Edit tour

Windows Analysis Report
https://check.cymyv.icu/gkcxv.google

Overview

General Information

Sample URL:https://check.cymyv.icu/gkcxv.google
Analysis ID:1653407
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6192 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2524,i,908010192394182464,11261446003865537638,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2552 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7048 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://check.cymyv.icu/gkcxv.google" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://check.cymyv.icu/gkcxv.googleAvira URL Cloud: detection malicious, Label: malware
Source: unknownHTTPS traffic detected: 142.250.72.100:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /gkcxv.google HTTP/1.1Host: check.cymyv.icuConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /gkcxv.google HTTP/1.1Host: check.cymyv.icuConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: check.cymyv.icu
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 396Content-Type: application/reports+jsonOrigin: https://check.cymyv.icuUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 01 Apr 2025 05:47:44 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}speculation-rules: "/cdn-cgi/speculation"Server: cloudflareCF-RAY: 9295cb1f6b2733a6-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=98337&min_rtt=96394&rtt_var=22339&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2818&recv_bytes=1249&delivery_rate=31687&cwnd=252&unsent_bytes=0&cid=02c015e30a1485b6&ts=453&x=0"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 01 Apr 2025 05:47:54 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BB4QjJtJXLyyEKbyKg%2BWXHhUBtN7eRJNaQ1UTnjMev0IR2VDqYbawhQJH1xphy8pFFsy2aT%2F%2FwgHR3ZSRA9tzX%2BPKQ1UPWkyGKbzPocdhnmYnH6Rzb7IJYvD9ex8uyeys5M%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}speculation-rules: "/cdn-cgi/speculation"Server: cloudflareCF-RAY: 9295cb5f6c9325dc-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=97620&min_rtt=96232&rtt_var=21679&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2818&recv_bytes=1281&delivery_rate=31723&cwnd=252&unsent_bytes=0&cid=672e8c210c6335ec&ts=10692&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownHTTPS traffic detected: 142.250.72.100:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.48.1:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: classification engineClassification label: mal48.win@20/0@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2524,i,908010192394182464,11261446003865537638,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2552 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://check.cymyv.icu/gkcxv.google"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2524,i,908010192394182464,11261446003865537638,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2552 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1653407 URL: https://check.cymyv.icu/gkc... Startdate: 01/04/2025 Architecture: WINDOWS Score: 48 22 Antivirus / Scanner detection for submitted sample 2->22 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 443, 49709, 49730 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 www.google.com 142.250.72.100, 443, 49730 GOOGLEUS United States 11->16 18 a.nel.cloudflare.com 35.190.80.1, 443, 49734, 49737 GOOGLEUS United States 11->18 20 check.cymyv.icu 104.21.48.1, 443, 49732, 49733 CLOUDFLARENETUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://check.cymyv.icu/gkcxv.google100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    check.cymyv.icu
    104.21.48.1
    truefalse
      unknown
      www.google.com
      142.250.72.100
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://check.cymyv.icu/gkcxv.googletrue
          unknown
          https://a.nel.cloudflare.com/report/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3Dfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            104.21.48.1
            check.cymyv.icuUnited States
            13335CLOUDFLARENETUSfalse
            142.250.72.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            35.190.80.1
            a.nel.cloudflare.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1653407
            Start date and time:2025-04-01 07:46:39 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 53s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://check.cymyv.icu/gkcxv.google
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:11
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@20/0@6/4
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.80.78, 142.250.72.99, 142.250.31.84, 142.251.32.110, 23.203.176.221, 199.232.38.172, 23.204.23.20, 4.245.163.56
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://check.cymyv.icu/gkcxv.google
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 86
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 1, 2025 07:47:30.914186954 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 07:47:37.022986889 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:37.350095987 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:37.956695080 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:39.161911011 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:40.528773069 CEST4968180192.168.2.42.17.190.73
            Apr 1, 2025 07:47:41.568967104 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:42.109869957 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:42.109894991 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:42.109955072 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:42.110116959 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:42.110132933 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:42.312916994 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:42.313183069 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:42.314188957 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:42.314193964 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:42.314698935 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:42.365413904 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:43.530548096 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.530596018 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.530658960 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.530832052 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.530848980 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.531173944 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.531213999 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.531265020 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.531411886 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.531426907 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.740731001 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.740833998 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.741894007 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.741906881 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.742229939 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.742503881 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.750684023 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.750780106 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.751607895 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:43.751615047 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.752082109 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.784301996 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:43.803642988 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:44.170270920 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:44.170344114 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:44.170387030 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:44.171195030 CEST49732443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:44.171214104 CEST44349732104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:44.292515993 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.292551994 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.292612076 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.292738914 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.292753935 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.499685049 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.499749899 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.501296043 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.501305103 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.501617908 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.501876116 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.544276953 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.846942902 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.847021103 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.847204924 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.847435951 CEST49734443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.847450018 CEST4434973435.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.848078012 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.848165035 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:44.848273993 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.848383904 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:44.848417997 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.027757883 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.028090000 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:45.028131962 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.028228045 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:45.028240919 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.232738018 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.233047962 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:45.233056068 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.233078957 CEST4434973735.190.80.1192.168.2.4
            Apr 1, 2025 07:47:45.233141899 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:45.233141899 CEST49737443192.168.2.435.190.80.1
            Apr 1, 2025 07:47:45.790882111 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:46.102850914 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:46.384099007 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:46.712229967 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:47.927661896 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:49.201839924 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.201841116 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.202157974 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.302405119 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.302443027 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.302537918 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.303567886 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.303585052 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.303664923 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.303664923 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.304536104 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.305526972 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.305600882 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.305797100 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.309029102 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.406048059 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.409343958 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.411905050 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.412038088 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.412161112 CEST44349709131.253.33.254192.168.2.4
            Apr 1, 2025 07:47:49.412426949 CEST49709443192.168.2.4131.253.33.254
            Apr 1, 2025 07:47:49.415188074 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:49.415566921 CEST49740443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:49.415596008 CEST44349740204.79.197.222192.168.2.4
            Apr 1, 2025 07:47:49.418585062 CEST49740443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:49.418828011 CEST49740443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:49.418845892 CEST44349740204.79.197.222192.168.2.4
            Apr 1, 2025 07:47:49.717711926 CEST44349740204.79.197.222192.168.2.4
            Apr 1, 2025 07:47:49.717886925 CEST49740443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:49.725155115 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:50.334546089 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:50.334574938 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:51.537940025 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:52.336410046 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:52.336525917 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:52.336620092 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:53.930820942 CEST49730443192.168.2.4142.250.72.100
            Apr 1, 2025 07:47:53.930834055 CEST44349730142.250.72.100192.168.2.4
            Apr 1, 2025 07:47:53.944463968 CEST49680443192.168.2.4204.79.197.222
            Apr 1, 2025 07:47:54.089795113 CEST49743443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.089895964 CEST44349743104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.089973927 CEST49743443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.090337992 CEST49743443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.090373039 CEST44349743104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.104372025 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.152268887 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.295124054 CEST44349743104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.295350075 CEST49743443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.295391083 CEST44349743104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.422550917 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.422724962 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:54.422801018 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.423856020 CEST49733443192.168.2.4104.21.48.1
            Apr 1, 2025 07:47:54.423878908 CEST44349733104.21.48.1192.168.2.4
            Apr 1, 2025 07:47:55.147197962 CEST49678443192.168.2.420.189.173.27
            Apr 1, 2025 07:47:55.990824938 CEST49671443192.168.2.4204.79.197.203
            Apr 1, 2025 07:47:58.756462097 CEST49680443192.168.2.4204.79.197.222
            TimestampSource PortDest PortSource IPDest IP
            Apr 1, 2025 07:47:37.979185104 CEST53605521.1.1.1192.168.2.4
            Apr 1, 2025 07:47:37.990786076 CEST53517031.1.1.1192.168.2.4
            Apr 1, 2025 07:47:38.736658096 CEST53618641.1.1.1192.168.2.4
            Apr 1, 2025 07:47:38.925535917 CEST53574011.1.1.1192.168.2.4
            Apr 1, 2025 07:47:42.022944927 CEST5178253192.168.2.41.1.1.1
            Apr 1, 2025 07:47:42.023170948 CEST6300253192.168.2.41.1.1.1
            Apr 1, 2025 07:47:42.108751059 CEST53517821.1.1.1192.168.2.4
            Apr 1, 2025 07:47:42.108783960 CEST53630021.1.1.1192.168.2.4
            Apr 1, 2025 07:47:43.407928944 CEST5098653192.168.2.41.1.1.1
            Apr 1, 2025 07:47:43.408189058 CEST6038153192.168.2.41.1.1.1
            Apr 1, 2025 07:47:43.526571035 CEST53509861.1.1.1192.168.2.4
            Apr 1, 2025 07:47:43.529983997 CEST53603811.1.1.1192.168.2.4
            Apr 1, 2025 07:47:44.203224897 CEST6269853192.168.2.41.1.1.1
            Apr 1, 2025 07:47:44.203711033 CEST5273653192.168.2.41.1.1.1
            Apr 1, 2025 07:47:44.290728092 CEST53626981.1.1.1192.168.2.4
            Apr 1, 2025 07:47:44.291855097 CEST53527361.1.1.1192.168.2.4
            Apr 1, 2025 07:47:55.954461098 CEST53615061.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 1, 2025 07:47:42.022944927 CEST192.168.2.41.1.1.10xadbStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:42.023170948 CEST192.168.2.41.1.1.10xc4dcStandard query (0)www.google.com65IN (0x0001)false
            Apr 1, 2025 07:47:43.407928944 CEST192.168.2.41.1.1.10x2df0Standard query (0)check.cymyv.icuA (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.408189058 CEST192.168.2.41.1.1.10x2126Standard query (0)check.cymyv.icu65IN (0x0001)false
            Apr 1, 2025 07:47:44.203224897 CEST192.168.2.41.1.1.10x3895Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:44.203711033 CEST192.168.2.41.1.1.10x2fd8Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 1, 2025 07:47:42.108751059 CEST1.1.1.1192.168.2.40xadbNo error (0)www.google.com142.250.72.100A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:42.108783960 CEST1.1.1.1192.168.2.40xc4dcNo error (0)www.google.com65IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.48.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.16.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.112.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.96.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.32.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.64.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.526571035 CEST1.1.1.1192.168.2.40x2df0No error (0)check.cymyv.icu104.21.80.1A (IP address)IN (0x0001)false
            Apr 1, 2025 07:47:43.529983997 CEST1.1.1.1192.168.2.40x2126No error (0)check.cymyv.icu65IN (0x0001)false
            Apr 1, 2025 07:47:44.290728092 CEST1.1.1.1192.168.2.40x3895No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
            • check.cymyv.icu
            • a.nel.cloudflare.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449732104.21.48.14436192C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-01 05:47:43 UTC677OUTGET /gkcxv.google HTTP/1.1
            Host: check.cymyv.icu
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-01 05:47:44 UTC848INHTTP/1.1 404 Not Found
            Date: Tue, 01 Apr 2025 05:47:44 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            cf-cache-status: DYNAMIC
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            speculation-rules: "/cdn-cgi/speculation"
            Server: cloudflare
            CF-RAY: 9295cb1f6b2733a6-EWR
            alt-svc: h3=":443"; ma=86400
            server-timing: cfL4;desc="?proto=TCP&rtt=98337&min_rtt=96394&rtt_var=22339&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2818&recv_bytes=1249&delivery_rate=31687&cwnd=252&unsent_bytes=0&cid=02c015e30a1485b6&ts=453&x=0"
            2025-04-01 05:47:44 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973435.190.80.14436192C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-01 05:47:44 UTC550OUTOPTIONS /report/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Origin: https://check.cymyv.icu
            Access-Control-Request-Method: POST
            Access-Control-Request-Headers: content-type
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-01 05:47:44 UTC336INHTTP/1.1 200 OK
            Content-Length: 0
            access-control-max-age: 86400
            access-control-allow-methods: OPTIONS, POST
            access-control-allow-origin: *
            access-control-allow-headers: content-length, content-type
            date: Tue, 01 Apr 2025 05:47:44 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44973735.190.80.14436192C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-01 05:47:45 UTC525OUTPOST /report/v4?s=igFjRlI8XjsEy6Snud6UER3xAHL77gUi1BlFM0s2qlGcgRCxYhHpDzQKu%2FcnGmA7XZf1w4NoBYl%2F5pvNpwFcJcKoOXUuxiq%2Ft1QW9rcuq%2FE306GXvUPOkH6YzSgmH%2B4%2B%2Fvo%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Content-Length: 396
            Content-Type: application/reports+json
            Origin: https://check.cymyv.icu
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-01 05:47:45 UTC396OUTData Raw: 5b 7b 22 61 67 65 22 3a 33 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 37 35 39 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 34 38 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 63 68 65 63 6b 2e 63 79 6d 79 76 2e 69 63 75 2f 67
            Data Ascii: [{"age":31,"body":{"elapsed_time":759,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.48.1","status_code":404,"type":"http.error"},"type":"network-error","url":"https://check.cymyv.icu/g
            2025-04-01 05:47:45 UTC214INHTTP/1.1 200 OK
            Content-Length: 0
            access-control-allow-origin: *
            vary: Origin
            date: Tue, 01 Apr 2025 05:47:44 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449733104.21.48.14436192C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-01 05:47:54 UTC709OUTGET /gkcxv.google HTTP/1.1
            Host: check.cymyv.icu
            Connection: keep-alive
            Cache-Control: max-age=0
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: cross-site
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-01 05:47:54 UTC846INHTTP/1.1 404 Not Found
            Date: Tue, 01 Apr 2025 05:47:54 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            cf-cache-status: DYNAMIC
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BB4QjJtJXLyyEKbyKg%2BWXHhUBtN7eRJNaQ1UTnjMev0IR2VDqYbawhQJH1xphy8pFFsy2aT%2F%2FwgHR3ZSRA9tzX%2BPKQ1UPWkyGKbzPocdhnmYnH6Rzb7IJYvD9ex8uyeys5M%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            speculation-rules: "/cdn-cgi/speculation"
            Server: cloudflare
            CF-RAY: 9295cb5f6c9325dc-EWR
            alt-svc: h3=":443"; ma=86400
            server-timing: cfL4;desc="?proto=TCP&rtt=97620&min_rtt=96232&rtt_var=21679&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2818&recv_bytes=1281&delivery_rate=31723&cwnd=252&unsent_bytes=0&cid=672e8c210c6335ec&ts=10692&x=0"
            2025-04-01 05:47:54 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            0510152025s020406080100

            Click to jump to process

            0510152025s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:01:47:32
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:01:47:36
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2524,i,908010192394182464,11261446003865537638,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2552 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:01:47:42
            Start date:01/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://check.cymyv.icu/gkcxv.google"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly