Edit tour

Windows Analysis Report
http://m.exactag.com/ai.aspx

Overview

General Information

Sample URL:http://m.exactag.com/ai.aspx
Analysis ID:1661715
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,5433129977445262161,2567772436523484126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2036 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://m.exactag.com/ai.aspx" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://cdn.exactag.com/1x1.gifHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 85.14.248.72:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 79.127.206.235:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 79.127.206.235:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /ai.aspx HTTP/1.1Host: m.exactag.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /1x1.gif HTTP/1.1Host: cdn.exactag.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.exactag.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://cdn.exactag.com/1x1.gifAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.exactag.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: m.exactag.com
Source: global trafficDNS traffic detected: DNS query: cdn.exactag.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 85.14.248.72:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 79.127.206.235:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 79.127.206.235:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir5928_1500515298Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir5928_1500515298Jump to behavior
Source: classification engineClassification label: clean1.win@22/5@10/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,5433129977445262161,2567772436523484126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2036 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://m.exactag.com/ai.aspx"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,5433129977445262161,2567772436523484126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2036 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1661715 URL: http://m.exactag.com/ai.aspx Startdate: 10/04/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.23 unknown unknown 5->13 15 192.168.2.4, 138, 443, 49512 unknown unknown 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 85.14.248.72, 443, 49730 MYLOC-ASIPBackboneofmyLocmanagedITAGDE Germany 10->17 19 tp-emea.exactag.com 85.14.248.91, 49728, 49729, 80 MYLOC-ASIPBackboneofmyLocmanagedITAGDE Germany 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://m.exactag.com/ai.aspx0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.35.164
truefalse
    high
    tp-emea.exactag.com
    85.14.248.91
    truefalse
      high
      1864845291.rsc.cdn77.org
      79.127.206.235
      truefalse
        high
        m.exactag.com
        unknown
        unknownfalse
          high
          cdn.exactag.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://cdn.exactag.com/favicon.icofalse
              high
              https://cdn.exactag.com/1x1.giffalse
                high
                https://m.exactag.com/ai.aspxfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  85.14.248.72
                  unknownGermany
                  24961MYLOC-ASIPBackboneofmyLocmanagedITAGDEfalse
                  85.14.248.91
                  tp-emea.exactag.comGermany
                  24961MYLOC-ASIPBackboneofmyLocmanagedITAGDEfalse
                  79.127.206.235
                  1864845291.rsc.cdn77.orgCzech Republic
                  9080GINCzechRepublicEUCZfalse
                  142.251.35.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  192.168.2.23
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1661715
                  Start date and time:2025-04-10 11:52:35 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 1s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://m.exactag.com/ai.aspx
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:21
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean1.win@22/5@10/6
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.251.41.3, 142.251.40.238, 142.251.179.84, 142.250.80.110, 142.250.81.238, 142.250.65.206, 142.251.35.174, 172.217.165.142, 142.251.40.142, 142.251.32.110, 142.250.65.227, 142.250.65.195, 142.250.65.238, 184.31.69.3, 204.79.197.222, 20.109.210.53
                  • Excluded domains from analysis (whitelisted): fp.msedge.net, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • VT rate limit hit for: http://m.exactag.com/ai.aspx
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
                  Category:downloaded
                  Size (bytes):503
                  Entropy (8bit):7.430762214701603
                  Encrypted:false
                  SSDEEP:12:6v/7Qs07xF5sGdZwZV0Ub6LREVV+LDr4QGDaRKnGmPbaeCR3GN4jtLyQFbx4R1:SWjOZVL6y0Dr4RDFGmR1NmmWbxo1
                  MD5:0B992B7E2D29CBCA8943C6596CA2C5EE
                  SHA1:90DEE84691A0F457C1DF9BD0BF30CA4A91C78393
                  SHA-256:A410CC8EA6FF8FAC6A200E4D380DD6B1F0A40F724475BD003864EE6AE8F5F277
                  SHA-512:392D6C891E3AA2999D16AD15F99D793AEB1E58CEC475878EA80FD2CEF5FBAF0680185F035BECD43777A04567481E42346C069B346E91F50441C3E231E3FD68E7
                  Malicious:false
                  Reputation:low
                  URL:https://cdn.exactag.com/favicon.ico
                  Preview:.PNG........IHDR... ... .....V.%(....IDAT8..K(.Q....7.yDI..JM..H.(Y IR...6j..D....B....YZ(.,$...j..h2..1..0...s.fVrW.......\.K.,..p8(.mM2..r...u......*`.S...7....~""......NDD.6...c.DD........*........Q;...n.....~{m.)u9.5.R 5...*._.w @G..6AdQ.>..j.....}q&....E.K.|.W.1:.7...91.i+..XL...?b..&.....O...[.x./z..9'x.UE.u...M..'L................/....n}%.....E.|.c@]|.,..v.....$....P...p+...r..G../[<..(e...8......1....^.xh..BA..R.k&Y..7.........3...3..v)&......4.-......IEND.B`.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:GIF image data, version 89a, 1 x 1
                  Category:downloaded
                  Size (bytes):799
                  Entropy (8bit):0.26440374314321946
                  Encrypted:false
                  SSDEEP:3:CUD//Rlzeze:Reze
                  MD5:124ECA84ABCE0CCCB0208C5EF285E6FD
                  SHA1:AA5973034EEB0FA83FA772AC526641B24A135B94
                  SHA-256:86927CAFA657AE14A28BDCA63BEFB837251FC4CE67683AA19FDCCF4D1BFEEF3B
                  SHA-512:8E8A05E499E90BD106B2BDF2F3425989D71523D35297748CAE0C51C0863AD2F1C0288B7932642FF73902F1DB0F1C3CD70C2578093BC4EC56529365D848435C09
                  Malicious:false
                  Reputation:low
                  URL:https://cdn.exactag.com/1x1.gif
                  Preview:GIF89a.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................,................;
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
                  Category:dropped
                  Size (bytes):503
                  Entropy (8bit):7.430762214701603
                  Encrypted:false
                  SSDEEP:12:6v/7Qs07xF5sGdZwZV0Ub6LREVV+LDr4QGDaRKnGmPbaeCR3GN4jtLyQFbx4R1:SWjOZVL6y0Dr4RDFGmR1NmmWbxo1
                  MD5:0B992B7E2D29CBCA8943C6596CA2C5EE
                  SHA1:90DEE84691A0F457C1DF9BD0BF30CA4A91C78393
                  SHA-256:A410CC8EA6FF8FAC6A200E4D380DD6B1F0A40F724475BD003864EE6AE8F5F277
                  SHA-512:392D6C891E3AA2999D16AD15F99D793AEB1E58CEC475878EA80FD2CEF5FBAF0680185F035BECD43777A04567481E42346C069B346E91F50441C3E231E3FD68E7
                  Malicious:false
                  Reputation:low
                  Preview:.PNG........IHDR... ... .....V.%(....IDAT8..K(.Q....7.yDI..JM..H.(Y IR...6j..D....B....YZ(.,$...j..h2..1..0...s.fVrW.......\.K.,..p8(.mM2..r...u......*`.S...7....~""......NDD.6...c.DD........*........Q;...n.....~{m.)u9.5.R 5...*._.w @G..6AdQ.>..j.....}q&....E.K.|.W.1:.7...91.i+..XL...?b..&.....O...[.x./z..9'x.UE.u...M..'L................/....n}%.....E.|.c@]|.,..v.....$....P...p+...r..G../[<..(e...8......1....^.xh..BA..R.k&Y..7.........3...3..v)&......4.-......IEND.B`.
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 87
                  • 443 (HTTPS)
                  • 80 (HTTP)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 10, 2025 11:53:29.813055992 CEST4968180192.168.2.42.17.190.73
                  Apr 10, 2025 11:53:36.170502901 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:36.506928921 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:37.211571932 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:38.421508074 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:39.421442032 CEST4968180192.168.2.42.17.190.73
                  Apr 10, 2025 11:53:40.828011990 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:41.274811029 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:41.274852037 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:41.274950027 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:41.275115013 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:41.275122881 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:41.477695942 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:41.477771044 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:41.479196072 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:41.479208946 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:41.479432106 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:41.530906916 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:42.974819899 CEST4972880192.168.2.485.14.248.91
                  Apr 10, 2025 11:53:42.975227118 CEST4972980192.168.2.485.14.248.91
                  Apr 10, 2025 11:53:42.998342037 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:42.998383045 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:42.998454094 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:42.998712063 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:42.998725891 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.143987894 CEST804972985.14.248.91192.168.2.4
                  Apr 10, 2025 11:53:43.144063950 CEST4972980192.168.2.485.14.248.91
                  Apr 10, 2025 11:53:43.145281076 CEST804972885.14.248.91192.168.2.4
                  Apr 10, 2025 11:53:43.145340919 CEST4972880192.168.2.485.14.248.91
                  Apr 10, 2025 11:53:43.520850897 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.520934105 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:43.527043104 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:43.527060986 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.527312040 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.527575016 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:43.568274975 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.701440096 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.701525927 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.701575041 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:43.704102039 CEST49730443192.168.2.485.14.248.72
                  Apr 10, 2025 11:53:43.704125881 CEST4434973085.14.248.72192.168.2.4
                  Apr 10, 2025 11:53:43.809520006 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:43.809568882 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:43.809917927 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:43.809917927 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:43.809950113 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.002382994 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:44.016426086 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.017261982 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.021583080 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.021605968 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.021938086 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.022648096 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.064279079 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.206650019 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.206721067 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.207287073 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.249428034 CEST49732443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.249465942 CEST4434973279.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.292802095 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.292866945 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.293142080 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.293142080 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.293180943 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.314008951 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:44.491625071 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.492165089 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.492208004 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.492513895 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.492528915 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.874672890 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.874747038 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:44.874815941 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.928731918 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:44.995181084 CEST49733443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:44.995220900 CEST4434973379.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.360332012 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.360375881 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.360446930 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.360646963 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.360660076 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.557956934 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.558057070 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.577325106 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.577338934 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.577630997 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.589001894 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.636264086 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.640341043 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:53:45.753246069 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.753331900 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:45.753384113 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.755142927 CEST49737443192.168.2.479.127.206.235
                  Apr 10, 2025 11:53:45.755167007 CEST4434973779.127.206.235192.168.2.4
                  Apr 10, 2025 11:53:46.140312910 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:48.547372103 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:48.588229895 CEST49709443192.168.2.4131.253.33.254
                  Apr 10, 2025 11:53:48.594763041 CEST49709443192.168.2.4131.253.33.254
                  Apr 10, 2025 11:53:48.688045979 CEST44349709131.253.33.254192.168.2.4
                  Apr 10, 2025 11:53:48.694689989 CEST44349709131.253.33.254192.168.2.4
                  Apr 10, 2025 11:53:48.698565960 CEST44349709131.253.33.254192.168.2.4
                  Apr 10, 2025 11:53:48.698589087 CEST44349709131.253.33.254192.168.2.4
                  Apr 10, 2025 11:53:48.698653936 CEST49709443192.168.2.4131.253.33.254
                  Apr 10, 2025 11:53:48.698689938 CEST49709443192.168.2.4131.253.33.254
                  Apr 10, 2025 11:53:51.497546911 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:51.497616053 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:51.497684956 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:53.359483004 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:53:53.468103886 CEST49726443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:53:53.468136072 CEST44349726142.251.35.164192.168.2.4
                  Apr 10, 2025 11:53:55.253220081 CEST49671443192.168.2.4204.79.197.203
                  Apr 10, 2025 11:54:02.964418888 CEST49678443192.168.2.420.189.173.27
                  Apr 10, 2025 11:54:03.315399885 CEST804972985.14.248.91192.168.2.4
                  Apr 10, 2025 11:54:03.315499067 CEST4972980192.168.2.485.14.248.91
                  Apr 10, 2025 11:54:03.318110943 CEST804972885.14.248.91192.168.2.4
                  Apr 10, 2025 11:54:03.318166971 CEST4972880192.168.2.485.14.248.91
                  Apr 10, 2025 11:54:03.452537060 CEST4972880192.168.2.485.14.248.91
                  Apr 10, 2025 11:54:03.452574968 CEST4972980192.168.2.485.14.248.91
                  Apr 10, 2025 11:54:03.623923063 CEST804972985.14.248.91192.168.2.4
                  Apr 10, 2025 11:54:03.624898911 CEST804972885.14.248.91192.168.2.4
                  Apr 10, 2025 11:54:22.703458071 CEST4971280192.168.2.4199.232.210.172
                  Apr 10, 2025 11:54:22.704277039 CEST4971480192.168.2.4199.232.210.172
                  Apr 10, 2025 11:54:22.796068907 CEST8049712199.232.210.172192.168.2.4
                  Apr 10, 2025 11:54:22.796093941 CEST8049712199.232.210.172192.168.2.4
                  Apr 10, 2025 11:54:22.796288967 CEST4971280192.168.2.4199.232.210.172
                  Apr 10, 2025 11:54:22.797122955 CEST8049714199.232.210.172192.168.2.4
                  Apr 10, 2025 11:54:22.797301054 CEST8049714199.232.210.172192.168.2.4
                  Apr 10, 2025 11:54:22.797370911 CEST4971480192.168.2.4199.232.210.172
                  Apr 10, 2025 11:54:41.236058950 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:41.236160040 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:41.236285925 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:41.236417055 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:41.236454010 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:41.443386078 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:41.443627119 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:41.443681955 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:51.473167896 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:51.473232031 CEST44349744142.251.35.164192.168.2.4
                  Apr 10, 2025 11:54:51.473288059 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:53.439419031 CEST49744443192.168.2.4142.251.35.164
                  Apr 10, 2025 11:54:53.439496040 CEST44349744142.251.35.164192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 10, 2025 11:53:37.522022963 CEST53505071.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:37.523706913 CEST53615421.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:38.065690041 CEST53601091.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:38.470735073 CEST53512371.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:41.173444033 CEST4951253192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:41.173707008 CEST5598453192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:41.273154020 CEST53559841.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:41.273178101 CEST53495121.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:42.869436026 CEST6531353192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:42.869781971 CEST6012753192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:42.896356106 CEST5696653192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:42.896531105 CEST6311353192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:42.970632076 CEST53653131.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:42.973151922 CEST53601271.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:42.997210026 CEST53569661.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:42.997797966 CEST53631131.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:43.706167936 CEST5404753192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:43.706449986 CEST6001353192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:43.807686090 CEST53540471.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:43.809076071 CEST53600131.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:45.256020069 CEST6465853192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:45.256359100 CEST5244853192.168.2.41.1.1.1
                  Apr 10, 2025 11:53:45.358218908 CEST53646581.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:45.358763933 CEST53524481.1.1.1192.168.2.4
                  Apr 10, 2025 11:53:55.534100056 CEST53537281.1.1.1192.168.2.4
                  Apr 10, 2025 11:54:14.474997997 CEST53550051.1.1.1192.168.2.4
                  Apr 10, 2025 11:54:36.790066004 CEST53529221.1.1.1192.168.2.4
                  Apr 10, 2025 11:54:36.813693047 CEST53520151.1.1.1192.168.2.4
                  Apr 10, 2025 11:54:38.368050098 CEST53499901.1.1.1192.168.2.4
                  Apr 10, 2025 11:54:43.523139954 CEST138138192.168.2.4192.168.2.255
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Apr 10, 2025 11:53:41.173444033 CEST192.168.2.41.1.1.10x99a8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:41.173707008 CEST192.168.2.41.1.1.10x1aa6Standard query (0)www.google.com65IN (0x0001)false
                  Apr 10, 2025 11:53:42.869436026 CEST192.168.2.41.1.1.10xdc95Standard query (0)m.exactag.comA (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:42.869781971 CEST192.168.2.41.1.1.10xa434Standard query (0)m.exactag.com65IN (0x0001)false
                  Apr 10, 2025 11:53:42.896356106 CEST192.168.2.41.1.1.10x5684Standard query (0)m.exactag.comA (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:42.896531105 CEST192.168.2.41.1.1.10x95adStandard query (0)m.exactag.com65IN (0x0001)false
                  Apr 10, 2025 11:53:43.706167936 CEST192.168.2.41.1.1.10xb490Standard query (0)cdn.exactag.comA (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:43.706449986 CEST192.168.2.41.1.1.10x2118Standard query (0)cdn.exactag.com65IN (0x0001)false
                  Apr 10, 2025 11:53:45.256020069 CEST192.168.2.41.1.1.10x280bStandard query (0)cdn.exactag.comA (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:45.256359100 CEST192.168.2.41.1.1.10xc1a5Standard query (0)cdn.exactag.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Apr 10, 2025 11:53:41.273154020 CEST1.1.1.1192.168.2.40x1aa6No error (0)www.google.com65IN (0x0001)false
                  Apr 10, 2025 11:53:41.273178101 CEST1.1.1.1192.168.2.40x99a8No error (0)www.google.com142.251.35.164A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:42.970632076 CEST1.1.1.1192.168.2.40xdc95No error (0)m.exactag.comtp-emea.exactag.comCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:42.970632076 CEST1.1.1.1192.168.2.40xdc95No error (0)tp-emea.exactag.com85.14.248.91A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:42.973151922 CEST1.1.1.1192.168.2.40xa434No error (0)m.exactag.comtp-emea.exactag.comCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:42.997210026 CEST1.1.1.1192.168.2.40x5684No error (0)m.exactag.comtp-emea.exactag.comCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:42.997210026 CEST1.1.1.1192.168.2.40x5684No error (0)tp-emea.exactag.com85.14.248.72A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:42.997797966 CEST1.1.1.1192.168.2.40x95adNo error (0)m.exactag.comtp-emea.exactag.comCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:43.807686090 CEST1.1.1.1192.168.2.40xb490No error (0)cdn.exactag.com1864845291.rsc.cdn77.orgCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:43.807686090 CEST1.1.1.1192.168.2.40xb490No error (0)1864845291.rsc.cdn77.org79.127.206.235A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:43.807686090 CEST1.1.1.1192.168.2.40xb490No error (0)1864845291.rsc.cdn77.org79.127.206.207A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:43.809076071 CEST1.1.1.1192.168.2.40x2118No error (0)cdn.exactag.com1864845291.rsc.cdn77.orgCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:45.358218908 CEST1.1.1.1192.168.2.40x280bNo error (0)cdn.exactag.com1864845291.rsc.cdn77.orgCNAME (Canonical name)IN (0x0001)false
                  Apr 10, 2025 11:53:45.358218908 CEST1.1.1.1192.168.2.40x280bNo error (0)1864845291.rsc.cdn77.org79.127.206.235A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:45.358218908 CEST1.1.1.1192.168.2.40x280bNo error (0)1864845291.rsc.cdn77.org79.127.206.208A (IP address)IN (0x0001)false
                  Apr 10, 2025 11:53:45.358763933 CEST1.1.1.1192.168.2.40xc1a5No error (0)cdn.exactag.com1864845291.rsc.cdn77.orgCNAME (Canonical name)IN (0x0001)false
                  • m.exactag.com
                  • cdn.exactag.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44973085.14.248.724431228C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-10 09:53:43 UTC670OUTGET /ai.aspx HTTP/1.1
                  Host: m.exactag.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-10 09:53:43 UTC710INHTTP/1.1 302 Found
                  Connection: close
                  Date: Thu, 10 Apr 2025 09:53:42 GMT
                  Content-Type: text/html; charset=utf-8
                  Cache-Control: max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                  Pragma: no-cache
                  Transfer-Encoding: chunked
                  Expires: Mon, 26 Jul 1997 05:00:00 GMT
                  Last-Modified: Do, 10 Apr 2025 09:53:43 GMT
                  Location: https://cdn.exactag.com/1x1.gif
                  P3P: policyref="https://m.exactag.com/w3c/p3p.xml", CP="NOI NID STP STA CUR OUR"
                  X-ET-Code: 20
                  X-ET-Camp: 0
                  X-ET-Monitoring: 1
                  X-ET-RequestId: 4493d160-b7f8-408a-b7d3-3ef67c0da827
                  Strict-Transport-Security: max-age=31536000
                  cross-origin-resource-policy: cross-origin
                  X-Xss-Protection: 0
                  X-Content-Type-Options: nosniff
                  2025-04-10 09:53:43 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44973279.127.206.2354431228C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-10 09:53:44 UTC672OUTGET /1x1.gif HTTP/1.1
                  Host: cdn.exactag.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-10 09:53:44 UTC538INHTTP/1.1 200 OK
                  Date: Thu, 10 Apr 2025 09:53:44 GMT
                  Content-Type: image/gif
                  Content-Length: 799
                  Connection: close
                  Last-Modified: Tue, 09 Jan 2024 16:31:09 GMT
                  x-rgw-object-type: Normal
                  ETag: "07b81fc1dad971b1c82bff6798131113-1"
                  x-amz-request-id: tx0000024bab65f294bfd6e-0066dc342c-69d73f2-prg
                  X-77-NZT: EwwBT3/O6QHXgAEAAAwBnJI76AG3rgEAAAgBWbu8pgAA
                  X-77-NZT-Ray: f03d06135a541cfb2895f76792a74609
                  X-77-Cache: HIT
                  X-77-Age: 384
                  Server: CDN77-Turbo
                  Access-Control-Allow-Origin: *
                  X-77-POP: newyorkUSNY
                  Accept-Ranges: bytes
                  2025-04-10 09:53:44 UTC799INData Raw: 47 49 46 38 39 61 01 00 01 00 f7 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  Data Ascii: GIF89a


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.44973379.127.206.2354431228C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-10 09:53:44 UTC600OUTGET /favicon.ico HTTP/1.1
                  Host: cdn.exactag.com
                  Connection: keep-alive
                  sec-ch-ua-platform: "Windows"
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://cdn.exactag.com/1x1.gif
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-10 09:53:44 UTC565INHTTP/1.1 200 OK
                  Date: Thu, 10 Apr 2025 09:53:44 GMT
                  Content-Type: image/x-icon
                  Content-Length: 503
                  Connection: close
                  Vary: Accept-Encoding
                  Last-Modified: Tue, 09 Jan 2024 17:12:19 GMT
                  x-rgw-object-type: Normal
                  ETag: "b3d745601af53dd937816023d8782cff-1"
                  x-amz-request-id: tx00000a3288e6cea9d6568-0066ea427a-69a661d-prg
                  X-77-NZT: EwwBT3/O6QGW6QwAAAwBuTvfFAG3xgAAAAgBbT1aDQAA
                  X-77-NZT-Ray: f03d0613ce4f5f052895f7679e321026
                  X-77-Cache: HIT
                  X-77-Age: 3305
                  Server: CDN77-Turbo
                  Access-Control-Allow-Origin: *
                  X-77-POP: newyorkUSNY
                  Accept-Ranges: bytes
                  2025-04-10 09:53:44 UTC503INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 00 00 00 00 56 11 25 28 00 00 01 be 49 44 41 54 38 cb b5 92 4b 28 84 51 14 c7 ff df 37 0f 79 44 49 99 f1 4a 4d c9 a3 d1 48 a4 28 59 20 49 52 b2 b0 19 36 6a 16 8a 44 89 05 c5 c2 42 99 94 94 14 59 5a 28 c9 82 2c 24 0b af bc 6a b2 f0 68 32 a2 86 31 18 c6 30 f3 1d 8b 73 e7 a1 66 56 72 57 f7 9e ff ff 9e f3 bb e7 5c e0 af 4b 82 2c f1 8e 94 88 70 38 28 c9 6d 4d 32 00 e0 72 d2 1d d2 75 fd 19 00 80 c0 f2 2a 60 d8 53 88 88 c8 37 a6 0d ea c9 b3 7e 22 22 0a ac ea 01 a0 da 4e 44 44 e4 36 8b bc f1 63 9f 44 44 a4 ec 18 18 c3 fc c2 8e 9b 2a 00 80 a6 e7 8d f5 b3 12 91 51 3b ee e3 c8 6e 2e 00 b9 dd c5 7e 7b 6d 88 29 75 39 c0 35 97 52 20 35 dc b2 fe d0 2a 85 5f 95 77 20 40 47 b4 e5 36 41 64 51 89 3e
                  Data Ascii: PNGIHDR V%(IDAT8K(Q7yDIJMH(Y IR6jDBYZ(,$jh210sfVrW\K,p8(mM2ru*`S7~""NDD6cDD*Q;n.~{m)u95R 5*_w @G6AdQ>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.44973779.127.206.2354431228C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-10 09:53:45 UTC390OUTGET /favicon.ico HTTP/1.1
                  Host: cdn.exactag.com
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: */*
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: cors
                  Sec-Fetch-Dest: empty
                  Sec-Fetch-Storage-Access: active
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-10 09:53:45 UTC562INHTTP/1.1 200 OK
                  Date: Thu, 10 Apr 2025 09:53:45 GMT
                  Content-Type: image/x-icon
                  Content-Length: 503
                  Connection: close
                  Vary: Accept-Encoding
                  Last-Modified: Tue, 09 Jan 2024 17:12:19 GMT
                  x-rgw-object-type: Normal
                  ETag: "b3d745601af53dd937816023d8782cff-1"
                  x-amz-request-id: tx00000a3288e6cea9d6568-0066ea427a-69a661d-prg
                  X-77-NZT: EwwBT3/O6QHXAQAAAAwBuTvfFAG3xgAAAAgBbT1aDQAA
                  X-77-NZT-Ray: f03d06136f47191b2995f7671d0ffe29
                  X-77-Cache: HIT
                  X-77-Age: 1
                  Server: CDN77-Turbo
                  Access-Control-Allow-Origin: *
                  X-77-POP: newyorkUSNY
                  Accept-Ranges: bytes
                  2025-04-10 09:53:45 UTC503INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 00 00 00 00 56 11 25 28 00 00 01 be 49 44 41 54 38 cb b5 92 4b 28 84 51 14 c7 ff df 37 0f 79 44 49 99 f1 4a 4d c9 a3 d1 48 a4 28 59 20 49 52 b2 b0 19 36 6a 16 8a 44 89 05 c5 c2 42 99 94 94 14 59 5a 28 c9 82 2c 24 0b af bc 6a b2 f0 68 32 a2 86 31 18 c6 30 f3 1d 8b 73 e7 a1 66 56 72 57 f7 9e ff ff 9e f3 bb e7 5c e0 af 4b 82 2c f1 8e 94 88 70 38 28 c9 6d 4d 32 00 e0 72 d2 1d d2 75 fd 19 00 80 c0 f2 2a 60 d8 53 88 88 c8 37 a6 0d ea c9 b3 7e 22 22 0a ac ea 01 a0 da 4e 44 44 e4 36 8b bc f1 63 9f 44 44 a4 ec 18 18 c3 fc c2 8e 9b 2a 00 80 a6 e7 8d f5 b3 12 91 51 3b ee e3 c8 6e 2e 00 b9 dd c5 7e 7b 6d 88 29 75 39 c0 35 97 52 20 35 dc b2 fe d0 2a 85 5f 95 77 20 40 47 b4 e5 36 41 64 51 89 3e
                  Data Ascii: PNGIHDR V%(IDAT8K(Q7yDIJMH(Y IR6jDBYZ(,$jh210sfVrW\K,p8(mM2ru*`S7~""NDD6cDD*Q;n.~{m)u95R 5*_w @G6AdQ>


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0050100MB

                  Click to jump to process

                  Target ID:1
                  Start time:05:53:31
                  Start date:10/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff786830000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:05:53:35
                  Start date:10/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,5433129977445262161,2567772436523484126,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2036 /prefetch:3
                  Imagebase:0x7ff786830000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:4
                  Start time:05:53:41
                  Start date:10/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://m.exactag.com/ai.aspx"
                  Imagebase:0x7ff786830000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly