Edit tour

Windows Analysis Report
http://www.translatebonus.net

Overview

General Information

Sample URL:http://www.translatebonus.net
Analysis ID:1658945
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6260 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1516 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2016 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7296 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3736 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.translatebonus.net" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.translatebonus.netAvira URL Cloud: detection malicious, Label: malware
Source: unknownHTTPS traffic detected: 142.250.176.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.32.99
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIk6HLAQiJo8sBCIWgzQEI9s/OAQiB1s4BCMHYzgEI0uDOAQiv5M4BCOLkzgEIi+XOAQ==Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.translatebonus.net
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 142.250.176.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: classification engineClassification label: mal48.win@24/2@22/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2016 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3736 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.translatebonus.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2016 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3736 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1658945 URL: http://www.translatebonus.net Startdate: 08/04/2025 Architecture: WINDOWS Score: 48 17 www.translatebonus.net 2->17 27 Antivirus / Scanner detection for submitted sample 2->27 7 chrome.exe 2->7         started        10 chrome.exe 2->10         started        signatures3 process4 dnsIp5 19 192.168.2.5, 443, 49287, 49699 unknown unknown 7->19 12 chrome.exe 7->12         started        15 chrome.exe 7->15         started        process6 dnsIp7 21 www.google.com 142.250.176.196, 443, 49701 GOOGLEUS United States 12->21 23 www.translatebonus.net 12->23 25 google.com 12->25

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.translatebonus.net100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.65.238
truefalse
    high
    www.google.com
    142.250.176.196
    truefalse
      high
      www.translatebonus.net
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://c.pki.goog/r/gsr1.crlfalse
          high
          http://c.pki.goog/r/r4.crlfalse
            high
            https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.176.196
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.5
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1658945
              Start date and time:2025-04-08 08:17:54 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 8s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://www.translatebonus.net
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:10
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal48.win@24/2@22/2
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • URL browsing timeout or error
              • URL not reachable
              • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 184.31.69.3, 199.232.214.172, 142.251.40.142, 142.250.80.99, 142.251.40.238, 142.251.179.84, 142.251.41.14, 142.251.32.110, 142.251.40.206, 142.250.65.206, 142.251.35.174, 172.202.163.200
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, clients2.google.com, redirector.gvt1.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, c.pki.goog
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenFile calls found.
              • VT rate limit hit for: http://www.translatebonus.net
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with very long lines (1082)
              Category:downloaded
              Size (bytes):1087
              Entropy (8bit):5.502019884569076
              Encrypted:false
              SSDEEP:24:adL13XQOUvslWBHslgT1d1uawINNsyfVk32qr+ATYuoBN2t2t2t2t2t2t2tomffL:aB1nfbWKlgJXwIN+y9kmqyAEuSNYYYYy
              MD5:BA254D4C3FDA9D7B540FD179CE5CA73E
              SHA1:86ABF8E4C6178463BB8D0BC7283A68AA3AC7CD0E
              SHA-256:CB7EB43D5F9950197BDE598B1D18C2D84370DCCB06D9B312A801354C07ED3587
              SHA-512:43E970CDC9E66F3A363E206AEFAB4FF56ECD65FFA2E26BF57DC77026C037531EC248778E77E20F3DCD1AD6DBBD95C56382BDBC3B7CC9D73BC5229368AABB185F
              Malicious:false
              Reputation:low
              URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
              Preview:)]}'.["",["easter shopping blackout","pj blue louisville football","cast love on the spectrum season 3","nintendo mario kart world","tornadoes leon county","aurora borealis forecast","fruity pebbles donuts","axe ceremonia music festival"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"google:entityinfo":"Cg0vZy8xMW03N2RncGQyEhBNYXJpbyBLYXJ0IFdvcmxkOhluaW50ZW5kbyBtYXJpbyBrYXJ0IHdvcmxkUk1nc19zc3A9ZUp6ajR0VlAxemMwekRVM1Qwa3ZTREV5WVBTU3pNdk1LMG5OUzhsWHlFMHN5c3hYeUU0c0tsRW96eV9LU1FFQUd0d09NQXAE","zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggesteventid":"-5770036398654224684","google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"g
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 48
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Apr 8, 2025 08:18:46.425297022 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:46.737133026 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:47.346519947 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:47.393372059 CEST49672443192.168.2.5204.79.197.203
              Apr 8, 2025 08:18:48.549655914 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:50.955935001 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:53.595247030 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:53.688914061 CEST8049699142.251.32.99192.168.2.5
              Apr 8, 2025 08:18:53.688993931 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:53.689156055 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:53.782538891 CEST8049699142.251.32.99192.168.2.5
              Apr 8, 2025 08:18:53.782648087 CEST8049699142.251.32.99192.168.2.5
              Apr 8, 2025 08:18:53.782690048 CEST8049699142.251.32.99192.168.2.5
              Apr 8, 2025 08:18:53.783066988 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:53.792545080 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:53.886548996 CEST8049699142.251.32.99192.168.2.5
              Apr 8, 2025 08:18:53.971652985 CEST4969980192.168.2.5142.251.32.99
              Apr 8, 2025 08:18:55.768719912 CEST49676443192.168.2.520.189.173.14
              Apr 8, 2025 08:18:57.003134012 CEST49672443192.168.2.5204.79.197.203
              Apr 8, 2025 08:18:57.669193983 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:18:57.669248104 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:18:57.669466019 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:18:57.669598103 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:18:57.669620037 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:18:57.874350071 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:18:57.874420881 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:18:57.875611067 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:18:57.875627041 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:18:57.875880003 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:18:57.928024054 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.088284016 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.132282019 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:01.214572906 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:01.256083965 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.256117105 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:01.316021919 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.338053942 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:01.338210106 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:01.338268995 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.338696003 CEST49701443192.168.2.5142.250.176.196
              Apr 8, 2025 08:19:01.338716984 CEST44349701142.250.176.196192.168.2.5
              Apr 8, 2025 08:19:05.378113031 CEST49676443192.168.2.520.189.173.14
              TimestampSource PortDest PortSource IPDest IP
              Apr 8, 2025 08:18:53.180483103 CEST53515641.1.1.1192.168.2.5
              Apr 8, 2025 08:18:53.398009062 CEST53511811.1.1.1192.168.2.5
              Apr 8, 2025 08:18:54.359877110 CEST53590011.1.1.1192.168.2.5
              Apr 8, 2025 08:18:57.569757938 CEST5640653192.168.2.51.1.1.1
              Apr 8, 2025 08:18:57.570133924 CEST5671253192.168.2.51.1.1.1
              Apr 8, 2025 08:18:57.666686058 CEST53564061.1.1.1192.168.2.5
              Apr 8, 2025 08:18:57.668127060 CEST53567121.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.472434998 CEST5568053192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.472652912 CEST5104753192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.494906902 CEST5725153192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.495024920 CEST5028153192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.577990055 CEST53556801.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.579425097 CEST53510471.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.580082893 CEST5147453192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.603832006 CEST53572511.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.603858948 CEST53502811.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.686974049 CEST53514741.1.1.1192.168.2.5
              Apr 8, 2025 08:18:58.691983938 CEST5479753192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.692523956 CEST5116053192.168.2.51.1.1.1
              Apr 8, 2025 08:18:58.834558964 CEST53511601.1.1.1192.168.2.5
              Apr 8, 2025 08:18:59.709250927 CEST5900553192.168.2.51.1.1.1
              Apr 8, 2025 08:18:59.814229965 CEST53590051.1.1.1192.168.2.5
              Apr 8, 2025 08:18:59.863861084 CEST6502853192.168.2.58.8.8.8
              Apr 8, 2025 08:18:59.864412069 CEST5763253192.168.2.51.1.1.1
              Apr 8, 2025 08:18:59.963239908 CEST53576321.1.1.1192.168.2.5
              Apr 8, 2025 08:18:59.966605902 CEST53650288.8.8.8192.168.2.5
              Apr 8, 2025 08:19:00.917053938 CEST5485853192.168.2.51.1.1.1
              Apr 8, 2025 08:19:00.917195082 CEST5766053192.168.2.51.1.1.1
              Apr 8, 2025 08:19:01.021910906 CEST53576601.1.1.1192.168.2.5
              Apr 8, 2025 08:19:01.027831078 CEST53548581.1.1.1192.168.2.5
              Apr 8, 2025 08:19:06.058689117 CEST6469353192.168.2.51.1.1.1
              Apr 8, 2025 08:19:06.059102058 CEST5538553192.168.2.51.1.1.1
              Apr 8, 2025 08:19:06.156061888 CEST53646931.1.1.1192.168.2.5
              Apr 8, 2025 08:19:06.165232897 CEST53553851.1.1.1192.168.2.5
              Apr 8, 2025 08:19:06.166162014 CEST5758253192.168.2.51.1.1.1
              Apr 8, 2025 08:19:06.264913082 CEST53575821.1.1.1192.168.2.5
              Apr 8, 2025 08:19:11.339723110 CEST53644851.1.1.1192.168.2.5
              Apr 8, 2025 08:19:13.097472906 CEST5060553192.168.2.51.1.1.1
              Apr 8, 2025 08:19:13.097610950 CEST6445853192.168.2.51.1.1.1
              Apr 8, 2025 08:19:13.200723886 CEST53506051.1.1.1192.168.2.5
              Apr 8, 2025 08:19:13.226341009 CEST53644581.1.1.1192.168.2.5
              Apr 8, 2025 08:19:13.227258921 CEST5622453192.168.2.51.1.1.1
              Apr 8, 2025 08:19:13.366663933 CEST53562241.1.1.1192.168.2.5
              Apr 8, 2025 08:19:13.386346102 CEST4928753192.168.2.51.1.1.1
              Apr 8, 2025 08:19:13.386967897 CEST5718053192.168.2.58.8.8.8
              Apr 8, 2025 08:19:13.486428022 CEST53492871.1.1.1192.168.2.5
              Apr 8, 2025 08:19:13.489411116 CEST53571808.8.8.8192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 8, 2025 08:18:57.569757938 CEST192.168.2.51.1.1.10xc6a6Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:57.570133924 CEST192.168.2.51.1.1.10x4565Standard query (0)www.google.com65IN (0x0001)false
              Apr 8, 2025 08:18:58.472434998 CEST192.168.2.51.1.1.10x671fStandard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.472652912 CEST192.168.2.51.1.1.10x3911Standard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:18:58.494906902 CEST192.168.2.51.1.1.10xc6d3Standard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.495024920 CEST192.168.2.51.1.1.10xb4Standard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:18:58.580082893 CEST192.168.2.51.1.1.10x7b4bStandard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.691983938 CEST192.168.2.51.1.1.10xf01dStandard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.692523956 CEST192.168.2.51.1.1.10x9aeaStandard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:18:59.709250927 CEST192.168.2.51.1.1.10xcd4Standard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:59.863861084 CEST192.168.2.58.8.8.80xba49Standard query (0)google.comA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:59.864412069 CEST192.168.2.51.1.1.10x3300Standard query (0)google.comA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:00.917053938 CEST192.168.2.51.1.1.10x231fStandard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:00.917195082 CEST192.168.2.51.1.1.10x5d70Standard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:19:06.058689117 CEST192.168.2.51.1.1.10x40c8Standard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:06.059102058 CEST192.168.2.51.1.1.10x548cStandard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:19:06.166162014 CEST192.168.2.51.1.1.10xe1f9Standard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.097472906 CEST192.168.2.51.1.1.10xcc7eStandard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.097610950 CEST192.168.2.51.1.1.10x5dc5Standard query (0)www.translatebonus.net65IN (0x0001)false
              Apr 8, 2025 08:19:13.227258921 CEST192.168.2.51.1.1.10x2eb3Standard query (0)www.translatebonus.netA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.386346102 CEST192.168.2.51.1.1.10x5fa5Standard query (0)google.comA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.386967897 CEST192.168.2.58.8.8.80x3726Standard query (0)google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 8, 2025 08:18:57.666686058 CEST1.1.1.1192.168.2.50xc6a6No error (0)www.google.com142.250.176.196A (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:57.668127060 CEST1.1.1.1192.168.2.50x4565No error (0)www.google.com65IN (0x0001)false
              Apr 8, 2025 08:18:58.577990055 CEST1.1.1.1192.168.2.50x671fName error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.579425097 CEST1.1.1.1192.168.2.50x3911Name error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:18:58.603832006 CEST1.1.1.1192.168.2.50xc6d3Name error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.603858948 CEST1.1.1.1192.168.2.50xb4Name error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:18:58.686974049 CEST1.1.1.1192.168.2.50x7b4bName error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:58.834558964 CEST1.1.1.1192.168.2.50x9aeaName error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:18:59.814229965 CEST1.1.1.1192.168.2.50xcd4Name error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:59.963239908 CEST1.1.1.1192.168.2.50x3300No error (0)google.com142.250.65.238A (IP address)IN (0x0001)false
              Apr 8, 2025 08:18:59.966605902 CEST8.8.8.8192.168.2.50xba49No error (0)google.com142.250.64.78A (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:01.021910906 CEST1.1.1.1192.168.2.50x5d70Name error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:19:01.027831078 CEST1.1.1.1192.168.2.50x231fName error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:06.156061888 CEST1.1.1.1192.168.2.50x40c8Name error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:06.165232897 CEST1.1.1.1192.168.2.50x548cName error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:19:06.264913082 CEST1.1.1.1192.168.2.50xe1f9Name error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.200723886 CEST1.1.1.1192.168.2.50xcc7eName error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.226341009 CEST1.1.1.1192.168.2.50x5dc5Name error (3)www.translatebonus.netnonenone65IN (0x0001)false
              Apr 8, 2025 08:19:13.366663933 CEST1.1.1.1192.168.2.50x2eb3Name error (3)www.translatebonus.netnonenoneA (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.486428022 CEST1.1.1.1192.168.2.50x5fa5No error (0)google.com142.250.65.174A (IP address)IN (0x0001)false
              Apr 8, 2025 08:19:13.489411116 CEST8.8.8.8192.168.2.50x3726No error (0)google.com142.250.64.78A (IP address)IN (0x0001)false
              • www.google.com
              • c.pki.goog
              Session IDSource IPSource PortDestination IPDestination Port
              0192.168.2.549699142.251.32.9980
              TimestampBytes transferredDirectionData
              Apr 8, 2025 08:18:53.689156055 CEST202OUTGET /r/gsr1.crl HTTP/1.1
              Cache-Control: max-age = 3000
              Connection: Keep-Alive
              Accept: */*
              If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
              User-Agent: Microsoft-CryptoAPI/10.0
              Host: c.pki.goog
              Apr 8, 2025 08:18:53.782648087 CEST1254INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
              Cross-Origin-Resource-Policy: cross-origin
              Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
              Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
              Content-Length: 1739
              X-Content-Type-Options: nosniff
              Server: sffe
              X-XSS-Protection: 0
              Date: Tue, 08 Apr 2025 06:06:39 GMT
              Expires: Tue, 08 Apr 2025 06:56:39 GMT
              Cache-Control: public, max-age=3000
              Age: 734
              Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
              Content-Type: application/pkix-crl
              Vary: Accept-Encoding
              Data Raw: 30 82 06 c7 30 82 05 af 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69 67 6e 20 6e 76 2d 73 61 31 10 30 0e 06 03 55 04 0b 13 07 52 6f 6f 74 20 43 41 31 1b 30 19 06 03 55 04 03 13 12 47 6c 6f 62 61 6c 53 69 67 6e 20 52 6f 6f 74 20 43 41 17 0d 32 35 30 34 30 37 30 30 30 30 30 30 5a 17 0d 32 35 30 37 31 35 30 30 30 30 30 30 5a 30 82 04 f1 30 2a 02 0b 04 00 00 00 00 01 1e 44 a5 e4 04 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 29 45 c3 a8 0f 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 20 19 c1 8d 68 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2c 5e 7f 1a 88 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 15 4b 5a [TRUNCATED]
              Data Ascii: 000*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA250407000000Z250715000000Z00*D141125000000Z00U0*)E141125000000Z00U0* h141125000000Z00U0*,^141125000000Z00U0*KZ160107000000Z00U0*/NIR170419000000Z00U0*/NG170419000000Z00U0*/N9191120000000Z00U0*/N=k191204000000Z00U
              Apr 8, 2025 08:18:53.782690048 CEST1198INData Raw: 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2f 4e e1 3b 58 17 0d 31 39 31 32 30 34 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2d 02 0e 47 c3 0f ff 8a 61 9a 37 f5 a8 2e f0 b5 75 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30
              Data Ascii: 0*/N;X191204000000Z00U0-Ga7.u200630000000Z00U0-GA>ThA200630000000Z00U0-GK&TA+200630000000Z00U0*6::200711160000Z00U0/vSBS
              Apr 8, 2025 08:18:53.792545080 CEST200OUTGET /r/r4.crl HTTP/1.1
              Cache-Control: max-age = 3000
              Connection: Keep-Alive
              Accept: */*
              If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
              User-Agent: Microsoft-CryptoAPI/10.0
              Host: c.pki.goog
              Apr 8, 2025 08:18:53.886548996 CEST1243INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
              Cross-Origin-Resource-Policy: cross-origin
              Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
              Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
              Content-Length: 530
              X-Content-Type-Options: nosniff
              Server: sffe
              X-XSS-Protection: 0
              Date: Tue, 08 Apr 2025 05:48:38 GMT
              Expires: Tue, 08 Apr 2025 06:38:38 GMT
              Cache-Control: public, max-age=3000
              Age: 1815
              Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
              Content-Type: application/pkix-crl
              Vary: Accept-Encoding
              Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
              Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.549701142.250.176.1964431516C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-08 06:19:01 UTC575OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
              Host: www.google.com
              Connection: keep-alive
              X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIk6HLAQiJo8sBCIWgzQEI9s/OAQiB1s4BCMHYzgEI0uDOAQiv5M4BCOLkzgEIi+XOAQ==
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-08 06:19:01 UTC1303INHTTP/1.1 200 OK
              Date: Tue, 08 Apr 2025 06:19:01 GMT
              Pragma: no-cache
              Expires: -1
              Cache-Control: no-cache, must-revalidate
              Content-Type: text/javascript; charset=UTF-8
              Strict-Transport-Security: max-age=31536000
              Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-qVjxJjcS6YoP2VUc8mSgJQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
              Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
              Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
              Accept-CH: Sec-CH-Prefers-Color-Scheme
              Accept-CH: Downlink
              Accept-CH: RTT
              Accept-CH: Sec-CH-UA-Form-Factors
              Accept-CH: Sec-CH-UA-Platform
              Accept-CH: Sec-CH-UA-Platform-Version
              Accept-CH: Sec-CH-UA-Full-Version
              Accept-CH: Sec-CH-UA-Arch
              Accept-CH: Sec-CH-UA-Model
              Accept-CH: Sec-CH-UA-Bitness
              Accept-CH: Sec-CH-UA-Full-Version-List
              Accept-CH: Sec-CH-UA-WoW64
              Permissions-Policy: unload=()
              Content-Disposition: attachment; filename="f.txt"
              Server: gws
              X-XSS-Protection: 0
              X-Frame-Options: SAMEORIGIN
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2025-04-08 06:19:01 UTC1094INData Raw: 34 33 66 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 65 61 73 74 65 72 20 73 68 6f 70 70 69 6e 67 20 62 6c 61 63 6b 6f 75 74 22 2c 22 70 6a 20 62 6c 75 65 20 6c 6f 75 69 73 76 69 6c 6c 65 20 66 6f 6f 74 62 61 6c 6c 22 2c 22 63 61 73 74 20 6c 6f 76 65 20 6f 6e 20 74 68 65 20 73 70 65 63 74 72 75 6d 20 73 65 61 73 6f 6e 20 33 22 2c 22 6e 69 6e 74 65 6e 64 6f 20 6d 61 72 69 6f 20 6b 61 72 74 20 77 6f 72 6c 64 22 2c 22 74 6f 72 6e 61 64 6f 65 73 20 6c 65 6f 6e 20 63 6f 75 6e 74 79 22 2c 22 61 75 72 6f 72 61 20 62 6f 72 65 61 6c 69 73 20 66 6f 72 65 63 61 73 74 22 2c 22 66 72 75 69 74 79 20 70 65 62 62 6c 65 73 20 64 6f 6e 75 74 73 22 2c 22 61 78 65 20 63 65 72 65 6d 6f 6e 69 61 20 6d 75 73 69 63 20 66 65 73 74 69 76 61 6c 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22
              Data Ascii: 43f)]}'["",["easter shopping blackout","pj blue louisville football","cast love on the spectrum season 3","nintendo mario kart world","tornadoes leon county","aurora borealis forecast","fruity pebbles donuts","axe ceremonia music festival"],["","","","
              2025-04-08 06:19:01 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              01020s020406080100

              Click to jump to process

              Click to jump to process

              Target ID:3
              Start time:02:18:47
              Start date:08/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff7b2be0000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:4
              Start time:02:18:51
              Start date:08/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2016 /prefetch:3
              Imagebase:0x7ff7b2be0000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:5
              Start time:02:18:54
              Start date:08/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,849919240312230884,2084503016808836682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3736 /prefetch:8
              Imagebase:0x7ff7b2be0000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:8
              Start time:02:18:57
              Start date:08/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.translatebonus.net"
              Imagebase:0x7ff7b2be0000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly