Edit tour

Windows Analysis Report
https://kajec.icu

Overview

General Information

Sample URL:https://kajec.icu
Analysis ID:1670493
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6304 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2064 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 5276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kajec.icu" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://kajec.icu/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.5:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.153.22:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.153.22:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.68.227
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: kajec.icuConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kajec.icuConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kajec.icu/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: kajec.icu
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 21 Apr 2025 17:42:12 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closeServer: cloudflareVary: accept-encodingCf-Cache-Status: DYNAMICCF-RAY: 933ead32f9a80a1a-MIAalt-svc: h3=":443"; ma=86400
Source: chromecache_41.4.drString found in binary or memory: https://fonts.gstatic.com/s/capriola/v14/wXKoE3YSppcvo1PDlk_1JeESnA.woff2)
Source: chromecache_41.4.drString found in binary or memory: https://fonts.gstatic.com/s/capriola/v14/wXKoE3YSppcvo1PDlk_7JeE.woff2)
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.5:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.153.22:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.153.22:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: classification engineClassification label: clean0.win@23/8@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Family,VirtualizationFirmwareEnabled FROM Win32_Processor
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2064 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kajec.icu"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2064 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kajec.icu"Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Windows Management Instrumentation
Path Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
System Information Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1670493 URL: https://kajec.icu Startdate: 21/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 192.168.2.5, 138, 443, 49675 unknown unknown 5->15 17 192.168.2.6 unknown unknown 5->17 10 chrome.exe 5->10         started        13 chrome.exe 5->13         started        process4 dnsIp5 19 www.google.com 192.178.49.164, 443, 49699, 49715 GOOGLEUS United States 10->19 21 kajec.icu 172.67.153.22, 443, 49701, 49702 CLOUDFLARENETUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://kajec.icu0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://kajec.icu/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
192.178.49.164
truefalse
    high
    kajec.icu
    172.67.153.22
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://c.pki.goog/r/r4.crlfalse
        high
        https://kajec.icu/false
          unknown
          https://kajec.icu/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          172.67.153.22
          kajec.icuUnited States
          13335CLOUDFLARENETUSfalse
          192.178.49.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.6
          192.168.2.5
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1670493
          Start date and time:2025-04-21 19:41:10 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 47s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://kajec.icu
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:15
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@23/8@4/4
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 192.178.49.206, 192.178.49.163, 192.178.49.174, 142.250.141.84, 199.232.214.172, 142.250.69.10, 142.250.69.3, 184.29.183.29, 172.202.163.200
          • Excluded domains from analysis (whitelisted): fonts.googleapis.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: https://kajec.icu
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):271
          Entropy (8bit):5.234124565998564
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoIR4wq8cXaoD:J0+oxBeRmR9etdzRxGezHDq8ma+
          MD5:8A300C41C0F21B9F81FCD635D24C54A5
          SHA1:886938622D2F612B8174EA5CCF9C7A59B37797A5
          SHA-256:EB26094EDEC47737B5522DD812AD9DD0AD30B371A5BCD978D359DCFE0A889588
          SHA-512:851AC640FDEBCA0E1C750DD05486E3CA234249C78B2E484D61F6B1B3B6F10F94711FC9877E6764AD470EA3F0F4D97003FA56135BD6F6B11854E3B677CF42BDC4
          Malicious:false
          Reputation:low
          URL:https://kajec.icu/favicon.ico
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<hr>.<address>Apache/2.4.58 (Ubuntu) Server at kajec.icu Port 80</address>.</body></html>.
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Web Open Font Format (Version 2), TrueType, length 20876, version 1.0
          Category:downloaded
          Size (bytes):20876
          Entropy (8bit):7.990241189634868
          Encrypted:true
          SSDEEP:384:lShzzaflLqW7fQKRsfhpgd29x6DUseewElvH/m6GrjEJNR1DRqEI6:4lzafpqW7fQxzHx0U4H+//ErR5oEI6
          MD5:DE58282A1CE2C94C8D03A2FEF04BADE2
          SHA1:9C8BAC0B423F92B154D3D8F1CD40222654EE160E
          SHA-256:3A699A96B93301126FA93A9E52306A65149C4BB3B686EDA38DA3895941EDAA4F
          SHA-512:8C598BA8D6165C63835E01EC96E455055D4C3FBB0656CC1D2C8B1EEEF3D2DFF6208D87E7AB957871AF80297E4CAB2F658AF983C9A0D94B179C66380E41A178DF
          Malicious:false
          Reputation:low
          URL:https://fonts.gstatic.com/s/capriola/v14/wXKoE3YSppcvo1PDlk_7JeE.woff2
          Preview:wOF2......Q...........Q1...........................`..H.0..I.....`..m..4..6.$..d. .....i.`..%c[F.n.(i..S...A..~`G.r;.B.....o..!...U'E..Yeu.......!:i.`h....$D../k....F..6zMA.%._x.R..]..DW.w......'G...".$*.....+..qA0.!m."!.K..p...K.G....?.....V.}TU.==.H=;.8..w..F........tY.a....6cf.........D.(...baT...j.....]..E....w.s..R.....II.>...y.n~.....2.B..xc.i`H...u=...z.#^[.f..}K<.8..(G.Y.N...-zBR.'..&..%.....kl...V...vh.f.fo..@,I..*.Y.,.S.$....?..t.W@h.q...G.n..5.Mr.........x...WY..._...{$...Q`...'./zm.H(..Qx...i.....\..h7@.P6W...ZSW...Gv.>.....n.&.b1....+..j...gI.`7M....L.....y.%.YJobR.[..%9....b.p.....(..H,p)...X.\......(..<K.[.9.....m.I.........O...7@.31.......".....@..".......Y.#k.\U...5.N....*.Y{.8.:[.j.w*....|gu.....kU ........]........0N. .~{j...F.}.2@.{.._.T.OON..A.....v.?"<..B..t.u...5 ..7.8..@......#J9q.&.N._..P... .x.o...|.$.n...}..k?.^.O.H.l.q...>Q.5u.....N_..t.6.......7k.....v....mZ#=...,.@...G.5._......./.,...^...Vk..IX.
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):2249
          Entropy (8bit):5.260918880676623
          Encrypted:false
          SSDEEP:48:t/pzRgdYJP2Om7yfw1KrXVEYPbqqnadwVq:jedYJujSw1QLvaz
          MD5:1BA7A30A07230726B3CECBEDE78B5476
          SHA1:7229FB742242DB43D708AE9E9205581D9289C3B9
          SHA-256:228A524C66A99BFF27A022E4ADA9C45CA41AFCDFCF31B87BE4EEC8FD8685F42F
          SHA-512:32560E13A47BF409A5ECE538AF1B52585EB6A5682B860381D72B855952E6F867C0F2476DC0EC631ED0CE05FDE332D942CF7A08A73F840A9A66F5532203349E7E
          Malicious:false
          Reputation:low
          URL:https://kajec.icu/
          Preview:<!DOCTYPE HTML>..<html>..<head>..<title>404</title>..<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>..<link href='//fonts.googleapis.com/css?family=Capriola' rel='stylesheet' type='text/css'>..<style type="text/css">..body{...font-family: 'Capriola', sans-serif;..}..body{...background:#DAD6CC;..}....wrap{...margin:0 auto;...width:1000px;..}...logo h1{...font-size:200px;...color:#FF7A00;...text-align:center;...margin-bottom:1px;...text-shadow:4px 4px 1px white;..}....logo p{...color:#B1A18D;...font-size:20px;...margin-top:1px;...text-align:center;..}....logo p span{...color:lightgreen;..}....sub a{...color:#ff7a00;...text-decoration:none;...padding:5px;...font-size:13px;...font-family: arial, serif;...font-weight:bold;..}....footer{...color:white;...position:absolute;...right:10px;...bottom:10px;..}....footer a{...color:#ff7a00;..}....@media (max-width:1024px) {....logo h1 {....font-size: 170px;....margin-top: 140px ...}....wrap {....width:100%;...}....footer {..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text
          Category:downloaded
          Size (bytes):801
          Entropy (8bit):5.296566285075733
          Encrypted:false
          SSDEEP:12:UNmFaO6ZRoT6perKa+zb77kYYtJcb65wCgDrqAFaO6ZRoT6pYhKayVVey90HcGuM:3aOYspxtJc+u/raOYswwy96cGSSf7
          MD5:254FA233C2FCA8D5F8A867061A7B806C
          SHA1:1BF4F2D344E415C1F2A0E4C130889EB8DE236840
          SHA-256:0FB42055E11A4F1279019E52FB475863D4D4591B156C00AE893815B7E088CB5A
          SHA-512:DDFA2129A67F33C039265216BFEBAE87F3D541A114F9962FD2FDF46660AD4029CFB450B64C8E4690A67792483FF932BD36E1D30D2B23A49F7E8EA6CAD9B35559
          Malicious:false
          Reputation:low
          URL:https://fonts.googleapis.com/css?family=Capriola
          Preview:/* latin-ext */.@font-face {. font-family: 'Capriola';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/capriola/v14/wXKoE3YSppcvo1PDlk_1JeESnA.woff2) format('woff2');. unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Capriola';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/capriola/v14/wXKoE3YSppcvo1PDlk_7JeE.woff2) format('woff2');. unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;.}.
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 44
          • 443 (HTTPS)
          • 80 (HTTP)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Apr 21, 2025 19:41:52.918874025 CEST49672443192.168.2.5204.79.197.203
          Apr 21, 2025 19:41:54.121999025 CEST49672443192.168.2.5204.79.197.203
          Apr 21, 2025 19:41:56.528239965 CEST49672443192.168.2.5204.79.197.203
          Apr 21, 2025 19:42:00.555964947 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:00.856374979 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:01.373806000 CEST49672443192.168.2.5204.79.197.203
          Apr 21, 2025 19:42:01.465744019 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:02.731359959 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:05.137409925 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:05.178462982 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:42:05.326141119 CEST8049697142.250.68.227192.168.2.5
          Apr 21, 2025 19:42:05.326236963 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:42:05.326396942 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:42:05.474019051 CEST8049697142.250.68.227192.168.2.5
          Apr 21, 2025 19:42:05.474706888 CEST8049697142.250.68.227192.168.2.5
          Apr 21, 2025 19:42:05.518282890 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:42:08.265832901 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:08.265866995 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:08.266037941 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:08.266166925 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:08.266180038 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:08.588176012 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:08.588289976 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:08.589590073 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:08.589610100 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:08.589894056 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:08.638175964 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:09.459835052 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.459893942 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.460022926 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.460396051 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.460427046 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.460587025 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.460599899 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.460617065 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.460786104 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.460799932 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.823405981 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.823509932 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.824839115 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.824862957 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.825109959 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.825726986 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.868274927 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.884877920 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.884946108 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.885340929 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.885348082 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.885548115 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:09.929795027 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:09.949771881 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:42:10.623255968 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:10.623313904 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:10.623399019 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:10.623521090 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:10.624535084 CEST49701443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:10.624553919 CEST44349701172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:10.983104944 CEST49672443192.168.2.5204.79.197.203
          Apr 21, 2025 19:42:11.575666904 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:11.620275974 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:12.153162003 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:12.153301954 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:12.153348923 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:12.155780077 CEST49702443192.168.2.5172.67.153.22
          Apr 21, 2025 19:42:12.155797005 CEST44349702172.67.153.22192.168.2.5
          Apr 21, 2025 19:42:17.177856922 CEST49675443192.168.2.52.23.227.208
          Apr 21, 2025 19:42:17.177886963 CEST443496752.23.227.208192.168.2.5
          Apr 21, 2025 19:42:17.549974918 CEST49710443192.168.2.5150.171.27.254
          Apr 21, 2025 19:42:17.550009966 CEST44349710150.171.27.254192.168.2.5
          Apr 21, 2025 19:42:17.550107002 CEST49710443192.168.2.5150.171.27.254
          Apr 21, 2025 19:42:17.550951958 CEST49710443192.168.2.5150.171.27.254
          Apr 21, 2025 19:42:17.550965071 CEST44349710150.171.27.254192.168.2.5
          Apr 21, 2025 19:42:17.984761953 CEST44349710150.171.27.254192.168.2.5
          Apr 21, 2025 19:42:17.984831095 CEST49710443192.168.2.5150.171.27.254
          Apr 21, 2025 19:42:18.586381912 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:18.586453915 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:18.586582899 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:19.545780897 CEST49699443192.168.2.5192.178.49.164
          Apr 21, 2025 19:42:19.545802116 CEST44349699192.178.49.164192.168.2.5
          Apr 21, 2025 19:42:19.559294939 CEST49676443192.168.2.520.189.173.14
          Apr 21, 2025 19:43:05.637742043 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:43:05.785510063 CEST8049697142.250.68.227192.168.2.5
          Apr 21, 2025 19:43:05.785612106 CEST4969780192.168.2.5142.250.68.227
          Apr 21, 2025 19:43:08.185709000 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:08.185745955 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:08.185815096 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:08.186028004 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:08.186038017 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:08.499835014 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:08.500294924 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:08.500309944 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:18.510253906 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:18.510309935 CEST44349715192.178.49.164192.168.2.5
          Apr 21, 2025 19:43:18.510349989 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:18.552705050 CEST49715443192.168.2.5192.178.49.164
          Apr 21, 2025 19:43:18.552728891 CEST44349715192.178.49.164192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Apr 21, 2025 19:42:03.970273972 CEST53505101.1.1.1192.168.2.5
          Apr 21, 2025 19:42:03.972007990 CEST53625711.1.1.1192.168.2.5
          Apr 21, 2025 19:42:04.851484060 CEST53513881.1.1.1192.168.2.5
          Apr 21, 2025 19:42:05.132817030 CEST53600231.1.1.1192.168.2.5
          Apr 21, 2025 19:42:08.124011040 CEST6408053192.168.2.51.1.1.1
          Apr 21, 2025 19:42:08.124250889 CEST6396953192.168.2.51.1.1.1
          Apr 21, 2025 19:42:08.264203072 CEST53640801.1.1.1192.168.2.5
          Apr 21, 2025 19:42:08.264659882 CEST53639691.1.1.1192.168.2.5
          Apr 21, 2025 19:42:09.285056114 CEST5445553192.168.2.51.1.1.1
          Apr 21, 2025 19:42:09.285794973 CEST6109353192.168.2.51.1.1.1
          Apr 21, 2025 19:42:09.457485914 CEST53544551.1.1.1192.168.2.5
          Apr 21, 2025 19:42:09.459031105 CEST53610931.1.1.1192.168.2.5
          Apr 21, 2025 19:42:10.784046888 CEST53529201.1.1.1192.168.2.5
          Apr 21, 2025 19:42:22.160053015 CEST53544581.1.1.1192.168.2.5
          Apr 21, 2025 19:42:40.935403109 CEST53581461.1.1.1192.168.2.5
          Apr 21, 2025 19:43:03.421060085 CEST53563101.1.1.1192.168.2.5
          Apr 21, 2025 19:43:03.533793926 CEST53589691.1.1.1192.168.2.5
          Apr 21, 2025 19:43:03.644805908 CEST138138192.168.2.5192.168.2.255
          Apr 21, 2025 19:43:06.779014111 CEST53622711.1.1.1192.168.2.5
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 21, 2025 19:42:08.124011040 CEST192.168.2.51.1.1.10xbc5dStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 21, 2025 19:42:08.124250889 CEST192.168.2.51.1.1.10x3143Standard query (0)www.google.com65IN (0x0001)false
          Apr 21, 2025 19:42:09.285056114 CEST192.168.2.51.1.1.10x7882Standard query (0)kajec.icuA (IP address)IN (0x0001)false
          Apr 21, 2025 19:42:09.285794973 CEST192.168.2.51.1.1.10x129cStandard query (0)kajec.icu65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 21, 2025 19:42:08.264203072 CEST1.1.1.1192.168.2.50xbc5dNo error (0)www.google.com192.178.49.164A (IP address)IN (0x0001)false
          Apr 21, 2025 19:42:08.264659882 CEST1.1.1.1192.168.2.50x3143No error (0)www.google.com65IN (0x0001)false
          Apr 21, 2025 19:42:09.457485914 CEST1.1.1.1192.168.2.50x7882No error (0)kajec.icu172.67.153.22A (IP address)IN (0x0001)false
          Apr 21, 2025 19:42:09.457485914 CEST1.1.1.1192.168.2.50x7882No error (0)kajec.icu104.21.32.171A (IP address)IN (0x0001)false
          Apr 21, 2025 19:42:09.459031105 CEST1.1.1.1192.168.2.50x129cNo error (0)kajec.icu65IN (0x0001)false
          • kajec.icu
          • c.pki.goog
          Session IDSource IPSource PortDestination IPDestination Port
          0192.168.2.549697142.250.68.22780
          TimestampBytes transferredDirectionData
          Apr 21, 2025 19:42:05.326396942 CEST200OUTGET /r/r4.crl HTTP/1.1
          Cache-Control: max-age = 3000
          Connection: Keep-Alive
          Accept: */*
          If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
          User-Agent: Microsoft-CryptoAPI/10.0
          Host: c.pki.goog
          Apr 21, 2025 19:42:05.474706888 CEST1243INHTTP/1.1 200 OK
          Accept-Ranges: bytes
          Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
          Cross-Origin-Resource-Policy: cross-origin
          Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
          Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
          Content-Length: 530
          X-Content-Type-Options: nosniff
          Server: sffe
          X-XSS-Protection: 0
          Date: Mon, 21 Apr 2025 17:18:04 GMT
          Expires: Mon, 21 Apr 2025 18:08:04 GMT
          Cache-Control: public, max-age=3000
          Age: 1441
          Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
          Content-Type: application/pkix-crl
          Vary: Accept-Encoding
          Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
          Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.549701172.67.153.224436816C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-04-21 17:42:09 UTC659OUTGET / HTTP/1.1
          Host: kajec.icu
          Connection: keep-alive
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-04-21 17:42:10 UTC352INHTTP/1.1 200 OK
          Date: Mon, 21 Apr 2025 17:42:10 GMT
          Content-Type: text/html; charset=UTF-8
          Transfer-Encoding: chunked
          Connection: close
          Server: cloudflare
          Last-Modified: Fri, 21 Mar 2025 14:48:14 GMT
          Etag: W/"8c9-630db5817d269-gzip"
          Cf-Cache-Status: DYNAMIC
          Vary: Accept-Encoding
          CF-RAY: 933ead293d478e66-PDX
          alt-svc: h3=":443"; ma=86400
          2025-04-21 17:42:10 UTC1017INData Raw: 38 63 39 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 2f 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 27 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 43 61 70 72 69 6f 6c 61 27 20 72 65 6c 3d 27 73 74 79 6c 65 73 68 65 65 74 27 20 74 79 70 65 3d 27 74 65 78 74 2f 63 73 73 27 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 62 6f 64 79 7b 0d 0a 09 66 6f 6e
          Data Ascii: 8c9<!DOCTYPE HTML><html><head><title>404</title><meta http-equiv="Content-Type" content="text/html; charset=utf-8"/><link href='//fonts.googleapis.com/css?family=Capriola' rel='stylesheet' type='text/css'><style type="text/css">body{fon
          2025-04-21 17:42:10 UTC1239INData Raw: 31 34 70 78 3b 0d 0a 09 09 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 33 30 70 78 3b 0d 0a 09 7d 0d 0a 7d 0d 0a 0d 0a 40 6d 65 64 69 61 20 28 6d 61 78 2d 77 69 64 74 68 3a 20 39 39 31 70 78 29 20 7b 0d 0a 09 2e 6c 6f 67 6f 20 68 31 20 7b 0d 0a 09 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 35 30 70 78 3b 0d 0a 09 7d 0d 0a 7d 0d 0a 09 0d 0a 40 6d 65 64 69 61 20 28 6d 61 78 2d 77 69 64 74 68 3a 20 37 36 38 70 78 29 20 7b 0d 0a 09 62 6f 64 79 20 7b 0d 0a 09 09 64 69 73 70 6c 61 79 3a 2d 77 65 62 6b 69 74 2d 66 6c 65 78 3b 0d 0a 09 09 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 0d 0a 09 09 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 0d 0a 09 09 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 0d 0a 09 09 68 65 69 67 68 74 3a 20 31 30
          Data Ascii: 14px;line-height: 30px;}}@media (max-width: 991px) {.logo h1 {font-size: 150px;}}@media (max-width: 768px) {body {display:-webkit-flex;display:flex;align-items: center;justify-content: center;height: 10
          2025-04-21 17:42:10 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.549702172.67.153.224436816C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-04-21 17:42:11 UTC581OUTGET /favicon.ico HTTP/1.1
          Host: kajec.icu
          Connection: keep-alive
          sec-ch-ua-platform: "Windows"
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://kajec.icu/
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-04-21 17:42:12 UTC284INHTTP/1.1 404 Not Found
          Date: Mon, 21 Apr 2025 17:42:12 GMT
          Content-Type: text/html; charset=iso-8859-1
          Transfer-Encoding: chunked
          Connection: close
          Server: cloudflare
          Vary: accept-encoding
          Cf-Cache-Status: DYNAMIC
          CF-RAY: 933ead32f9a80a1a-MIA
          alt-svc: h3=":443"; ma=86400
          2025-04-21 17:42:12 UTC278INData Raw: 31 30 66 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 6b 61 6a 65 63 2e 69 63 75 20 50 6f 72 74 20 38 30 3c 2f 61 64 64
          Data Ascii: 10f<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.58 (Ubuntu) Server at kajec.icu Port 80</add
          2025-04-21 17:42:12 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          020406080s020406080100

          Click to jump to process

          020406080s0.0050100MB

          Click to jump to process

          Target ID:1
          Start time:13:41:56
          Start date:21/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff768d10000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:4
          Start time:13:42:01
          Start date:21/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2064 /prefetch:3
          Imagebase:0x7ff768d10000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:8
          Start time:13:42:04
          Start date:21/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2032,i,876960488278925228,1103831399019611287,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5000 /prefetch:8
          Imagebase:0x7ff768d10000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:11
          Start time:13:42:07
          Start date:21/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kajec.icu"
          Imagebase:0x7ff768d10000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly