Edit tour

Windows Analysis Report
http://storage.ml-cachehost.net/lib/config-a.js

Overview

General Information

Sample URL:http://storage.ml-cachehost.net/lib/config-a.js
Analysis ID:1663590
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2592 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,10697822270708087813,16803609729803447203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2120 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6872 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://storage.ml-cachehost.net/lib/config-a.js" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 142.251.15.99:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.17.111:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.48.20
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.48.20
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /lib/config-a.js HTTP/1.1Host: storage.ml-cachehost.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: storage.ml-cachehost.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://storage.ml-cachehost.net/lib/config-a.jsAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: storage.ml-cachehost.net
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 453Content-Type: application/reports+jsonOrigin: https://storage.ml-cachehost.netUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Fri, 11 Apr 2025 22:43:31 GMTContent-Type: application/xml; charset=UTF-8Content-Length: 111Connection: closeX-GUploader-UploadID: AKDAyIuTX48-CTrr43lK42Ma0FxhGV7yANBC6HZxlzN7M7m_DShX8VrrLdAGynAJBe_A0MwN4OiubWoExpires: Fri, 11 Apr 2025 22:43:31 GMTCache-Control: private, max-age=0CF-Cache-Status: BYPASSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 92ee00d7b9aabd52-ATLalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=108246&min_rtt=108232&rtt_var=22852&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2838&recv_bytes=1198&delivery_rate=37291&cwnd=252&unsent_bytes=0&cid=83c723110f70fe15&ts=334&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 142.251.15.99:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.17.111:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: classification engineClassification label: clean0.win@22/2@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,10697822270708087813,16803609729803447203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2120 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://storage.ml-cachehost.net/lib/config-a.js"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,10697822270708087813,16803609729803447203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2120 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1663590 URL: http://storage.ml-cachehost... Startdate: 12/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49550 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.251.15.99, 443, 49724, 49742 GOOGLEUS United States 10->15 17 a.nel.cloudflare.com 35.190.80.1, 443, 49729, 49730 GOOGLEUS United States 10->17 19 2 other IPs or domains 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://storage.ml-cachehost.net/lib/config-a.js0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    storage.ml-cachehost.net
    172.67.175.195
    truefalse
      high
      www.google.com
      142.251.15.99
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://storage.ml-cachehost.net/favicon.icofalse
          high
          https://storage.ml-cachehost.net/lib/config-a.jsfalse
            high
            https://a.nel.cloudflare.com/report/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3Dfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.251.15.99
              www.google.comUnited States
              15169GOOGLEUSfalse
              104.21.17.111
              unknownUnited States
              13335CLOUDFLARENETUSfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1663590
              Start date and time:2025-04-12 00:42:27 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 54s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://storage.ml-cachehost.net/lib/config-a.js
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:19
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@22/2@8/4
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 64.233.185.94, 74.125.21.113, 74.125.21.101, 74.125.21.102, 74.125.21.138, 74.125.21.139, 74.125.21.100, 173.194.219.139, 173.194.219.100, 173.194.219.102, 173.194.219.138, 173.194.219.113, 173.194.219.101, 64.233.185.84, 74.125.136.100, 74.125.136.113, 74.125.136.101, 74.125.136.102, 74.125.136.138, 74.125.136.139, 64.233.176.139, 64.233.176.101, 64.233.176.113, 64.233.176.102, 64.233.176.138, 64.233.176.100, 74.125.138.100, 74.125.138.138, 74.125.138.102, 74.125.138.139, 74.125.138.101, 74.125.138.113, 23.13.145.132, 23.218.145.145, 108.177.122.102, 108.177.122.101, 108.177.122.138, 108.177.122.113, 108.177.122.139, 108.177.122.100, 142.250.9.139, 142.250.9.102, 142.250.9.113, 142.250.9.100, 142.250.9.101, 142.250.9.138, 74.125.138.94, 23.79.17.61, 4.245.163.56
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenFile calls found.
              • VT rate limit hit for: http://storage.ml-cachehost.net/lib/config-a.js
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):111
              Entropy (8bit):4.62062991365628
              Encrypted:false
              SSDEEP:3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n
              MD5:E7A9350210B4DBA641F6020447C96045
              SHA1:581ACCEF4A8B7FBED97291FE7DD4E113F794EC80
              SHA-256:08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80
              SHA-512:2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2
              Malicious:false
              Reputation:low
              URL:https://storage.ml-cachehost.net/favicon.ico
              Preview:<?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 87
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Apr 12, 2025 00:43:19.097172976 CEST49680443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:25.252866030 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:25.554990053 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:26.159884930 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:27.362838030 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:28.384222031 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.384325981 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:28.384408951 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.384569883 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.384592056 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:28.617815018 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:28.618005037 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.619036913 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.619087934 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:28.619858980 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:28.674618959 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:28.705979109 CEST49680443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:29.768381119 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:30.064481020 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.064521074 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.064593077 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.064723015 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.064734936 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.296408892 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.296518087 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.297544003 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.297558069 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.297930002 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.298258066 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.307915926 CEST8049711217.20.48.20192.168.2.4
              Apr 12, 2025 00:43:30.308027983 CEST4971180192.168.2.4217.20.48.20
              Apr 12, 2025 00:43:30.340310097 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.571073055 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.571216106 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.571398020 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.696463108 CEST49726443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.696532965 CEST44349726104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.723651886 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.723752022 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.723831892 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.724037886 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.724066973 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.950330019 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.956950903 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.957041979 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:30.963004112 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:30.963058949 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:31.279164076 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:31.279315948 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:31.279393911 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:31.287734032 CEST49727443192.168.2.4104.21.17.111
              Apr 12, 2025 00:43:31.287779093 CEST44349727104.21.17.111192.168.2.4
              Apr 12, 2025 00:43:31.390041113 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.390067101 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.390122890 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.390244007 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.390254021 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.626157999 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.626306057 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.627754927 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.627763987 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.628104925 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.628437042 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.676276922 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.860157013 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.860372066 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.860569954 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.860631943 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.860651970 CEST4434972935.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.860661983 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.860702038 CEST49729443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.861468077 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.861562014 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:31.861650944 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.861766100 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:31.861793041 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.085206985 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.085571051 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:32.085633039 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.085696936 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:32.085719109 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.324670076 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.324750900 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.325097084 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:32.325097084 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:32.325167894 CEST4434973035.190.80.1192.168.2.4
              Apr 12, 2025 00:43:32.325231075 CEST49730443192.168.2.435.190.80.1
              Apr 12, 2025 00:43:34.021826982 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:34.330785036 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:34.580738068 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:34.941941023 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:36.145057917 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:38.372167110 CEST4971180192.168.2.4217.20.48.20
              Apr 12, 2025 00:43:38.381907940 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:38.478343010 CEST8049711217.20.48.20192.168.2.4
              Apr 12, 2025 00:43:38.550476074 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:38.609970093 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:38.610032082 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:38.610441923 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:38.690962076 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:38.708184958 CEST49724443192.168.2.4142.251.15.99
              Apr 12, 2025 00:43:38.708245993 CEST44349724142.251.15.99192.168.2.4
              Apr 12, 2025 00:43:38.740854025 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.741553068 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.741592884 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.846874952 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.847500086 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.847557068 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.848139048 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.848181009 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.848258972 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.848328114 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.848885059 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.849777937 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.849798918 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:38.849848986 CEST49710443192.168.2.4204.79.197.222
              Apr 12, 2025 00:43:38.954762936 CEST44349710204.79.197.222192.168.2.4
              Apr 12, 2025 00:43:39.300487995 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:40.503575087 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:42.909929991 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:43.363070965 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:44.190582037 CEST49671443192.168.2.4204.79.197.203
              Apr 12, 2025 00:43:47.720808029 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:43:52.966629982 CEST49678443192.168.2.420.189.173.27
              Apr 12, 2025 00:43:57.323173046 CEST4968180192.168.2.42.17.190.73
              Apr 12, 2025 00:44:28.332983017 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:28.333070993 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:28.333173990 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:28.333352089 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:28.333388090 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:28.555896044 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:28.556436062 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:28.556492090 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:38.569329023 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:38.569399118 CEST44349742142.251.15.99192.168.2.4
              Apr 12, 2025 00:44:38.569566965 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:38.708471060 CEST49742443192.168.2.4142.251.15.99
              Apr 12, 2025 00:44:38.708504915 CEST44349742142.251.15.99192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 12, 2025 00:43:24.722714901 CEST53566971.1.1.1192.168.2.4
              Apr 12, 2025 00:43:24.725739956 CEST53588621.1.1.1192.168.2.4
              Apr 12, 2025 00:43:25.669807911 CEST53594761.1.1.1192.168.2.4
              Apr 12, 2025 00:43:25.857006073 CEST53643881.1.1.1192.168.2.4
              Apr 12, 2025 00:43:28.271564960 CEST6060153192.168.2.41.1.1.1
              Apr 12, 2025 00:43:28.271564960 CEST6188153192.168.2.41.1.1.1
              Apr 12, 2025 00:43:28.380261898 CEST53606011.1.1.1192.168.2.4
              Apr 12, 2025 00:43:28.383424044 CEST53618811.1.1.1192.168.2.4
              Apr 12, 2025 00:43:29.938505888 CEST6336553192.168.2.41.1.1.1
              Apr 12, 2025 00:43:29.938505888 CEST4993553192.168.2.41.1.1.1
              Apr 12, 2025 00:43:29.955585957 CEST6250253192.168.2.41.1.1.1
              Apr 12, 2025 00:43:29.956082106 CEST5760753192.168.2.41.1.1.1
              Apr 12, 2025 00:43:30.045631886 CEST53633651.1.1.1192.168.2.4
              Apr 12, 2025 00:43:30.046000004 CEST53499351.1.1.1192.168.2.4
              Apr 12, 2025 00:43:30.062899113 CEST53576071.1.1.1192.168.2.4
              Apr 12, 2025 00:43:30.064034939 CEST53625021.1.1.1192.168.2.4
              Apr 12, 2025 00:43:31.280375957 CEST5841953192.168.2.41.1.1.1
              Apr 12, 2025 00:43:31.280458927 CEST5180053192.168.2.41.1.1.1
              Apr 12, 2025 00:43:31.388853073 CEST53518001.1.1.1192.168.2.4
              Apr 12, 2025 00:43:31.389641047 CEST53584191.1.1.1192.168.2.4
              Apr 12, 2025 00:43:42.878786087 CEST53620801.1.1.1192.168.2.4
              Apr 12, 2025 00:44:01.816864967 CEST53552511.1.1.1192.168.2.4
              Apr 12, 2025 00:44:23.989916086 CEST53495501.1.1.1192.168.2.4
              Apr 12, 2025 00:44:24.476025105 CEST53516061.1.1.1192.168.2.4
              Apr 12, 2025 00:44:26.785655975 CEST53624231.1.1.1192.168.2.4
              Apr 12, 2025 00:44:33.510577917 CEST138138192.168.2.4192.168.2.255
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 12, 2025 00:43:28.271564960 CEST192.168.2.41.1.1.10xe493Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.271564960 CEST192.168.2.41.1.1.10x26bdStandard query (0)www.google.com65IN (0x0001)false
              Apr 12, 2025 00:43:29.938505888 CEST192.168.2.41.1.1.10x8a6bStandard query (0)storage.ml-cachehost.netA (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:29.938505888 CEST192.168.2.41.1.1.10xa241Standard query (0)storage.ml-cachehost.net65IN (0x0001)false
              Apr 12, 2025 00:43:29.955585957 CEST192.168.2.41.1.1.10xd24bStandard query (0)storage.ml-cachehost.netA (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:29.956082106 CEST192.168.2.41.1.1.10x7531Standard query (0)storage.ml-cachehost.net65IN (0x0001)false
              Apr 12, 2025 00:43:31.280375957 CEST192.168.2.41.1.1.10xa5ddStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:31.280458927 CEST192.168.2.41.1.1.10xf7e9Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.99A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.105A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.104A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.106A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.103A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.380261898 CEST1.1.1.1192.168.2.40xe493No error (0)www.google.com142.251.15.147A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:28.383424044 CEST1.1.1.1192.168.2.40x26bdNo error (0)www.google.com65IN (0x0001)false
              Apr 12, 2025 00:43:30.045631886 CEST1.1.1.1192.168.2.40x8a6bNo error (0)storage.ml-cachehost.net172.67.175.195A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:30.045631886 CEST1.1.1.1192.168.2.40x8a6bNo error (0)storage.ml-cachehost.net104.21.17.111A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:30.046000004 CEST1.1.1.1192.168.2.40xa241No error (0)storage.ml-cachehost.net65IN (0x0001)false
              Apr 12, 2025 00:43:30.062899113 CEST1.1.1.1192.168.2.40x7531No error (0)storage.ml-cachehost.net65IN (0x0001)false
              Apr 12, 2025 00:43:30.064034939 CEST1.1.1.1192.168.2.40xd24bNo error (0)storage.ml-cachehost.net104.21.17.111A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:30.064034939 CEST1.1.1.1192.168.2.40xd24bNo error (0)storage.ml-cachehost.net172.67.175.195A (IP address)IN (0x0001)false
              Apr 12, 2025 00:43:31.389641047 CEST1.1.1.1192.168.2.40xa5ddNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              • storage.ml-cachehost.net
              • a.nel.cloudflare.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449726104.21.17.1114432592C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-11 22:43:30 UTC689OUTGET /lib/config-a.js HTTP/1.1
              Host: storage.ml-cachehost.net
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-11 22:43:30 UTC1365INHTTP/1.1 200 OK
              Date: Fri, 11 Apr 2025 22:43:30 GMT
              Content-Type: text/javascript
              Content-Length: 0
              Connection: close
              X-GUploader-UploadID: AKDAyItOWdvyE7eVkYkCKhAOHi4AYxYcoGaWCHheJq4O-ehuv39PEHdVhtKJFxC7mb1pu4xUp6e1vJY
              x-goog-generation: 1743184271495855
              x-goog-metageneration: 4
              x-goog-stored-content-encoding: identity
              x-goog-stored-content-length: 0
              x-goog-hash: crc32c=AAAAAA==
              x-goog-hash: md5=1B2M2Y8AsgTpgAmY7PhCfg==
              x-goog-storage-class: STANDARD
              Accept-Ranges: bytes
              Expires: Tue, 08 Apr 2025 11:41:17 GMT
              Cache-Control: public, max-age=1209600
              Last-Modified: Fri, 28 Mar 2025 17:51:11 GMT
              ETag: "d41d8cd98f00b204e9800998ecf8427e"
              Age: 302407
              cf-cache-status: HIT
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OVG967uPMakUzr2gSMPHjgpAEtr67HdLDu0vOuN8EM%2BzTFnHXchY7obICqFM5igVQUKcjRXdU482y2Q8TzvNk0eL32wizv9gf%2BFekspXQATp8LOlJ1OSrMny%2BfztlDj8oLxVjDLI%2FVrrR2M%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Access-Control-Allow-Origin: *
              Server: cloudflare
              CF-RAY: 92ee00d39eadbfe0-ATL
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=106103&min_rtt=105933&rtt_var=22602&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2839&recv_bytes=1261&delivery_rate=37931&cwnd=252&unsent_bytes=0&cid=37e8446250971c29&ts=291&x=0"


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449727104.21.17.1114432592C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-11 22:43:30 UTC626OUTGET /favicon.ico HTTP/1.1
              Host: storage.ml-cachehost.net
              Connection: keep-alive
              sec-ch-ua-platform: "Windows"
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://storage.ml-cachehost.net/lib/config-a.js
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-11 22:43:31 UTC989INHTTP/1.1 403 Forbidden
              Date: Fri, 11 Apr 2025 22:43:31 GMT
              Content-Type: application/xml; charset=UTF-8
              Content-Length: 111
              Connection: close
              X-GUploader-UploadID: AKDAyIuTX48-CTrr43lK42Ma0FxhGV7yANBC6HZxlzN7M7m_DShX8VrrLdAGynAJBe_A0MwN4OiubWo
              Expires: Fri, 11 Apr 2025 22:43:31 GMT
              Cache-Control: private, max-age=0
              CF-Cache-Status: BYPASS
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 92ee00d7b9aabd52-ATL
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=108246&min_rtt=108232&rtt_var=22852&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2838&recv_bytes=1198&delivery_rate=37291&cwnd=252&unsent_bytes=0&cid=83c723110f70fe15&ts=334&x=0"
              2025-04-11 22:43:31 UTC111INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 27 31 2e 30 27 20 65 6e 63 6f 64 69 6e 67 3d 27 55 54 46 2d 38 27 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 64 65 6e 69 65 64 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
              Data Ascii: <?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44972935.190.80.14432592C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-11 22:43:31 UTC565OUTOPTIONS /report/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://storage.ml-cachehost.net
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-11 22:43:31 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: POST, OPTIONS
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Fri, 11 Apr 2025 22:43:31 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44973035.190.80.14432592C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-11 22:43:32 UTC540OUTPOST /report/v4?s=XWxR37ldYWc6hX%2FIhPsGeiVSewSI0GocgWdu6jcooD9goEpogcIffiiSMnxNo5ievVJuk2Yfjb9dDD1N%2FfxFSSRplpyJYoT%2FqeXRCyr64Dnv0iZl4UPEBqTZshMawot0hFAW%2BXkXz8PRr1o%3D HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 453
              Content-Type: application/reports+json
              Origin: https://storage.ml-cachehost.net
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-11 22:43:32 UTC453OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 35 35 38 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 73 74 6f 72 61 67 65 2e 6d 6c 2d 63 61 63 68 65 68 6f 73 74 2e 6e 65 74 2f 6c 69 62 2f 63 6f 6e 66 69 67 2d 61 2e 6a 73 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 31 37 2e 31 31 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22
              Data Ascii: [{"age":0,"body":{"elapsed_time":558,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://storage.ml-cachehost.net/lib/config-a.js","sampling_fraction":1.0,"server_ip":"104.21.17.111","status_code":403,"type":"http.error"},"type"
              2025-04-11 22:43:32 UTC214INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-allow-origin: *
              vary: Origin
              date: Fri, 11 Apr 2025 22:43:32 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              020406080s020406080100

              Click to jump to process

              020406080s0.0050100MB

              Click to jump to process

              Target ID:0
              Start time:18:43:21
              Start date:11/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:1
              Start time:18:43:22
              Start date:11/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2016,i,10697822270708087813,16803609729803447203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2120 /prefetch:3
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:18:43:28
              Start date:11/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://storage.ml-cachehost.net/lib/config-a.js"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly