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce--8XgWhAt-KHZKJ3_NiQJAw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
              Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
              Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
              Accept-CH: Sec-CH-Prefers-Color-Scheme
              Accept-CH: Downlink
              Accept-CH: RTT
              Accept-CH: Sec-CH-UA-Form-Factors
              Accept-CH: Sec-CH-UA-Platform
              Accept-CH: Sec-CH-UA-Platform-Version
              Accept-CH: Sec-CH-UA-Full-Version
              Accept-CH: Sec-CH-UA-Arch
              Accept-CH: Sec-CH-UA-Model
              Accept-CH: Sec-CH-UA-Bitness
              Accept-CH: Sec-CH-UA-Full-Version-List
              Accept-CH: Sec-CH-UA-WoW64
              Permissions-Policy: unload=()
              Content-Disposition: attachment; filename="f.txt"
              Server: gws
              X-XSS-Protection: 0
              X-Frame-Options: SAMEORIGIN
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2025-03-31 09:19:40 UTC862INData Raw: 33 35 37 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 61 6c 61 62 61 6d 61 20 64 75 6b 65 20 62 61 73 6b 65 74 62 61 6c 6c 20 67 61 6d 65 22 2c 22 6b 65 6c 73 65 79 20 67 72 61 6d 6d 65 72 20 63 6f 74 74 61 67 65 22 2c 22 65 61 72 74 68 71 75 61 6b 65 73 20 63 61 72 69 62 62 65 61 6e 22 2c 22 6e 69 6e 74 65 6e 64 6f 20 73 77 69 74 63 68 20 70 72 65 20 6f 72 64 65 72 22 2c 22 63 6f 66 66 65 65 20 72 65 63 61 6c 6c 65 64 22 2c 22 77 65 61 74 68 65 72 20 73 74 6f 72 6d 73 20 74 6f 72 6e 61 64 6f 65 73 22 2c 22 64 61 6e 7a 69 67 20 6d 65 72 63 68 22 2c 22 64 65 74 72 6f 69 74 20 70 69 73 74 6f 6e 73 20 6d 69 6e 6e 65 73 6f 74 61 20 74 69 6d 62 65 72 77 6f 6c 76 65 73 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b
              Data Ascii: 357)]}'["",["alabama duke basketball game","kelsey grammer cottage","earthquakes caribbean","nintendo switch pre order","coffee recalled","weather storms tornadoes","danzig merch","detroit pistons minnesota timberwolves"],["","","","","","","",""],[],{
              2025-03-31 09:19:40 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0050100MB

              Click to jump to process

              Target ID:1
              Start time:05:19:27
              Start date:31/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:05:19:31
              Start date:31/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1732,i,16455052471638053670,1639732912571325463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2588 /prefetch:3
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:4
              Start time:05:19:37
              Start date:31/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly