Edit tour

Windows Analysis Report
https://www.pdfskillsapp.com

Overview

General Information

Sample URL:https://www.pdfskillsapp.com
Analysis ID:1654103
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Multi AV Scanner detection for dropped file
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Suricata IDS alerts with low severity for network traffic

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6996 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6300 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1920,i,16582036239216053173,2715190799957100512,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1560 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 2984 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.pdfskillsapp.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-01T23:18:30.541163+020020221121Exploit Kit Activity Detected192.168.2.16497665.161.255.1443TCP
2025-04-01T23:18:41.154904+020020221121Exploit Kit Activity Detected192.168.2.16497675.161.255.1443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://dldtalent.com/download?visitor=99c94355-e563-4647-8fb2-1584c19a2698-c&agent=%257B%2522browserVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253AA-Brand%2522%252C%2522version%2522%253A%252224.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%255D%252C%2522platformVersion%2522%253A%252210.0.0%2522%252C%2522architecture%2522%253A%2522x86%2522%252C%2522mobile%2522%253Afalse%252C%2522platform%2522%253A%2522Windows%2522%257D&name=pdfskills&cid=null&adgroup_id=null&placement_id=null&creative_id=null&campaign_id=nullAvira URL Cloud: Label: malware
Source: C:\Users\user\Downloads\Unconfirmed 649834.crdownloadReversingLabs: Detection: 20%
Source: https://www.pdfskillsapp.com/HTTP Parser: No favicon
Source: https://www.pdfskillsapp.com/HTTP Parser: No favicon
Source: https://www.pdfskillsapp.com/HTTP Parser: No favicon
Source: https://www.pdfskillsapp.com/HTTP Parser: No favicon
Source: https://www.pdfskillsapp.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.130.137:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.41.4:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.174:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.155.154:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.194:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.100:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.238.55.96:443 -> 192.168.2.16:49750 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.54.30.30:443 -> 192.168.2.16:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.255.1:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.255.1:443 -> 192.168.2.16:49767 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49768 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.174:443 -> 192.168.2.16:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 1MB later: 31MB
Source: Network trafficSuricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.16:49766 -> 5.161.255.1:443
Source: Network trafficSuricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.16:49767 -> 5.161.255.1:443
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.64.67
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.64.67
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/style.css HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/logo.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/card-limits.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /ajax/libs/normalize/8.0.1/normalize.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/5.15.4/css/all.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/images/card-fast.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/card-secured.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/logo.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/logo-light.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/scripts.js HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/card-limits.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/images/card-secured.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/logo-light.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /assets/images/card-fast.png HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo
Source: global trafficHTTP traffic detected: GET /report?event_name=lpage_report&dataSet=report&platform=pc&infoJson=%7B%22distributer_id%22%3Anull%2C%22cid%22%3Anull%2C%22uuid%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22language%22%3A%22en-US%22%2C%22visit_num%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22user_agent%22%3A%22mozilla%2F5.0%20(windows%20nt%2010.0%3B%20win64%3B%20x64)%20applewebkit%2F537.36%20(khtml%2C%20like%20gecko)%20chrome%2F134.0.0.0%20safari%2F537.36%22%2C%22application%22%3A%221705825209490372%22%2C%22lp_id%22%3A%22%22%7D HTTP/1.1Host: mrt.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://www.pdfskillsapp.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /report?event_name=lpage_report&dataSet=report&platform=pc&infoJson=%7B%22distributer_id%22%3Anull%2C%22cid%22%3Anull%2C%22uuid%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22language%22%3A%22en-US%22%2C%22visit_num%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22user_agent%22%3A%22mozilla%2F5.0%20(windows%20nt%2010.0%3B%20win64%3B%20x64)%20applewebkit%2F537.36%20(khtml%2C%20like%20gecko)%20chrome%2F134.0.0.0%20safari%2F537.36%22%2C%22application%22%3A%221705825209490372%22%2C%22lp_id%22%3A%22%22%7D HTTP/1.1Host: mrt.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo; uuid=99c94355-e563-4647-8fb2-1584c19a2698-c; _gcl_au=1.1.349423907.1743542293; lpage_report_sent=true
Source: global trafficHTTP traffic detected: GET /td/ga/rul?tid=G-1T23SJFGC8&gacid=1495354347.1743542294&gtm=45je53v0v9192131470z89192109920za200zb9192109920&dma=0&gcs=G111&gcd=13t3t3t3t5l1&npa=0&pscdl=noapi&aip=1&fledge=1&frm=0&tag_exp=102788824~102803279~102813109~102887800~102926062~102964103~102975949~102976415&z=768009238 HTTP/1.1Host: td.doubleclick.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /td/rul/16657993244?random=1743542294520&cv=11&fst=1743542294520&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&ct_cookie_present=0 HTTP/1.1Host: td.doubleclick.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: test_cookie=CheckForPermission
Source: global trafficHTTP traffic detected: GET /td/rul/16657993244?random=1743542294530&cv=11&fst=1743542294530&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse HTTP/1.1Host: td.doubleclick.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: test_cookie=CheckForPermission
Source: global trafficHTTP traffic detected: GET /pagead/viewthroughconversion/16657993244/?random=1743542294530&cv=11&fst=1743542294530&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=4 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: test_cookie=CheckForPermission
Source: global trafficHTTP traffic detected: GET /pagead/1p-user-list/16657993244/?random=1743542294530&cv=11&fst=1743541200000&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=3&is_vtc=1&cid=CAQSKQCjtLzMlA6nMWRDCMEvRsKH_JWk0gQbHJ_LWWo8jOwWRDpC_8OEqXRC&random=206447747&rmt_tld=0&ipr=y HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/viewthroughconversion/16657993244/?random=1225794179&cv=11&fst=1743542294520&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABShVldmVudC1zb3VyY2UsIHRyaWdnZXJaAwoBAWIECgICAw&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LUJrQCgObKACLS5CmOC1OM_sL2QtuKhYvg&pscrd=CNXjx-yH24zojgEiEwjkptaZ4beMAxVED3EKHQ33D20yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bG8yeWxCZHJveWdqcTQ1OG1YX05taXpoQVRxMmRpekJWMnNVV0JEdkNHcTE5bjh2RzFuOTQ HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: IDE=AHWqTUllgivcorIm-o_gxV6WCsEZvTKvvr34yMHydtd_7t9ZwbdnqUGvZ1WSSnU_
Source: global trafficHTTP traffic detected: GET /.well-known/protected-auction/v1/public-keys HTTP/1.1Host: publickeyservice.pa.aws.privacysandboxservices.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /.well-known/protected-auction/v1/public-keys HTTP/1.1Host: publickeyservice.pa.gcp.privacysandboxservices.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=1225794179&cv=11&fst=1743542294520&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABShVldmVudC1zb3VyY2UsIHRyaWdnZXJaAwoBAWIECgICAw&pscrd=CNXjx-yH24zojgEiEwjkptaZ4beMAxVED3EKHQ33D20yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bG8yeWxCZHJveWdqcTQ1OG1YX05taXpoQVRxMmRpekJWMnNVV0JEdkNHcTE5bjh2RzFuOTQ&is_vtc=1&cid=CAQSKQCjtLzMSmNqVou6l2xmWB9HhlcV05UxNRe55VscuqRjI7WdIYHIPL7p&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3Lc_R52WGMofP6pDtCeh_J_vEwB6HcTQ-JQ&random=3574243805 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/1p-user-list/16657993244/?random=1743542294530&cv=11&fst=1743541200000&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=3&is_vtc=1&cid=CAQSKQCjtLzMlA6nMWRDCMEvRsKH_JWk0gQbHJ_LWWo8jOwWRDpC_8OEqXRC&random=206447747&rmt_tld=0&ipr=y HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CLbgygE=Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=1225794179&cv=11&fst=1743542294520&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABShVldmVudC1zb3VyY2UsIHRyaWdnZXJaAwoBAWIECgICAw&pscrd=CNXjx-yH24zojgEiEwjkptaZ4beMAxVED3EKHQ33D20yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bG8yeWxCZHJveWdqcTQ1OG1YX05taXpoQVRxMmRpekJWMnNVV0JEdkNHcTE5bjh2RzFuOTQ&is_vtc=1&cid=CAQSKQCjtLzMSmNqVou6l2xmWB9HhlcV05UxNRe55VscuqRjI7WdIYHIPL7p&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3Lc_R52WGMofP6pDtCeh_J_vEwB6HcTQ-JQ&random=3574243805 HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CLbgygE=Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/images/favicon.ico HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo; uuid=99c94355-e563-4647-8fb2-1584c19a2698-c; _gcl_au=1.1.349423907.1743542293; lpage_report_sent=true; _ga=GA1.1.1495354347.1743542294; _ga_1T23SJFGC8=GS1.1.1743542293.1.0.1743542293.60.0.55947760
Source: global trafficHTTP traffic detected: GET /assets/images/favicon.ico HTTP/1.1Host: www.pdfskillsapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=WN6zlurD.ysaIncOp14gD9c.HYREmVbhVgCmKtNjqdY-1743542292-1.0.1.1-IYJspa0DGVc55ah9U4_qtA5nWdVXnDNpfDpx1AZKWJThj_8kCgG97pdJ7.8sWPqZkGkJpJiNFn5aZIjJ_zsr9rjSNGbWUOQQX.tqd6RufGo; uuid=99c94355-e563-4647-8fb2-1584c19a2698-c; _gcl_au=1.1.349423907.1743542293; lpage_report_sent=true; _ga=GA1.1.1495354347.1743542294; _ga_1T23SJFGC8=GS1.1.1743542293.1.0.1743542293.60.0.55947760
Source: global trafficHTTP traffic detected: GET /td/rul/16657993244?random=1743542308008&cv=11&fst=1743542308008&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&ct_cookie_present=0 HTTP/1.1Host: td.doubleclick.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: IDE=AHWqTUllgivcorIm-o_gxV6WCsEZvTKvvr34yMHydtd_7t9ZwbdnqUGvZ1WSSnU_
Source: global trafficHTTP traffic detected: GET /download?visitor=99c94355-e563-4647-8fb2-1584c19a2698-c&agent=%257B%2522browserVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253AA-Brand%2522%252C%2522version%2522%253A%252224.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%255D%252C%2522platformVersion%2522%253A%252210.0.0%2522%252C%2522architecture%2522%253A%2522x86%2522%252C%2522mobile%2522%253Afalse%252C%2522platform%2522%253A%2522Windows%2522%257D&name=pdfskills&cid=null&adgroup_id=null&placement_id=null&creative_id=null&campaign_id=null HTTP/1.1Host: dldtalent.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/viewthroughconversion/16657993244/?random=1861038819&cv=11&fst=1743542308008&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABSid0cmlnZ2VyLCBldmVudC1zb3VyY2U7bmF2aWdhdGlvbi1zb3VyY2VaAwoBAWIECgICAw&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LWBcLLZZ2JlkxUt0NFF-h7-paK5EOWBAqQ&pscrd=CN6Sq4-ZiP_Y_wEiEwjg94Wg4beMAxUYDWgIHZK0IoIyDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bWlJNnVfVXYzMVVvUDFELVdBTGVwS2VWdjQ3NXRiTVB3UnVvWkpFcGUyV0sxSmJsVnZWYnM HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: IDE=AHWqTUllgivcorIm-o_gxV6WCsEZvTKvvr34yMHydtd_7t9ZwbdnqUGvZ1WSSnU_
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=1861038819&cv=11&fst=1743542308008&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABSid0cmlnZ2VyLCBldmVudC1zb3VyY2U7bmF2aWdhdGlvbi1zb3VyY2VaAwoBAWIECgICAw&pscrd=CN6Sq4-ZiP_Y_wEiEwjg94Wg4beMAxUYDWgIHZK0IoIyDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bWlJNnVfVXYzMVVvUDFELVdBTGVwS2VWdjQ3NXRiTVB3UnVvWkpFcGUyV0sxSmJsVnZWYnM&is_vtc=1&cid=CAQSKQCjtLzMRgCa1qszvIbydggVGZALseQs9kM0uCbkyAsDgkL-MGMFAC8V&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LfnLNiVR_s5o6IZjFqinweeMlQIp-yi1Dg&random=334361090 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=1861038819&cv=11&fst=1743542308008&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQIiAQE4AUABSid0cmlnZ2VyLCBldmVudC1zb3VyY2U7bmF2aWdhdGlvbi1zb3VyY2VaAwoBAWIECgICAw&pscrd=CN6Sq4-ZiP_Y_wEiEwjg94Wg4beMAxUYDWgIHZK0IoIyDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3bWlJNnVfVXYzMVVvUDFELVdBTGVwS2VWdjQ3NXRiTVB3UnVvWkpFcGUyV0sxSmJsVnZWYnM&is_vtc=1&cid=CAQSKQCjtLzMRgCa1qszvIbydggVGZALseQs9kM0uCbkyAsDgkL-MGMFAC8V&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LfnLNiVR_s5o6IZjFqinweeMlQIp-yi1Dg&random=334361090 HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CLbgygE=Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /download?visitor=99c94355-e563-4647-8fb2-1584c19a2698-c&agent=%257B%2522browserVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253AA-Brand%2522%252C%2522version%2522%253A%252224.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%255D%252C%2522platformVersion%2522%253A%252210.0.0%2522%252C%2522architecture%2522%253A%2522x86%2522%252C%2522mobile%2522%253Afalse%252C%2522platform%2522%253A%2522Windows%2522%257D&name=pdfskills&cid=null&adgroup_id=null&placement_id=null&creative_id=null&campaign_id=null HTTP/1.1Host: dldtalent.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9If-None-Match: W/"4aa128-bJDK5ixuS1x/vtKsEyUkEK8BMrw"
Source: global trafficHTTP traffic detected: GET /pagead/viewthroughconversion/16657993244/?random=2010800420&cv=11&fst=1743542319082&bg=ffffff&guid=ON&async=1&gcl_ctr=3&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQII_86xAiIBATgBQAFKLGV2ZW50LXNvdXJjZSwgdHJpZ2dlciwgbm90LW5hdmlnYXRpb24tc291cmNlWgMKAQFiBAoCAgM&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LR8oD6DfRicvZl1B0Tx2Syxx8MSuZX_ETw&pscrd=CNaF7YXXzoyUvwEiEwjG_6ql4beMAxUXAmgIHedhKU0yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3ay0yNHNMTmlkRzJWMXl0Q2xnWXBrTEdZV19lak9nTWJDcDFRdFhYVzNNc2gtRG91SFotOVE HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: IDE=AHWqTUllgivcorIm-o_gxV6WCsEZvTKvvr34yMHydtd_7t9ZwbdnqUGvZ1WSSnU_
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=2010800420&cv=11&fst=1743542319082&bg=ffffff&guid=ON&async=1&gcl_ctr=3&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQII_86xAiIBATgBQAFKLGV2ZW50LXNvdXJjZSwgdHJpZ2dlciwgbm90LW5hdmlnYXRpb24tc291cmNlWgMKAQFiBAoCAgM&pscrd=CNaF7YXXzoyUvwEiEwjG_6ql4beMAxUXAmgIHedhKU0yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3ay0yNHNMTmlkRzJWMXl0Q2xnWXBrTEdZV19lak9nTWJDcDFRdFhYVzNNc2gtRG91SFotOVE&is_vtc=1&cid=CAQSKQCjtLzMZy1vPA8N_b_ScQafwWF7csucQdjwDNz-dqqpP0rMLgTzdEqF&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LezK1PqQIve8J0PvuFuH0_D0xrntWhl8VQ&random=3161699583 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pagead/1p-conversion/16657993244/?random=2010800420&cv=11&fst=1743542319082&bg=ffffff&guid=ON&async=1&gcl_ctr=3&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&fmt=3&ct_cookie_present=false&crd=CPLOsQIIscGxAgiwwbECCLHDsQIIisWxAgjCybECCJDJsQII08WxAgjrzLECCM_OsQII_86xAiIBATgBQAFKLGV2ZW50LXNvdXJjZSwgdHJpZ2dlciwgbm90LW5hdmlnYXRpb24tc291cmNlWgMKAQFiBAoCAgM&pscrd=CNaF7YXXzoyUvwEiEwjG_6ql4beMAxUXAmgIHedhKU0yDAgDYggIABAAGAAgADIMCARiCAgAEAAYACAAMgwIB2IICAAQABgAIAAyDAgIYggIABAAGAAgADIMuserCAgAEAAYACAAMgwICmIICAAQABgAIAAyDAgCYggIABAAGAAgADIMCAtiCAgAEAAYACAAMgwIFWIICAAQABgAIAAyDAgfYggIABAAGAAgADIMCBNiCAgAEAAYACAAMgwIEmIICAAQABgAIAA6HWh0dHBzOi8vd3d3LnBkZnNraWxsc2FwcC5jb20vQldDaEVJOEoydXZ3WVFnZDNrLThieHd0Q3JBUklzQUYwOXk3ay0yNHNMTmlkRzJWMXl0Q2xnWXBrTEdZV19lak9nTWJDcDFRdFhYVzNNc2gtRG91SFotOVE&is_vtc=1&cid=CAQSKQCjtLzMZy1vPA8N_b_ScQafwWF7csucQdjwDNz-dqqpP0rMLgTzdEqF&eitems=ChAI8J2uvwYQ5uKz0erJvuxaEh0A1WG3LezK1PqQIve8J0PvuFuH0_D0xrntWhl8VQ&random=3161699583 HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CLbgygE=Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.pdfskillsapp.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: global trafficDNS traffic detected: DNS query: mrt.pdfskillsapp.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: analytics.google.com
Source: global trafficDNS traffic detected: DNS query: stats.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: td.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: publickeyservice.pa.gcp.privacysandboxservices.com
Source: global trafficDNS traffic detected: DNS query: publickeyservice.pa.aws.privacysandboxservices.com
Source: global trafficDNS traffic detected: DNS query: dldtalent.com
Source: unknownHTTP traffic detected: POST /ccm/collect?en=page_view&dl=https%3A%2F%2Fwww.pdfskillsapp.com%2F&scrsrc=www.googletagmanager.com&frm=0&rnd=968042264.1743542293&dt=PDF%20Skills&auid=349423907.1743542293&navt=n&npa=0&_tu=CA&gtm=45He53v0v9192109920za200&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887800~102926062~102964103~102975949~102976415&tft=1743542292674&tfd=2349&apve=1 HTTP/1.1Host: www.google.comConnection: keep-aliveContent-Length: 0sec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://www.pdfskillsapp.comX-Client-Data: CLbgygE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeReferer: https://www.pdfskillsapp.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.130.137:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.19.38:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.41.4:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.174:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.155.154:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.194:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.100:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.238.55.96:443 -> 192.168.2.16:49750 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.54.30.30:443 -> 192.168.2.16:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.18.38:443 -> 192.168.2.16:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.255.1:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 5.161.255.1:443 -> 192.168.2.16:49767 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49768 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.174:443 -> 192.168.2.16:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.80.66:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6996_619691386
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6996_619691386
Source: classification engineClassification label: mal56.win@27/34@32/303
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\d747315d-8045-490f-a1d0-2bca6162c286.tmp
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1920,i,16582036239216053173,2715190799957100512,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1560 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.pdfskillsapp.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1920,i,16582036239216053173,2715190799957100512,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=1560 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\c73d94a7-ecaa-4340-9b35-942058b09845.tmpJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\Unconfirmed 649834.crdownloadJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\d747315d-8045-490f-a1d0-2bca6162c286.tmpJump to dropped file
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
11
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.pdfskillsapp.com0%Avira URL Cloudsafe
SourceDetectionScannerLabelLink
C:\Users\user\Downloads\Unconfirmed 649834.crdownload21%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.pdfskillsapp.com/assets/scripts.js0%Avira URL Cloudsafe
https://mrt.pdfskillsapp.com/report?event_name=lpage_report&dataSet=report&platform=pc&infoJson=%7B%22distributer_id%22%3Anull%2C%22cid%22%3Anull%2C%22uuid%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22language%22%3A%22en-US%22%2C%22visit_num%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22user_agent%22%3A%22mozilla%2F5.0%20(windows%20nt%2010.0%3B%20win64%3B%20x64)%20applewebkit%2F537.36%20(khtml%2C%20like%20gecko)%20chrome%2F134.0.0.0%20safari%2F537.36%22%2C%22application%22%3A%221705825209490372%22%2C%22lp_id%22%3A%22%22%7D0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/logo.png0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/card-fast.png0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/card-limits.png0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/logo-light.png0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/favicon.ico0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/images/card-secured.png0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/assets/style.css0%Avira URL Cloudsafe
https://www.pdfskillsapp.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js0%Avira URL Cloudsafe
https://dldtalent.com/download?visitor=99c94355-e563-4647-8fb2-1584c19a2698-c&agent=%257B%2522browserVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253AA-Brand%2522%252C%2522version%2522%253A%252224.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%255D%252C%2522platformVersion%2522%253A%252210.0.0%2522%252C%2522architecture%2522%253A%2522x86%2522%252C%2522mobile%2522%253Afalse%252C%2522platform%2522%253A%2522Windows%2522%257D&name=pdfskills&cid=null&adgroup_id=null&placement_id=null&creative_id=null&campaign_id=null100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
code.jquery.com
151.101.130.137
truefalse
    high
    googleads.g.doubleclick.net
    142.250.80.66
    truefalse
      high
      cdnjs.cloudflare.com
      104.17.25.14
      truefalse
        high
        dldtalent.com
        5.161.255.1
        truefalse
          unknown
          www.pdfskillsapp.com
          104.18.18.38
          truefalse
            high
            publickeyservice-a.pa-3.gcp.privacysandboxservices.com
            34.54.30.30
            truefalse
              high
              www.google.com
              142.251.41.4
              truefalse
                high
                analytics.google.com
                142.251.35.174
                truefalse
                  high
                  td.doubleclick.net
                  142.250.65.194
                  truefalse
                    high
                    mrt.pdfskillsapp.com
                    104.18.19.38
                    truefalse
                      high
                      stats.g.doubleclick.net
                      192.178.155.154
                      truefalse
                        high
                        publickeyservice.pa-3.aws.privacysandboxservices.com
                        18.238.55.96
                        truefalse
                          high
                          publickeyservice.pa.gcp.privacysandboxservices.com
                          unknown
                          unknownfalse
                            high
                            publickeyservice.pa.aws.privacysandboxservices.com
                            unknown
                            unknownfalse
                              high
                              NameMaliciousAntivirus DetectionReputation
                              https://www.pdfskillsapp.com/assets/style.cssfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://www.pdfskillsapp.com/assets/images/card-secured.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://www.pdfskillsapp.com/assets/images/logo.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://www.pdfskillsapp.com/assets/images/logo-light.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://code.jquery.com/jquery-3.6.0.min.jsfalse
                                high
                                https://mrt.pdfskillsapp.com/report?event_name=lpage_report&dataSet=report&platform=pc&infoJson=%7B%22distributer_id%22%3Anull%2C%22cid%22%3Anull%2C%22uuid%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22language%22%3A%22en-US%22%2C%22visit_num%22%3A%2299c94355-e563-4647-8fb2-1584c19a2698-c%22%2C%22user_agent%22%3A%22mozilla%2F5.0%20(windows%20nt%2010.0%3B%20win64%3B%20x64)%20applewebkit%2F537.36%20(khtml%2C%20like%20gecko)%20chrome%2F134.0.0.0%20safari%2F537.36%22%2C%22application%22%3A%221705825209490372%22%2C%22lp_id%22%3A%22%22%7Dfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://www.pdfskillsapp.com/false
                                  unknown
                                  https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.4/css/all.min.cssfalse
                                    high
                                    https://www.pdfskillsapp.com/assets/scripts.jsfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://www.pdfskillsapp.com/assets/images/card-fast.pngfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://publickeyservice.pa.aws.privacysandboxservices.com/.well-known/protected-auction/v1/public-keysfalse
                                      high
                                      https://www.pdfskillsapp.com/assets/images/card-limits.pngfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://www.pdfskillsapp.com/assets/images/favicon.icofalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://cdnjs.cloudflare.com/ajax/libs/normalize/8.0.1/normalize.min.cssfalse
                                        high
                                        https://dldtalent.com/download?visitor=99c94355-e563-4647-8fb2-1584c19a2698-c&agent=%257B%2522browserVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253AA-Brand%2522%252C%2522version%2522%253A%252224.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522134.0.6998.36%2522%257D%255D%252C%2522platformVersion%2522%253A%252210.0.0%2522%252C%2522architecture%2522%253A%2522x86%2522%252C%2522mobile%2522%253Afalse%252C%2522platform%2522%253A%2522Windows%2522%257D&name=pdfskills&cid=null&adgroup_id=null&placement_id=null&creative_id=null&campaign_id=nulltrue
                                        • Avira URL Cloud: malware
                                        unknown
                                        https://www.pdfskillsapp.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.jsfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://publickeyservice.pa.gcp.privacysandboxservices.com/.well-known/protected-auction/v1/public-keysfalse
                                          high
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          142.250.80.46
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          104.18.18.38
                                          www.pdfskillsapp.comUnited States
                                          13335CLOUDFLARENETUSfalse
                                          172.253.63.84
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.251.40.227
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.251.40.202
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.250.80.66
                                          googleads.g.doubleclick.netUnited States
                                          15169GOOGLEUSfalse
                                          151.101.130.137
                                          code.jquery.comUnited States
                                          54113FASTLYUSfalse
                                          192.178.155.154
                                          stats.g.doubleclick.netUnited States
                                          15169GOOGLEUSfalse
                                          142.250.65.238
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          5.161.255.1
                                          dldtalent.comGermany
                                          24940HETZNER-ASDEfalse
                                          142.250.65.232
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          172.217.165.136
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          18.238.55.96
                                          publickeyservice.pa-3.aws.privacysandboxservices.comUnited States
                                          16509AMAZON-02USfalse
                                          142.251.35.174
                                          analytics.google.comUnited States
                                          15169GOOGLEUSfalse
                                          34.54.30.30
                                          publickeyservice-a.pa-3.gcp.privacysandboxservices.comUnited States
                                          2686ATGS-MMD-ASUSfalse
                                          1.1.1.1
                                          unknownAustralia
                                          13335CLOUDFLARENETUSfalse
                                          104.18.19.38
                                          mrt.pdfskillsapp.comUnited States
                                          13335CLOUDFLARENETUSfalse
                                          142.250.65.194
                                          td.doubleclick.netUnited States
                                          15169GOOGLEUSfalse
                                          142.250.81.228
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.250.80.99
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.251.40.100
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.251.40.98
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.251.32.110
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          142.250.176.194
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          104.17.25.14
                                          cdnjs.cloudflare.comUnited States
                                          13335CLOUDFLARENETUSfalse
                                          142.251.41.4
                                          www.google.comUnited States
                                          15169GOOGLEUSfalse
                                          142.251.35.163
                                          unknownUnited States
                                          15169GOOGLEUSfalse
                                          IP
                                          192.168.2.16
                                          192.168.2.4
                                          Joe Sandbox version:42.0.0 Malachite
                                          Analysis ID:1654103
                                          Start date and time:2025-04-01 23:17:34 +02:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                          Sample URL:https://www.pdfskillsapp.com
                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                          Number of analysed new started processes analysed:15
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • EGA enabled
                                          Analysis Mode:stream
                                          Analysis stop reason:Timeout
                                          Detection:MAL
                                          Classification:mal56.win@27/34@32/303
                                          • Exclude process from analysis (whitelisted): svchost.exe
                                          • Excluded IPs from analysis (whitelisted): 142.251.32.110, 142.250.80.99, 142.250.80.46, 172.253.63.84, 172.217.165.142, 142.251.40.238, 142.251.40.202, 142.251.40.110, 172.217.165.136, 142.250.65.232, 142.251.40.98, 142.250.176.194, 13.85.23.206, 20.12.23.50
                                          • Excluded domains from analysis (whitelisted): fonts.googleapis.com, www.googleadservices.com, accounts.google.com, slscr.update.microsoft.com, fonts.gstatic.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, redirector.gvt1.com, www.googletagmanager.com, glb.cws.prod.dcat.dsp.trafficmanager.net, clients.l.google.com
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                          • VT rate limit hit for: https://www.pdfskillsapp.com
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                          Category:dropped
                                          Size (bytes):0
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:0C51015F45CA531C063B1A828BCA322F
                                          SHA1:548D5B3113BA06B5882309202CDBEDC697CDE6A5
                                          SHA-256:A785BE911DB7BA1AE6D7D18870190246BBC7285452C5E6C5C92F14E444FE87B9
                                          SHA-512:12D377DAA8C3EAF27D76C7EE2FF1AC886C2E53F9F91C8CE744927DAA27E1AA1726B8DFCCBEA296C4B6B2EB2E44B83824DE6CC934D884C442B8EFF4EB0E85D359
                                          Malicious:true
                                          Reputation:unknown
                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...6............"...0..,J..D........... .....@..... ........................J..... .J...`...@......@............... ...............................`J..C...........rJ.(/...........KJ.............................................................. ..H............text....+J.. ...,J................. ..`.rsrc....C...`J..D....J.............@..@........................................H.......XF...m..........@...p.I.........................................z..(....s.....(.....(....o....*Bs....(....(}...*2s....o....&*..( ...*..(!...*.~....-.r...p.....("...o#...s$........~....*.~....*.......*.~....*..(%...*Vs....(&...t.........*..{....*"..}....*..{....*..('....(.....(......((.....}....*&..(.....*J.(.....(....o....*J.(.....(....o....*.0..q........(.....r?..p(.....R.(d...o.....(y........U...%...o)....%.(*....%..o+....%.r...p.%..o,....(-...o.......(....o....*...........
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                          Category:dropped
                                          Size (bytes):4890920
                                          Entropy (8bit):7.805093483132582
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:6993F5E370CA16EF520108FC8E24ECF5
                                          SHA1:6C90CAE62C6E4B5C7FBED2AC13252410AF0132BC
                                          SHA-256:1994B6C8C30B4346F6B00DA12FC161EB73210AF08B914A1C4768B109B234F2DF
                                          SHA-512:928216309D8303108EBD29E8AC29DE57E6B5DB11995E912CEF2B4E47671A8DD92745AA3CB846FE8D10AE064413B77873E222F49DB8B6938E738CBBBC4FB69724
                                          Malicious:true
                                          Antivirus:
                                          • Antivirus: ReversingLabs, Detection: 21%
                                          Reputation:unknown
                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...6............"...0..,J..D........... .....@..... ........................J..... .J...`...@......@............... ...............................`J..C...........rJ.(/...........KJ.............................................................. ..H............text....+J.. ...,J................. ..`.rsrc....C...`J..D....J.............@..@........................................H.......XF...m..........@...p.I.........................................z..(....s.....(.....(....o....*Bs....(....(}...*2s....o....&*..( ...*..(!...*.~....-.r...p.....("...o#...s$........~....*.~....*.......*.~....*..(%...*Vs....(&...t.........*..{....*"..}....*..{....*..('....(.....(......((.....}....*&..(.....*J.(.....(....o....*J.(.....(....o....*.0..q........(.....r?..p(.....R.(d...o.....(y........U...%...o)....%.(*....%..o+....%.r...p.%..o,....(-...o.......(....o....*...........
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                          Category:dropped
                                          Size (bytes):4128768
                                          Entropy (8bit):7.762846449744175
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:0C51015F45CA531C063B1A828BCA322F
                                          SHA1:548D5B3113BA06B5882309202CDBEDC697CDE6A5
                                          SHA-256:A785BE911DB7BA1AE6D7D18870190246BBC7285452C5E6C5C92F14E444FE87B9
                                          SHA-512:12D377DAA8C3EAF27D76C7EE2FF1AC886C2E53F9F91C8CE744927DAA27E1AA1726B8DFCCBEA296C4B6B2EB2E44B83824DE6CC934D884C442B8EFF4EB0E85D359
                                          Malicious:true
                                          Reputation:unknown
                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...6............"...0..,J..D........... .....@..... ........................J..... .J...`...@......@............... ...............................`J..C...........rJ.(/...........KJ.............................................................. ..H............text....+J.. ...,J................. ..`.rsrc....C...`J..D....J.............@..@........................................H.......XF...m..........@...p.I.........................................z..(....s.....(.....(....o....*Bs....(....(}...*2s....o....&*..( ...*..(!...*.~....-.r...p.....("...o#...s$........~....*.~....*.......*.~....*..(%...*Vs....(&...t.........*..{....*"..}....*..{....*..('....(.....(......((.....}....*&..(.....*J.(.....(....o....*J.(.....(....o....*.0..q........(.....r?..p(.....R.(d...o.....(y........U...%...o)....%.(*....%..o+....%.r...p.%..o,....(-...o.......(....o....*...........
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                          Category:dropped
                                          Size (bytes):8434
                                          Entropy (8bit):4.830956452633078
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:F2B4A37EE95D736A6F358832DC222741
                                          SHA1:F490263E6A774AD3319E6C618FDC2F93447DD459
                                          SHA-256:94289ECDB1F9C18586C676B911561D4BFD4582D37C71FCE7FF487AEED0C25B1C
                                          SHA-512:8A3C07C8F674CB74D46DD927C848D03FA0B5A8F279EA4D49F94D4E41C393FB52BDD108C3E2B03BA7451D6643E8AC9D6AAB6F245FF819B7EC6DAEDC60C04D4891
                                          Malicious:true
                                          Reputation:unknown
                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...6............"...0..,J..D........... .....@..... ........................J..... .J...`...@......@............... ...............................`J..C...........rJ.(/...........KJ.............................................................. ..H............text....+J.. ...,J................. ..`.rsrc....C...`J..D....J.............@..@........................................H.......XF...m..........@...p.I.........................................z..(....s.....(.....(....o....*Bs....(....(}...*2s....o....&*..( ...*..(!...*.~....-.r...p.....("...o#...s$........~....*.~....*.......*.~....*..(%...*Vs....(&...t.........*..{....*"..}....*..{....*..('....(.....(......((.....}....*&..(.....*J.(.....(....o....*J.(.....(....o....*.0..q........(.....r?..p(.....R.(d...o.....(y........U...%...o)....%.(*....%..o+....%.r...p.%..o,....(-...o.......(....o....*...........
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                          Category:dropped
                                          Size (bytes):0
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:6993F5E370CA16EF520108FC8E24ECF5
                                          SHA1:6C90CAE62C6E4B5C7FBED2AC13252410AF0132BC
                                          SHA-256:1994B6C8C30B4346F6B00DA12FC161EB73210AF08B914A1C4768B109B234F2DF
                                          SHA-512:928216309D8303108EBD29E8AC29DE57E6B5DB11995E912CEF2B4E47671A8DD92745AA3CB846FE8D10AE064413B77873E222F49DB8B6938E738CBBBC4FB69724
                                          Malicious:true
                                          Reputation:unknown
                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...6............"...0..,J..D........... .....@..... ........................J..... .J...`...@......@............... ...............................`J..C...........rJ.(/...........KJ.............................................................. ..H............text....+J.. ...,J................. ..`.rsrc....C...`J..D....J.............@..@........................................H.......XF...m..........@...p.I.........................................z..(....s.....(.....(....o....*Bs....(....(}...*2s....o....&*..( ...*..(!...*.~....-.r...p.....("...o#...s$........~....*.~....*.......*.~....*..(%...*Vs....(&...t.........*..{....*"..}....*..{....*..('....(.....(......((.....}....*&..(.....*J.(.....(....o....*J.(.....(....o....*.0..q........(.....r?..p(.....R.(d...o.....(y........U...%...o)....%.(*....%..o+....%.r...p.%..o,....(-...o.......(....o....*...........
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:C++ source, ASCII text
                                          Category:downloaded
                                          Size (bytes):6314
                                          Entropy (8bit):4.760707834967574
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:1F54912CAAD56B182BC2E7CF0AB78AE9
                                          SHA1:E3E8302F04B9FED9753F40A9A6540863D60F948C
                                          SHA-256:F4AD03E9312619E22B83DC57B1DD5EB46C3C09B6B98F1DC384302B04D6840967
                                          SHA-512:4A26FDD95FB24ED5A3E5FDADD98D0B1567C85406B295E34399FC3F124C2FB58C5F6BE0EC8B056F0A51D2AF39E03B85CF3805E2F0AF1C51E21490793FC9E6C25A
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/assets/scripts.js
                                          Preview:const REPORT_PATH = 'https://mrt.pdfskillsapp.com/report?';.const DL_DOMAIN = "https://dldtalent.com";..function setCookie(name, value, days = 365) {. var expires = "";. if (days) {. var date = new Date();. date.setTime(date.getTime() + (days * 24 * 60 * 60 * 1000));. expires = "; expires=" + date.toUTCString();. }. var domain = "." + window.location.hostname.split('.').slice(-2).join('.'); // Get root domain. document.cookie = name + "=" + encodeURIComponent(value) + expires + "; path=/" + "; domain=" + domain;.}..const getCookie = name => {. const cookie = document.cookie.match(`(^|;) ?${name}=([^;]*)(;|$)`);. return cookie ? cookie[2] : null;.};..function generateUUID() {. const uuid = crypto.randomUUID . ? crypto.randomUUID() . : 'xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx'.replace(/[xy]/g, function(c) {. var r = (Math.random() * 16) | 0,. v = c === 'x' ? r : (r & 0x3) | 0x8;. return v.toStrin
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (17272)
                                          Category:downloaded
                                          Size (bytes):454775
                                          Entropy (8bit):5.6555669555591725
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:7E569F4AFF60421820A9F3987585CFBB
                                          SHA1:7CE865350B054A212C593E1B1E068E35AFC89B23
                                          SHA-256:D63ADD5AB3CEBB866AA7667F3881D1AE6E1A897F0165006488F6BC2033658A49
                                          SHA-512:92EE68AF4D0CAFC4D79DA92AC9AA1486CA2EA04DE39FB2FBE158ABFAB3C67D085C2F77FBFF42F22416114801DAC85407633DDE1F4A8358F8D5C6EB62F1AB09C5
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googletagmanager.com/gtag/js?id=G-1T23SJFGC8&l=dataLayer&cx=c&gtm=45He53v0v9192109920za200&tag_exp=102788824~102803279~102813109~102887800~102926062~102964103~102975949~102976415
                                          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":17,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_manualEmailEnabled":false,"vtp_cityValue":"","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneValue":"","vtp_autoPhoneEnabled":false,"vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"","vtp_isAutoCollectPiiEnabledFlag":false,"tag_id":4},{"function":"__ccd_ga_first","priority":16,"vtp_instanceDestinationId":"G-1T23SJFGC8","tag_id":22},{"function":"__set_product_settings","priority":15,"vtp_instanceDestinationId":"G-1T23SJFGC8","vtp_foreignTldMacroResult":["macro",1],"vtp_isCh
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (65536), with no line terminators
                                          Category:downloaded
                                          Size (bytes):84064
                                          Entropy (8bit):5.488472670481671
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:C287B5E79E933404F26196EE50435025
                                          SHA1:53FBC9B31656F32973116D19BDC064318C9AFA71
                                          SHA-256:6D661570239E7355EF3EEC043D466A3F3345D9A69B8D8639B3DB4B781C493A8F
                                          SHA-512:AE99B8F91C67ACF9E39C1F1654244A704ADD4E0745C0F5D141E389A1B411CA12CA50560F6E50B7470238014756C53C97298C889976ABA57B8E2B3593B772AA29
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://td.doubleclick.net/td/rul/16657993244?random=1743542294530&cv=11&fst=1743542294530&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse
                                          Preview:<html><body><script>var ig_list={"interestGroups":[{"action":0,"expirationTimeInSeconds":7775996,"interestGroupAttributes":{"owner":"https://td.doubleclick.net","name":"4s349423907.1743542293","biddingLogicUrl":"https://td.doubleclick.net/td/bjs","dailyUpdateUrl":"https://td.doubleclick.net/td/update?ig_name=4s349423907.1743542293\u0026ig_key=1sNHMzNDk0MjM5MDcuMTc0MzU0MjI5Mw!2saGL_FA!3sAAptDV6mpz6J\u0026tag_eid=44804419","trustedBiddingSignalsUrl":"https://td.doubleclick.net/td/bts","trustedBiddingSignalsKeys":["1s0FkH3Q!2saGL_FA!3sAAptDV6mpz6J","1i44804419"],"userBiddingSignals":[["8730873404","8731847256","8732212382"],null,1743542295996264],"ads":[{"renderUrl":"https://tdsf.doubleclick.net/td/adfetch/gda?adg_id=180081824041\u0026cr_id=739195573650\u0026cv_id=0\u0026format=${AD_WIDTH}x${AD_HEIGHT}\u0026rds=${RENDER_DATA}\u0026seat=2\u0026rp_id=r1j8732212382!4s*2A","metadata":["180081824041","739195573650",null,"22344402479",null,null,null,null,null,null,"8732212382"],"adRenderId":"Ir
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (3898), with no line terminators
                                          Category:downloaded
                                          Size (bytes):3898
                                          Entropy (8bit):5.806701383272077
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:DE1234837FAD5850CD59213AB2344B9F
                                          SHA1:FF77B5D18E4AB44275413E265A402CDBF0C6E08A
                                          SHA-256:F8C7DEFFCF6D64927B2DAEF21572DD5F23B332F580C7A18964E370A51CBE2FD0
                                          SHA-512:FAF21EDD5D822A91D70E758C1E435BAB1B556715E30D2339078578DEAFFC1755839945891477F903B81BE8AEC707363E433DE879874DF917C40BBB617E34C3BD
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://googleads.g.doubleclick.net/pagead/viewthroughconversion/16657993244/?random=1743542294530&cv=11&fst=1743542294530&bg=ffffff&guid=ON&async=1&gtm=45be53v0z89192109920za201zb9192131470&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=4
                                          Preview:(function(){var s = {};(function(){var k=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,d,b){if(a==Array.prototype||a==Object.prototype)return a;a[d]=b.value;return a};function l(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var d=0;d<a.length;++d){var b=a[d];if(b&&b.Math==Math)return b}throw Error("Cannot find global object");} var p=l(this),q=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",r={},t={};function u(a,d,b){if(!b||a!=null){b=t[d];if(b==null)return a[d];b=a[b];return b!==void 0?b:a[d]}} function v(a,d,b){if(d)a:{var c=a.split(".");a=c.length===1;var e=c[0],g;!a&&e in r?g=r:g=p;for(e=0;e<c.length-1;e++){var f=c[e];if(!(f in g))break a;g=g[f]}c=c[c.length-1];b=q&&b==="es6"?g[c]:null;d=d(b);d!=null&&(a?k(r,c,{configurable:!0,writable:!0,value:d}):d!==b&&(t[c]===void 0&&(a=Math.random()*1E9>>>0,t[c]=q?p.Symbol(c):"$jscp$"+a+"$"+c),k(g,t[c],{co
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with no line terminators
                                          Category:downloaded
                                          Size (bytes):13
                                          Entropy (8bit):2.7773627950641693
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:C83301425B2AD1D496473A5FF3D9ECCA
                                          SHA1:941EFB7368E46B27B937D34B07FC4D41DA01B002
                                          SHA-256:B633A587C652D02386C4F16F8C6F6AAB7352D97F16367C3C40576214372DD628
                                          SHA-512:83BAFE4C888008AFDD1B72C028C7F50DEE651CA9E7D8E1B332E0BF3AA1315884155A1458A304F6E5C5627E714BF5A855A8B8D7DB3F4EB2BB2789FE2F8F6A1D83
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://td.doubleclick.net/td/ga/rul?tid=G-1T23SJFGC8&gacid=1495354347.1743542294&gtm=45je53v0v9192131470z89192109920za200zb9192109920&dma=0&gcs=G111&gcd=13t3t3t3t5l1&npa=0&pscdl=noapi&aip=1&fledge=1&frm=0&tag_exp=102788824~102803279~102813109~102887800~102926062~102964103~102975949~102976415&z=768009238
                                          Preview:<html></html>
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (65536), with no line terminators
                                          Category:downloaded
                                          Size (bytes):84064
                                          Entropy (8bit):5.4883966303688085
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:7279E5A92DFF92EE24165CF78F4897AC
                                          SHA1:8E39681A8225E34CA5D67E9685AF6EEECB27C318
                                          SHA-256:F7F37F434E19744C0D6A548AEBB2FE02E7CD017C5C45A10ECA96C82290866623
                                          SHA-512:C9075F527888140EDEA0E967B45E7B359A9F4304DC3E02F89510A6B9636F8962F4172206FA1612436DDAEBBDCBDC0181410451B9A4514B20BBF20B6A819918D3
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://td.doubleclick.net/td/rul/16657993244?random=1743542308008&cv=11&fst=1743542308008&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&ct_cookie_present=0
                                          Preview:<html><body><script>var ig_list={"interestGroups":[{"action":0,"expirationTimeInSeconds":7775983,"interestGroupAttributes":{"owner":"https://td.doubleclick.net","name":"4s349423907.1743542293","biddingLogicUrl":"https://td.doubleclick.net/td/bjs","dailyUpdateUrl":"https://td.doubleclick.net/td/update?ig_name=4s349423907.1743542293\u0026ig_key=1sNHMzNDk0MjM5MDcuMTc0MzU0MjI5Mw!2saGL_FA!3sAAptDV6mpz6J\u0026tag_eid=44804419","trustedBiddingSignalsUrl":"https://td.doubleclick.net/td/bts","trustedBiddingSignalsKeys":["1s0FkH3Q!2saGL_FA!3sAAptDV6mpz6J","1i44804419"],"userBiddingSignals":[["8731847256","8732212382","8730873404"],null,1743542309466106],"ads":[{"renderUrl":"https://tdsf.doubleclick.net/td/adfetch/gda?adg_id=180081824041\u0026cr_id=739195573650\u0026cv_id=0\u0026format=${AD_WIDTH}x${AD_HEIGHT}\u0026rds=${RENDER_DATA}\u0026seat=2\u0026rp_id=r1j8731847256!4s*2A","metadata":["180081824041","739195573650",null,"22344402479",null,null,null,null,null,null,"8731847256"],"adRenderId":"-s
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                          Category:dropped
                                          Size (bytes):7447
                                          Entropy (8bit):7.9656287427263255
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:25788859DF46DF4ECDF1031DAF69AE07
                                          SHA1:57D13B7931DBEA680C60291BDD6ED4BD43874197
                                          SHA-256:05E190940649BEF295F49C5369BBDACA114DEDC6DC06BABC92C36D819F8ACEE1
                                          SHA-512:F3095CE4006E8F5020ECF47BB4B3DC32615D777B3CBE9D24D36BBC4F923F09B4D7F43D1D7E65F8222131E9CF1039FD0B70176FD9F0ECD486E1EC2CACF2B48C8E
                                          Malicious:false
                                          Reputation:unknown
                                          Preview:.PNG........IHDR.............<.q.....IDATx...TT....{3(.wHl...Qc...mM..n...O....$*h.v........19I.n...{.$.xNw.l.I.X'M.[..._.$..$.De.'....y..0.....|.s.0..}........000..K.Rkl."0.........&.J..b...I..\.o;. l. .A+.........5..'..R..uw.=_~|...BD.+..b...l.....4.......c1_;.r.3/u_..$........E./...H.&....?....mj.0/:..4..z"RX.D5v.............s........BF..K....1.\\QWN,5,Wh.(a.......rE'...z....N.....(PW!*/$.....k5Kq.x..-....V....A...u.H.)4Z...vji.WfVu]....AC..C.u.W..1.a.............AP..2.1.(.".;%......j.c..b.x.....][,9X.1.a.$].6.[.WDSA`..tk...J.*;3K(6.@._O.........]...0.(..Xn&..N.U=.T..[..i....`.pt),r.((k...1s......E...(..B.!kHV..3.V......{.Zd......D.}.->-.......E.1V.l.8..{.%2a..g...`..A.....:...A(....W.B..%`.7.)M&k.....eC8hik.7...e..3..4.{.D7....J..=...E........e`..........WC8Y.....X..~..a..m[..BH.4..... 1!.f..G..B&.. 7<.U.....G.VP^+..."..".<y.u...<...........<...^..:...O...;.......2f.....?...k......6'm:he..yp.......j&.y....S....W@-..|....*..;..n..
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text
                                          Category:downloaded
                                          Size (bytes):20707
                                          Entropy (8bit):4.935166461692911
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:14033CD91EDBFB19872F526965D69FBC
                                          SHA1:457F809895B9A0A43AF023C38582C1B02C782CAA
                                          SHA-256:A5B68959D4180D5DF0A7A62E4D3A09544C696443E0BAF642D3EAF14B0AE05FA7
                                          SHA-512:075A1E94593D1E545EF8707A2DE1551AC55C536FA3F95235BFFAB96CD469C95FBBA480E028DE4E9243BCBBDF697464205E0564882026F98347712735DFDE43FE
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/assets/style.css
                                          Preview:@import url("https://fonts.googleapis.com/css2?family=DM+Sans:wght@400;500;700&display=swap");./* Apply this to the entire page to prevent horizontal scrolling */.* {. box-sizing: border-box; /* Ensures padding and borders are included in width/height */.}.html,.body {. overflow-x: hidden;.}.body {. margin: 0;. font-family: "DM Sans", sans-serif;.}..h1 {. font-size: 70px;.}..h2 {. font-size: 60px;.}..h3 {. font-size: 50px;.}..p {. font-size: 10px;.}...vertical-align {. display: flex;. flex-direction: column;. justify-content: center;.}...light-bg {. background-color: #fefefe;.}...align-center {. text-align: center;.}...align-right {. text-align: right;.}...align-left {. text-align: left !important;.}...my-1 {. margin: 1rem 0;.}...mt-1 {. margin-top: 1rem;.}...mb-1 {. margin-bottom: 1rem;.}...my-2 {. margin: 2rem 0;.}...mt-2 {. margin-top: 2rem;.}...mb-2 {. margin-bottom: 2rem;.}...my-3 {. margin: 3.5rem 0;.}...mt-3 {. margin-top: 3.5rem;.}...mb-3 {. margin-botto
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 26 x 36, 8-bit/color RGBA, non-interlaced
                                          Category:dropped
                                          Size (bytes):689
                                          Entropy (8bit):7.526737190463689
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:2115C8AE609AA91AE3B41239BB57C713
                                          SHA1:D57BFB185960AAB1B7578C65E0B8E67246ECF1B1
                                          SHA-256:FBDA9FCEACAA2443705E43151430FA4FA1C3603AF522636509BEE492F415D318
                                          SHA-512:BC67C93FB739D3695892AFF24090197BD040B0068EB872F11CCC27E45E58CCEAC33AE50812FA072F6637FFA1F6058C5276B9A49506F315800F7658AD77382B9D
                                          Malicious:false
                                          Reputation:unknown
                                          Preview:.PNG........IHDR.......$......:*.....pHYs.................sRGB.........gAMA......a....FIDATx....q.@........... .A. ..I..........T`RA... dl.-.mv%K#................o...<{...&.?....y...V>....(.P...;.~e.a)..?... %.g..06.ny..ZY...A...z..S.LK..#t..t...................f...$...E..l,..:...c)N.....("Z3.6._E ".G.Q.ye....XF ...j.1...p...f..j.A.h....`....2.)u...Y..'..2..u.0.By...n.LR..Ww.R`..rY...B./. ......:...O.X..*t..SU..7Q1..Y#.e._;.....D..&R..j...6....W....._..TN\..p&.*]'....L.....:.T............?K..<.<.%..c.&..dV.n......ge......@.vr...tR.Z......bh=>......L..y+..V..t.j.$....62.l.Y.d..q.....n.$^..9.G...,Y"#......zl.;=..1r.}>+..2...Ldg^S...#W....T.+.;}.....IEND.B`.
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, Unicode text, UTF-8 text
                                          Category:downloaded
                                          Size (bytes):7410
                                          Entropy (8bit):4.505184292368631
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:8505217D79EB8B4E5EA13CF21185F8AF
                                          SHA1:1C855A2D510AD5FF96AA40511D73721F6E41088E
                                          SHA-256:B282FA567E65C2D36E88697C64AF7E58E75CFC2A6BFC0A71B8746BE9C32E9727
                                          SHA-512:D7CE48647BE372B7ED8FAF27D7C1B492745B62AA04E8AFCC652BA3641EB295C9AA7956BB81C825F46AF6BC79AF124110D9DC5036BF2C9C04E4B107E38CB73519
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/
                                          Preview:<!DOCTYPE html>.<html lang="en">..<head>. Meta Tags -->. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>PDF Skills</title>. Normalize CSS -->. <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/normalize/8.0.1/normalize.min.css">. FontAwesome CSS -->. <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.4/css/all.min.css">. Custom Stylesheet -->. <link rel="stylesheet" href="assets/style.css">. Favicon -->. <link rel="icon" href="assets/images/favicon.ico" type="image/x-icon">. Google Tag Manager -->. <script>. (function (w, d, s, l, i) {. w[l] = w[l] || []; w[l].push({. 'gtm.start':. new Date().getTime(), event: 'gtm.js'. }); var f = d.getElementsByTagName(s)[0],. j = d.createElement(s), dl = l != 'dataLayer' ? '&l=' + l : ''; j.asyn
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text
                                          Category:downloaded
                                          Size (bytes):2613
                                          Entropy (8bit):5.365928254771976
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:E886D481E3A09D9C59E9592A2E5C26A3
                                          SHA1:17808F0A187C25DA3C83C480DEB3CCCD2262FA74
                                          SHA-256:3152C018F548899E2DA6FE638841EF215A059D73007F3986A28153DC39983201
                                          SHA-512:01ED71C3198B4532F77297B6F234A05929609FFDEABAB84242A2B956B8F8086ECD70F7DDC53E0F908B2D536773A88D0E63080A26C33B320A72C4D653F500C208
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://fonts.googleapis.com/css2?family=DM+Sans:wght@400;500;700&display=swap
                                          Preview:/* latin-ext */.@font-face {. font-family: 'DM Sans';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/dmsans/v15/rP2Yp2ywxg089UriI5-g4vlH9VoD8Cmcqbu6-K6h9Q.woff2) format('woff2');. unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'DM Sans';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/dmsans/v15/rP2Yp2ywxg089UriI5-g4vlH9VoD8Cmcqbu0-K4.woff2) format('woff2');. unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;.}./* latin-ext */.@font-face {. font-family: 'DM Sans';. font-style: normal;. font-weight: 500;. font-display: swap;. src: url
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (59119)
                                          Category:downloaded
                                          Size (bytes):59305
                                          Entropy (8bit):4.716988765402807
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:ECD507B3125EDC4D2A03AA6AE5D07DA9
                                          SHA1:A57EE68D11601B0FD8E5037FC241FF65A754473C
                                          SHA-256:99464CEB71BC9BBDCC72275FAEFE44F98EB5CBB6B5D8EE665B87B35376F1A96E
                                          SHA-512:D72727E8871A410E34FCC2815B65B84618ACFC36C82D4EF80B5BD2ACB2710AAE7BA3DE35626D354B036C38CAAF10116572051AEB12E23D8FCD4B947E13ACED25
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.4/css/all.min.css
                                          Preview:/*!. * Font Awesome Free 5.15.4 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). */..fa,.fab,.fad,.fal,.far,.fas{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:inline-block;font-style:normal;font-variant:normal;text-rendering:auto;line-height:1}.fa-lg{font-size:1.33333em;line-height:.75em;vertical-align:-.0667em}.fa-xs{font-size:.75em}.fa-sm{font-size:.875em}.fa-1x{font-size:1em}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-6x{font-size:6em}.fa-7x{font-size:7em}.fa-8x{font-size:8em}.fa-9x{font-size:9em}.fa-10x{font-size:10em}.fa-fw{text-align:center;width:1.25em}.fa-ul{list-style-type:none;margin-left:2.5em;padding-left:0}.fa-ul>li{position:relative}.fa-li{left:-2em;position:absolute;text-align:center;width:2em;line-height:inherit}.fa-border{border:.08em solid #eee;border-radius:.1em;padding:.2em .25em .15em}.fa-pu
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (6253), with no line terminators
                                          Category:downloaded
                                          Size (bytes):6253
                                          Entropy (8bit):6.012507616334301
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:9AB9CDA60FF96FF4F5B6398253E20F90
                                          SHA1:D3446EAAAF9396F29C95BDB36344BC7B1313F7E8
                                          SHA-256:F5FE1857EA9F4472FDA6B28ACBE881E160339FB46130785A5F461382D5D12C2B
                                          SHA-512:25FDC53E6B6ADE5347D8EC4544FDC256CD914F80E58271056C083EF45A10CD400FEA03A30FEA362F8B62D4BCCA1AFF064B92101C13D6F861D05FCC9B0557A31E
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googleadservices.com/pagead/conversion/16657993244/?random=1743542319082&cv=11&fst=1743542319082&bg=ffffff&guid=ON&async=1&gcl_ctr=3&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=4
                                          Preview:(function(){var s = {};(function(){var k=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,d,b){if(a==Array.prototype||a==Object.prototype)return a;a[d]=b.value;return a};function l(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var d=0;d<a.length;++d){var b=a[d];if(b&&b.Math==Math)return b}throw Error("Cannot find global object");} var p=l(this),q=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",r={},t={};function u(a,d,b){if(!b||a!=null){b=t[d];if(b==null)return a[d];b=a[b];return b!==void 0?b:a[d]}} function v(a,d,b){if(d)a:{var c=a.split(".");a=c.length===1;var e=c[0],g;!a&&e in r?g=r:g=p;for(e=0;e<c.length-1;e++){var f=c[e];if(!(f in g))break a;g=g[f]}c=c[c.length-1];b=q&&b==="es6"?g[c]:null;d=d(b);d!=null&&(a?k(r,c,{configurable:!0,writable:!0,value:d}):d!==b&&(t[c]===void 0&&(a=Math.random()*1E9>>>0,t[c]=q?p.Symbol(c):"$jscp$"+a+"$"+c),k(g,t[c],{co
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (1238)
                                          Category:downloaded
                                          Size (bytes):1239
                                          Entropy (8bit):5.068464054671174
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:9E8F56E8E1806253BA01A95CFC3D392C
                                          SHA1:A8AF90D7482E1E99D03DE6BF88FED2315C5DD728
                                          SHA-256:2595496FE48DF6FCF9B1BC57C29A744C121EB4DD11566466BC13D2E52E6BBCC8
                                          SHA-512:63F0F6F94FBABADC3F774CCAA6A401696E8A7651A074BC077D214F91DA080B36714FD799EB40FED64154972008E34FC733D6EE314AC675727B37B58FFBEBEBEE
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js
                                          Preview:!function(){"use strict";function e(e){try{if("undefined"==typeof console)return;"error"in console?console.error(e):console.log(e)}catch(e){}}function t(e){return d.innerHTML='<a href="'+e.replace(/"/g,"&quot;")+'"></a>',d.childNodes[0].getAttribute("href")||""}function r(e,t){var r=e.substr(t,2);return parseInt(r,16)}function n(n,c){for(var o="",a=r(n,c),i=c+2;i<n.length;i+=2){var l=r(n,i)^a;o+=String.fromCharCode(l)}try{o=decodeURIComponent(escape(o))}catch(u){e(u)}return t(o)}function c(t){for(var r=t.querySelectorAll("a"),c=0;c<r.length;c++)try{var o=r[c],a=o.href.indexOf(l);a>-1&&(o.href="mailto:"+n(o.href,a+l.length))}catch(i){e(i)}}function o(t){for(var r=t.querySelectorAll(u),c=0;c<r.length;c++)try{var o=r[c],a=o.parentNode,i=o.getAttribute(f);if(i){var l=n(i,0),d=document.createTextNode(l);a.replaceChild(d,o)}}catch(h){e(h)}}function a(t){for(var r=t.querySelectorAll("template"),n=0;n<r.length;n++)try{i(r[n].content)}catch(c){e(c)}}function i(t){try{c(t),o(t),a(t)}catch(r){e(r
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (8133)
                                          Category:downloaded
                                          Size (bytes):326205
                                          Entropy (8bit):5.5807035436040255
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:60708A3FF11B929E0CC963DC63E7FDF1
                                          SHA1:2D4520BB2B6E752F80CF10050DC969B5F124A98F
                                          SHA-256:F34E49E8A529519E33BCA2EDAA2572607F06CA9803E62C7DD9D17F3F0D22295A
                                          SHA-512:9EF2AD50580FDBEEA53D9B550785368F4353949632C73D70D033544A8225903DD69E162C255940EFFD4483AAA499A28FC920DE272AEB1DA45393CCE49C89AC9D
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googletagmanager.com/gtm.js?id=GTM-5NXZ8L6F
                                          Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"13",. . "macros":[{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"eventAction"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"eventLabel"},{"function":"__e"},{"function":"__c","vtp_value":"G-1T23SJFGC8"},{"function":"__jsm","vtp_javascript":["template","(function(){var a=navigator.userAgent.toLowerCase();return a.indexOf(\"chrome\")\u003E-1\u0026\u0026a.indexOf(\"edg\")===-1\u0026\u0026a.indexOf(\"opr\")===-1\u0026\u0026a.indexOf(\"brave\")===-1?\"Chrome\":a.indexOf(\"edg\")\u003E-1?\"Edge\":a.indexOf(\"opr\")\u003E-1?\"Opera\":a.indexOf(\"firefox\")\u003E-1?\"Firefox\":a.indexOf(\"safari\")\u003E-1\u0026\u0026a.indexOf(\"chrome\")===-1?\"Safari\":a.indexOf(\"brave\")\u003E-1?\"Brave\":\"Other\"})();"]},{"
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (65536), with no line terminators
                                          Category:downloaded
                                          Size (bytes):84064
                                          Entropy (8bit):5.488525038954813
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:B54626A9776E92F7DAD697364A9B4C1D
                                          SHA1:CDB7E474B18693BB7F0696400E3941C2049CC452
                                          SHA-256:8F5E1A7B931A4F5115380148B5B9B0A4871243F914B0311FEB40F3E8FFB11535
                                          SHA-512:E7DB5DDFDAC5D38572220733A908B95640F9C415DCDA55FBB4D6363CDC66EB56A5F0D4FF9D470FFEA24905427CE56BD09E9905A89F2C569B6B565E6206516839
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://td.doubleclick.net/td/rul/16657993244?random=1743542294520&cv=11&fst=1743542294520&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&ct_cookie_present=0
                                          Preview:<html><body><script>var ig_list={"interestGroups":[{"action":0,"expirationTimeInSeconds":7775996,"interestGroupAttributes":{"owner":"https://td.doubleclick.net","name":"4s349423907.1743542293","biddingLogicUrl":"https://td.doubleclick.net/td/bjs","dailyUpdateUrl":"https://td.doubleclick.net/td/update?ig_name=4s349423907.1743542293\u0026ig_key=1sNHMzNDk0MjM5MDcuMTc0MzU0MjI5Mw!2saGL_FA!3sAAptDV6mpz6J\u0026tag_eid=44801597","trustedBiddingSignalsUrl":"https://td.doubleclick.net/td/bts","trustedBiddingSignalsKeys":["1s0FkH3Q!2saGL_FA!3sAAptDV6mpz6J","1i44801597"],"userBiddingSignals":[["8731847256","8732212382","8730873404"],null,1743542295994853],"ads":[{"renderUrl":"https://tdsf.doubleclick.net/td/adfetch/gda?adg_id=180081824041\u0026cr_id=739195573650\u0026cv_id=0\u0026format=${AD_WIDTH}x${AD_HEIGHT}\u0026rds=${RENDER_DATA}\u0026seat=2\u0026rp_id=r1j8731847256!4s*2A","metadata":["180081824041","739195573650",null,"22344402479",null,null,null,null,null,null,"8731847256"],"adRenderId":"-s
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 26 x 36, 8-bit/color RGBA, non-interlaced
                                          Category:downloaded
                                          Size (bytes):747
                                          Entropy (8bit):7.597125497285913
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:781AFAC11430D7B15F13042A889B898E
                                          SHA1:203F399A1E92A3ECFF79D2A7DE811EE11BF90795
                                          SHA-256:9C277BCE0DFF1624ED6B6462E9A16A03BEB2A767606E08D11B419573CB9D6C9D
                                          SHA-512:DE2E4EF4B4C9E5CA2B24E65EA65503A1066D520E111D6DDA3336F45ED18A18152E660F683ADBBC77E16D91F1B4658AD0A61F68B94D7076E9F48112D0CBA2C66F
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/assets/images/logo.png
                                          Preview:.PNG........IHDR.......$......:*.....pHYs.................sRGB.........gAMA......a.....IDATx..._n.@..gv..."...Jm.....QJ.r....N...%'.9A.[DR.7.2...'...J....# vp....i.;.E.Q.o.....X.k....z.5.)..H.3.EE... iC...1.>..u..~~k..rGF.t.o..A...S.emaB.,%K...~.Y.>......~DY_.,.... ..S Z..:.`..g g'..).-B<......K.....8... ..(&".|....b..Q\..m.... .....**.OC...B..y..t.ic.;.o6.g..54.~....;v.5...?.xI.l.....W!.o.....KS.\....m.....1...X.xcL..QP.m...p...K....O....08....Tam......q.y....l........4GWx....n*........G&..>...6 .S.....0.f..9.\..$K8c.A.+.$.}C.U. ...,.....V.!...v.......&`...R.........I.P.......H.....e.t.. .t;.....Z./...g...&...%.........y.C.i.."..<...DD.U..b.m:....^.%.RB......R..2v.6.Mw..9b.ElLO.A...d...R.i....IEND.B`.
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:JSON data
                                          Category:downloaded
                                          Size (bytes):514
                                          Entropy (8bit):5.128004245945965
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:1DBAE0C190E2A7C14407258262D6AD83
                                          SHA1:6B35AA63B3C7C3FEF29C2C1CC7B28CD4CC5CC79F
                                          SHA-256:ED44BC086841F94804258E3999154A84B6AB33AD4D3F6686791443822D0D9ABE
                                          SHA-512:A0BAA2D42386D68D37E0EB30FE96C52115F6E58F19EB1E889E1A0A56E44CBA660DBA95DA55B80BB4888DC4CBE25D29DE2EE3538186B12CE29312C349705927BF
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://publickeyservice.pa.aws.privacysandboxservices.com/.well-known/protected-auction/v1/public-keys
                                          Preview:{. "keys": [{. "id": "0700000000000000",. "key": "jNGmK3ofFdfqnGsi96yvoRaMT+IZ0s6/3srzSmh9kiI\u003d". }, {. "id": "3B00000000000000",. "key": "4gjx6lZ49XPrMydqJR3c5SKUVEXQVFGZnMWD03/+fGo\u003d". }, {. "id": "7B00000000000000",. "key": "OB0N3svb02h9iVNfAJ+syD8RFT7Xy/xRXX6HGd5aMj8\u003d". }, {. "id": "BB00000000000000",. "key": "VuVn2AZjbmcdqVrbNgslngBx110Pxzfqa8T9sPSEGFU\u003d". }, {. "id": "FB00000000000000",. "key": "b+kJ3yUfdFd5QNEQHF4ALGc8R/ygWNn+LLUmXDRvDzM\u003d". }].}
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                          Category:dropped
                                          Size (bytes):8689
                                          Entropy (8bit):7.968106062960917
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:079F9486B6C8F601476E92104F774B7A
                                          SHA1:8284741F994B80C53B4BD58D9EEE39AFF5AFAAF3
                                          SHA-256:264B5B928C0B89204CB560639D693E773EFDDC5963721284BA1941CD6C9C6B41
                                          SHA-512:CA1DB911C6642DAE31DFC7FB73C6066BD717ECD4B06B9875BD6951AEB3683015F62CA686457816DCEE357F0679C03B0C5F22377BE05E1F3602C81E71573C1E58
                                          Malicious:false
                                          Reputation:unknown
                                          Preview:.PNG........IHDR.............<.q...!.IDATx..].\Te.~g@...M{..tY...k.Z.M..uWp7uK.S.V....2MQ......je`......j&.......n:.......S3.....<.N...3s.......~&....@g.)...@.X......0..b.`............#.Sh.#.......)A..oV:..U.n..F........O`..7...z..Z..}.^.FO...;..kj7O.6.nF...o@.X.g.S..#DO..U...8..lYo..x..$qS0...^.rn....g.}.......`W..}J\..15....w J,X,9...%...tL...Qb...Br....{wQ'..|..c.h\.r`.....,L[..[g..U.,.c.......w...-.i..z...}....>.Cj..,C. .....0.U7....Vdd.cE....Y+g@d;..cWfS-1......+eWiy.{t..*Evl..!}).......'........m.!{'m..C.........'.....@...)......l..ZN........B.c.++._t....#yl......]..n.@?......gmg..DC...V.-....-Z.I=...._............y...._G.....{4.~A,....zDDG.E..t.\).......L,KD....d-]...}.g.Vx.......}.).].s...e......7aV.../U.F*w.u...2.c...@.|.X....8j.I.. .......j..4XK.@.|.X!.....19..9.(.r.J/.sI....f.`..'......'Rp#....{)5.K.C7..._........=s...Q.q.?.....=.._-;=.I.............7<.....@,..[.5..-.....;..21P..7..i.......H..._....H.....u..7.._.....)B.
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:JSON data
                                          Category:downloaded
                                          Size (bytes):514
                                          Entropy (8bit):5.20319208667438
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:AA9B37259D079F934B6682B45F7A3F2F
                                          SHA1:19DE4F664684144A7C18A535C103D8DDCF2AA317
                                          SHA-256:19A39EEE4C164DDE79990B0D242DBAF92511865CAA01A09C5B48A8098E9DDAA8
                                          SHA-512:2C6D000CE672F5441F09CB6FC940A18D2C27FB600AB52D29DCA85F75DA4D0CE5C25293214A33DE98540E6F3A8CE104742410400B30952CC941239F6CF84F428B
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://publickeyservice.pa.gcp.privacysandboxservices.com/.well-known/protected-auction/v1/public-keys
                                          Preview:{. "keys": [{. "id": "1980000000000000",. "key": "Eqad0khkxGrG/yztq4O8lMGsgKQN9+WziCNVv32aNwM\u003d". }, {. "id": "2980000000000000",. "key": "84/ChnR5VzKRkwYFS66E3jB1MCSo0LH6EKO3V5shwgw\u003d". }, {. "id": "6980000000000000",. "key": "Y68D/+8fNEGj4MmVuAK/aqAaVe+JmU85+CjF5GppsnA\u003d". }, {. "id": "A980000000000000",. "key": "2kKb2vMYAWKcmdynh7Z1sV4CUtIoOi3IHHHTWuucYnc\u003d". }, {. "id": "E980000000000000",. "key": "1H2UFUY14QpVK2cu0UKV7tE8grhS1gkmd6Z9DQFM1SE\u003d". }].}
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:Web Open Font Format (Version 2), TrueType, length 36848, version 1.0
                                          Category:downloaded
                                          Size (bytes):36848
                                          Entropy (8bit):7.995112872818791
                                          Encrypted:true
                                          SSDEEP:
                                          MD5:3CCD9AB2050B2F26898B77AF9148B8E2
                                          SHA1:7F9F46B2FB3F121F3C0600E1182D725B1BE6C176
                                          SHA-256:258F9F1B553BB57419619F41D3B1445226C7BC63D2A3409EFEF4A68426709E94
                                          SHA-512:6F9F764D77A563A132E952BD49790F22AA80A88F885BB9AA82F1C25BBC9FBA1451F3E4FADD1EABDF86DC77F7FCDC13C5B183AEE617077F3061E04D54E7246AFE
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://fonts.gstatic.com/s/dmsans/v15/rP2Yp2ywxg089UriI5-g4vlH9VoD8Cmcqbu0-K4.woff2
                                          Preview:wOF2..............*....~.................................J?HVAR.".`?STAT.\'2.../l.....,.A....0..4.6.$..8. .....8..[..Q#.....m..A......N.2Y......6.....e..iIe.m.KZ......=...,.....-+..6"..s.j..23.+.Y.vY....YX'.w^N..@...-mu....!...9.i....DS.=....>.a.t.Q,\t..G.2!.....[../S........D..A&.8...!.A.7K+2Q.c....D..._..i....*..J(f=7...C.[..n6.B....B.t.z4C.T+...b...!.B..x..*r>D....q.C......9.Z....?....{./.......D#..N..O]+..5.5.......{".l.XD...,."a.l0bD..FcD].W..^.qzQ.^.uMA...>h.0.K=.4..h.....T..mG.+.........n+_DG..I.GT..B..igd.X.!u.n&U.;.C.~S.........d....h..{.... .. ..KL...!N.$..5.a.SN......6.=}j.HJ:J.pG.n.~b.AOS..'.T....G.........E.]..O\...|.p/...l..-.i4?....J*0..y.........N.O....3.4&ql...t.T.......I..q..$..........i.n..m..O...v....P.m!...........K...M....r.6Q......:E..$.D>.it...h..>B...R..~.NmF.....x{1`.c..[brR..T....%..\.wz.^..V...?..YG^...eok....b.uu.V.ZqP`.04,.^..L.K.l....i......%Vj..'.0...o..g.....w7z..i`8R.Cj........V.HV.;..w.Qg......pY...b.3$
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (815)
                                          Category:downloaded
                                          Size (bytes):3501
                                          Entropy (8bit):5.383873370647921
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:147FD3B00C22BA9C939712E9213C24CA
                                          SHA1:3B48369B86FA0574F35379AACD1F42CC9C98A52B
                                          SHA-256:70F5B11C1870CF90201A6D5F770CA318A3FA5827C74A8765EDE22B487F7D4532
                                          SHA-512:E8419A71232EDAC8FD131446777F7D034B3171EFE07B3267479B439E4982650DB65A0D1DDC9F516315D5ED1B01ECFD2F7EB55D75D44AA51EE0AD494D441586D2
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googletagmanager.com/static/service_worker/53k0/sw_iframe.html?origin=https%3A%2F%2Fwww.pdfskillsapp.com
                                          Preview:<!DOCTYPE html>.<html>.<head>. <link rel="shortcut icon" href="data:image/x-icon;," type="image/x-icon">.</head>.<body>. <script>.'use strict';class m{constructor(a){this.j=a;this.g={};this.h={};this.i=0;this.id=String(Math.floor(Number.MAX_SAFE_INTEGER*Math.random()))}}function n(a){return a.performance&&a.performance.now()||Date.now()}.var p=function(a,b){class d{constructor(c,g,f){this.failureType=c;this.data=g;this.g=f;this.h=new m(n(f))}s(c,g){const f=c.clientId;if(c.type===0){c.isDead=!0;var e=this.h,h=n(this.g);e.g[f]==null&&(e.g[f]=0,e.h[f]=h,e.i++);e.g[f]++;c.stats={targetId:e.id,clientCount:e.i,totalLifeMs:Math.round(h-e.j),heartbeatCount:e.g[f],clientLifeMs:Math.round(h-e.h[f])}}c.failure={failureType:this.failureType,data:this.data};g(c)}}return new d(5,a,b)};/*.. Copyright Google LLC. SPDX-License-Identifier: Apache-2.0.*/.let q=globalThis.trustedTypes,r;function t(){let a=null;if(!q)return a;try{const b=d=>d;a=q.createPolicy("goog#html",{createHTML:b,createScript:b,crea
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (1815)
                                          Category:downloaded
                                          Size (bytes):1861
                                          Entropy (8bit):4.963483690165822
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:36974225AA51D7B413C9A1CFB22E9C06
                                          SHA1:FE4F3F561D5BD50A21BDDE90EC7D0E3EFFF061BF
                                          SHA-256:97CE4E98F3A3BE297F48EBD5B771E74928F31754D43324FD795D1CD81CC41B35
                                          SHA-512:361482D589B2AEE5E27DC8FF285456A02E7AD58A47A5CE49B7382F6EECF1E55A332A95AF43EE275E13DD1609B1F31A9EC517290209538FDB0805620D5DAF31E7
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://cdnjs.cloudflare.com/ajax/libs/normalize/8.0.1/normalize.min.css
                                          Preview:/*! normalize.css v8.0.1 | MIT License | github.com/necolas/normalize.css */html{line-height:1.15;-webkit-text-size-adjust:100%}body{margin:0}main{display:block}h1{font-size:2em;margin:.67em 0}hr{box-sizing:content-box;height:0;overflow:visible}pre{font-family:monospace,monospace;font-size:1em}a{background-color:transparent}abbr[title]{border-bottom:none;text-decoration:underline;text-decoration:underline dotted}b,strong{font-weight:bolder}code,kbd,samp{font-family:monospace,monospace;font-size:1em}small{font-size:80%}sub,sup{font-size:75%;line-height:0;position:relative;vertical-align:baseline}sub{bottom:-.25em}sup{top:-.5em}img{border-style:none}button,input,optgroup,select,textarea{font-family:inherit;font-size:100%;line-height:1.15;margin:0}button,input{overflow:visible}button,select{text-transform:none}[type=button],[type=reset],[type=submit],button{-webkit-appearance:button}[type=button]::-moz-focus-inner,[type=reset]::-moz-focus-inner,[type=submit]::-moz-focus-inner,button::-moz
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (65447)
                                          Category:downloaded
                                          Size (bytes):89501
                                          Entropy (8bit):5.289893677458563
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                          SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                          SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                          SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://code.jquery.com/jquery-3.6.0.min.js
                                          Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 148 x 148, 8-bit/color RGBA, non-interlaced
                                          Category:downloaded
                                          Size (bytes):7950
                                          Entropy (8bit):7.9701540417252055
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:048BE6284CF60DC5E6F1BE697E1E5AF7
                                          SHA1:34392F97E7A0086200EA56DF0241CA2155087EE3
                                          SHA-256:2FF75F6D3FB43411AD46A6D983268972494E97B203E050BC12582F13379AE960
                                          SHA-512:FD1E8DDBCBD62A6D16BCBAA21214FA84E8B4120C30B9451326C513758C84F6363FC75ECAEA780E93AACEE239AF0BBF14F9E47BF89A6A8217CEB03685994D56FF
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/assets/images/card-fast.png
                                          Preview:.PNG........IHDR.............u<......IDATx...|.....#..$...I.S.........H.jUPA.B....o.~$..zU.Vm.. .X.. ..Q.9.x..E..I@.....fg..&;a3;{...~>#...&1...<...3.E..U.A..y.G....O.S.NG39....`..3..i5D.....#......T....b8...k.y....{.d.y~. ..l8.....i.(#...I4m.H.h.NrTDZ*...".X..*a...f........|.e.'..k."....A...T.>.}vLX.f.0p...9...SuB.U8....--B...".BAL..9..p...........D...{.|N...7U..!......i.p.(....^.7.<@.n[N=3.....5.MJH.JHe"VPpsY..L..../HY...:6....T.........T]S'.......Q..m..^...Z..32....U.....:....+..\.f....z..Yv3.f.j..`...D....]X....S.;.>v.[.|R...Pe.B....L}..o//..}Xu..K<....;.H.'.l...K.s."..@....K..X.0.Dq...)..G..0.. .j...'(..8.....|...i..2t..k..Heeg.b..0n.P.....x.q......w.O.8>.==....t...H*....de.h.8..Y....BI..*Nt.qq.._..h.2(Nt.Q.*9.E..r6R..%b,T.%.Y.8..|......8.IDX(........[F;a.T\L.../-..e.....H*.VA!f..I}l,+.d.n....J.j.*l.2....5+....afI........2g.j.q...F#.N."(.M-.3.J..m..A..(Nt.rA......t.......u.Eq.....!.....c..5.gI_.~...5S..%...6.....?.S:.xduA...y...!..5.eJ.
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                          Category:downloaded
                                          Size (bytes):655
                                          Entropy (8bit):7.4300479828065376
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:9CC3300CC8D7059C43E24600640B7ADF
                                          SHA1:6D6B8C07CB31C30C77C00A984882052407E3BB9A
                                          SHA-256:66F18CE08EFC91F7E9B2DE6663F8654BF73FADFB62A963F3C1118BF4400D9802
                                          SHA-512:861C21FCEB4F92ED621DDF35DA3B2AF919DCC13EA909D71C1284BB667779381FD127FA70786E063B64D96C4BD4CE2989655E2AA756F3EEDD94F8726B67B3193E
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.pdfskillsapp.com/assets/images/favicon.ico
                                          Preview:.PNG........IHDR... ... .....szz.....pHYs.................sRGB.........gAMA......a....$IDATx..?H.Q...w5UTKM...kE5GTPK..!d.b...5xM..R..PhA....b$....q.E...~.....=....q...}.{..}..P......v..qY.O..=..wc.m0..a...1...cH...'.E0..j*wuw..2.S3#...../kmk...><7cY.....7..P`...O&>....x..?...........c. x1....c.F'..f..:..(_.Y.\...f...k.S........ew.O....yP....w.r0g.}.....3>..I7...4$.<p.H1..D#.P-.!8...(........M.P".K2.r.1..u..<<..o,.f...R!....%..OO.!..s'.fN.B.=........s#.|...Z.Ux...C..h.mmk)y..|...x.Y...)....^:.........VB.?"j9..t.....].P.}R.YO..4e.+{\...m2-Z.y...\....[..Nm!9.M7.^.es.....4.G\.e............~.%+{.zm.....]I....5).C.....IEND.B`.
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (6227), with no line terminators
                                          Category:downloaded
                                          Size (bytes):6227
                                          Entropy (8bit):6.014393894795642
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:E4CE5EE77FB75368ABA11C8EDAD52B0D
                                          SHA1:EE2D991459DFF7101041E8269C725AEDD87834D9
                                          SHA-256:7B91B7CA7D56618BC8ADBB5C6AC56177D14430E879D3CC9AE391509924B4E859
                                          SHA-512:9615884782962BEEE342C63C74ED6688DE135D3DBF3EC081885119563331FE54BCB6DEF2E209C7DFF5CBF2F89E006238D976E737C771909D369F3046F4156921
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googleadservices.com/pagead/conversion/16657993244/?random=1743542308008&cv=11&fst=1743542308008&bg=ffffff&guid=ON&async=1&gcl_ctr=2&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=4
                                          Preview:(function(){var s = {};(function(){var k=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,d,b){if(a==Array.prototype||a==Object.prototype)return a;a[d]=b.value;return a};function l(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var d=0;d<a.length;++d){var b=a[d];if(b&&b.Math==Math)return b}throw Error("Cannot find global object");} var p=l(this),q=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",r={},t={};function u(a,d,b){if(!b||a!=null){b=t[d];if(b==null)return a[d];b=a[b];return b!==void 0?b:a[d]}} function v(a,d,b){if(d)a:{var c=a.split(".");a=c.length===1;var e=c[0],g;!a&&e in r?g=r:g=p;for(e=0;e<c.length-1;e++){var f=c[e];if(!(f in g))break a;g=g[f]}c=c[c.length-1];b=q&&b==="es6"?g[c]:null;d=d(b);d!=null&&(a?k(r,c,{configurable:!0,writable:!0,value:d}):d!==b&&(t[c]===void 0&&(a=Math.random()*1E9>>>0,t[c]=q?p.Symbol(c):"$jscp$"+a+"$"+c),k(g,t[c],{co
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (1236)
                                          Category:downloaded
                                          Size (bytes):20705
                                          Entropy (8bit):5.470065366668187
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:9E67DCDB1F1B369CB5D5D77EB947102A
                                          SHA1:EF6A1C09FE34FAD919456157FF0C66BCDC03DF3A
                                          SHA-256:2E169E8A7BD2F1F80187C99B59ECEAA1E3233D030361802F717D31DA1312323C
                                          SHA-512:FA1746D661425F6113E2E6884BB35074169FDD4C43345C797945FE10858EDA9A2E68F89CBD8EDC8F0976BF0420690D13FD82C80D217544C839F851C117FFD00E
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googletagmanager.com/static/service_worker/53k0/sw.js?origin=https%3A%2F%2Fwww.pdfskillsapp.com
                                          Preview:'use strict';var aa=function(a){function b(d){return a.next(d)}function c(d){return a.throw(d)}return new Promise(function(d,e){function f(g){g.done?d(g.value):Promise.resolve(g.value).then(b,c).then(f,e)}f(a.next())})},h=function(a){return aa(a())};/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var n={},r=null,x=function(a){var b=3;b===void 0&&(b=0);w();const c=n[b],d=Array(Math.floor(a.length/3)),e=c[64]||"";let f=0,g=0;for(;f<a.length-2;f+=3){const p=a[f],q=a[f+1],A=a[f+2],v=c[p>>2],m=c[(p&3)<<4|q>>4],t=c[(q&15)<<2|A>>6],u=c[A&63];d[g++]=""+v+m+t+u}let k=0,l=e;switch(a.length-f){case 2:k=a[f+1],l=c[(k&15)<<2]||e;case 1:const p=a[f];d[g]=""+c[p>>2]+c[(p&3)<<4|k>>4]+l+e}return d.join("")},B=function(a){const b=a.length;let c=b*3/4;c%3?c=Math.floor(c):"=.".indexOf(a[b-1])!=-1&&(c="=.".indexOf(a[b-.2])!=-1?c-2:c-1);const d=new Uint8Array(c);let e=0;ba(a,function(f){d[e++]=f});return e!==c?d.subarray(0,e):d},ba=function(a,b){function c(e){for(;d<a.len
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (6179), with no line terminators
                                          Category:downloaded
                                          Size (bytes):6179
                                          Entropy (8bit):6.005905515258766
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:D0818AFFAAAF15138146F06EFE5F8AD0
                                          SHA1:A71A470A1E7669FB80FE094235890FA39CE53BDC
                                          SHA-256:7B5E97BBBCB87BFDE2A064FDEBAE678F3D51215A716BB5E0FA049380C5673D86
                                          SHA-512:DA7F7678FDBC6EA8D20441EB8D5552A12C13FEB48992299CF13DE12EDB432D4F0A3E351F90038E3419E4BFC77354BA2F3AEDB0B880E05CD1C32AC6AE1FD77032
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googleadservices.com/pagead/conversion/16657993244/?random=1743542294520&cv=11&fst=1743542294520&bg=ffffff&guid=ON&async=1&gcl_ctr=1&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=5Y6HCPLq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&rfmt=3&fmt=4
                                          Preview:(function(){var s = {};(function(){var k=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,d,b){if(a==Array.prototype||a==Object.prototype)return a;a[d]=b.value;return a};function l(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var d=0;d<a.length;++d){var b=a[d];if(b&&b.Math==Math)return b}throw Error("Cannot find global object");} var p=l(this),q=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",r={},t={};function u(a,d,b){if(!b||a!=null){b=t[d];if(b==null)return a[d];b=a[b];return b!==void 0?b:a[d]}} function v(a,d,b){if(d)a:{var c=a.split(".");a=c.length===1;var e=c[0],g;!a&&e in r?g=r:g=p;for(e=0;e<c.length-1;e++){var f=c[e];if(!(f in g))break a;g=g[f]}c=c[c.length-1];b=q&&b==="es6"?g[c]:null;d=d(b);d!=null&&(a?k(r,c,{configurable:!0,writable:!0,value:d}):d!==b&&(t[c]===void 0&&(a=Math.random()*1E9>>>0,t[c]=q?p.Symbol(c):"$jscp$"+a+"$"+c),k(g,t[c],{co
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:ASCII text, with very long lines (5436)
                                          Category:downloaded
                                          Size (bytes):324830
                                          Entropy (8bit):5.594616359013325
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:19D4456AAEBDD536A50BCA6EADB3ADB9
                                          SHA1:04D9745B470A5603636401D25D9B7F5F14982108
                                          SHA-256:3753BDCADE85488833D943037CEB626466F19EDD323C2898973A5C762E0BE0E3
                                          SHA-512:5849A56CCF38DE82732C5C3D116F8BED1F16586257C1173D85DE1A6A82631976485EB2714DCA606DF2B79D711F64DF647EDA16C7680276437DF0944A5EB8CF87
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://www.googletagmanager.com/gtag/destination?id=AW-16657993244&l=dataLayer&cx=c&gtm=45je53v0v9192131470za200zb9192109920&tag_exp=102788824~102803279~102813109~102887800~102926062~102964103~102975949~102976415
                                          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"}],. "tags":[{"function":"__ogt_ads_datatos","priority":16,"vtp_instanceDestinationId":"AW-16657993244","tag_id":10},{"function":"__ogt_1p_data_v2","priority":6,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_re
                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          File Type:HTML document, ASCII text, with very long lines (65536), with no line terminators
                                          Category:downloaded
                                          Size (bytes):84064
                                          Entropy (8bit):5.488391746606978
                                          Encrypted:false
                                          SSDEEP:
                                          MD5:C4190AFADF8E9CE68750D3BAAEF9D688
                                          SHA1:B457716A22131D7DD800F1C72B022E4A65007F01
                                          SHA-256:C67E84C48232A70CBC8941E3C0211FC3762F3175ACDB36350A298B1821C43A8C
                                          SHA-512:2047F66DECD65A093DE227238590F795C896C60C2DD1ABFA6BEAFC5CBC3EDB020FFA5732514500E4C0F36AACC1F401335AE871A94DD40732C2C2E4ED400EEAFD
                                          Malicious:false
                                          Reputation:unknown
                                          URL:https://td.doubleclick.net/td/rul/16657993244?random=1743542319082&cv=11&fst=1743542319082&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=3&gtm=45be53v0z89192109920za201zb9192131470&gcs=G111&gcd=13t3t3t3t5l1&dma=0&tag_exp=102788824~102803279~102813109~102887799~102926062~102964103~102975949~102976415&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.pdfskillsapp.com%2F&label=DeOHCPXq9MYZEJyck4c-&hn=www.googleadservices.com&frm=0&tiba=PDF%20Skills&value=0&bttype=purchase&npa=0&pscdl=noapi&auid=349423907.1743542293&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&capi=1&_tu=Cg&data=ads_data_redaction%3Dfalse&ct_cookie_present=0
                                          Preview:<html><body><script>var ig_list={"interestGroups":[{"action":0,"expirationTimeInSeconds":7775972,"interestGroupAttributes":{"owner":"https://td.doubleclick.net","name":"4s349423907.1743542293","biddingLogicUrl":"https://td.doubleclick.net/td/bjs","dailyUpdateUrl":"https://td.doubleclick.net/td/update?ig_name=4s349423907.1743542293\u0026ig_key=1sNHMzNDk0MjM5MDcuMTc0MzU0MjI5Mw!2saGL_FA!3sAAptDV6mpz6J\u0026tag_eid=44804419","trustedBiddingSignalsUrl":"https://td.doubleclick.net/td/bts","trustedBiddingSignalsKeys":["1s0FkH3Q!2saGL_FA!3sAAptDV6mpz6J","1i44804419"],"userBiddingSignals":[["8730873404","8731847256","8732212382"],null,1743542320539502],"ads":[{"renderUrl":"https://tdsf.doubleclick.net/td/adfetch/gda?adg_id=180081824041\u0026cr_id=739195573650\u0026cv_id=0\u0026format=${AD_WIDTH}x${AD_HEIGHT}\u0026rds=${RENDER_DATA}\u0026seat=2\u0026rp_id=r1j8730873404!4s*2A","metadata":["180081824041","739195573650",null,"22344402479",null,null,null,null,null,null,"8730873404"],"adRenderId":"ie
                                          No static file info