Edit tour

Windows Analysis Report
https://ragnar.tmadev.co.uk/.well-known/

Overview

General Information

Sample URL:https://ragnar.tmadev.co.uk/.well-known/
Analysis ID:1671086
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected suspicious crossdomain redirect

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4872 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3880 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2104,i,10223845786539962517,12020072481281899686,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2132 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ragnar.tmadev.co.uk/.well-known/" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://logistikinfozentrum-gls.online/favicon.icoAvira URL Cloud: Label: malware
Source: https://logistikinfozentrum-gls.online/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.6:49695 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.55.128.254:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.55.128.254:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 186.2.171.5:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: ragnar.tmadev.co.uk to https://logistikinfozentrum-gls.online
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /.well-known/ HTTP/1.1Host: ragnar.tmadev.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: logistikinfozentrum-gls.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: logistikinfozentrum-gls.onlineConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://logistikinfozentrum-gls.online/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __ddg8_=AR43cFQiC6tBYYoz; __ddg10_=1745330362; __ddg9_=173.244.56.186; __ddg1_=bVE6AIHyT8bfajHrYTLy
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: ragnar.tmadev.co.uk
Source: global trafficDNS traffic detected: DNS query: logistikinfozentrum-gls.online
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: ddos-guardConnection: closeSet-Cookie: __ddg8_=AR43cFQiC6tBYYoz; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMTSet-Cookie: __ddg10_=1745330362; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMTSet-Cookie: __ddg9_=173.244.56.186; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMTSet-Cookie: __ddg1_=bVE6AIHyT8bfajHrYTLy; Domain=.logistikinfozentrum-gls.online; HttpOnly; Path=/; Expires=Wed, 22-Apr-2026 13:59:22 GMTDate: Tue, 22 Apr 2025 13:59:22 GMTContent-Length: 318Content-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: ddos-guardConnection: closeSet-Cookie: __ddg8_=xQv5hAgS9nbQ103d; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMTSet-Cookie: __ddg10_=1745330363; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMTSet-Cookie: __ddg9_=173.244.56.186; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMTDate: Tue, 22 Apr 2025 13:59:23 GMTContent-Length: 315Content-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.6:49695 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.55.128.254:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.55.128.254:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknownHTTPS traffic detected: 186.2.171.5:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: classification engineClassification label: mal48.win@24/4@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2104,i,10223845786539962517,12020072481281899686,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2132 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ragnar.tmadev.co.uk/.well-known/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2104,i,10223845786539962517,12020072481281899686,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2132 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1671086 URL: https://ragnar.tmadev.co.uk... Startdate: 22/04/2025 Architecture: WINDOWS Score: 48 22 Antivirus detection for URL or domain 2->22 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.6, 138, 443, 49681 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 www.google.com 142.250.69.4, 443, 49695, 49710 GOOGLEUS United States 11->16 18 logistikinfozentrum-gls.online 186.2.171.5, 443, 49703, 49704 DDOS-GUARDCORPBZ Belize 11->18 20 ragnar.tmadev.co.uk 162.55.128.254, 443, 49698, 49699 ACPCA United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://ragnar.tmadev.co.uk/.well-known/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://logistikinfozentrum-gls.online/favicon.ico100%Avira URL Cloudmalware

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.69.4
truefalse
    high
    ragnar.tmadev.co.uk
    162.55.128.254
    truefalse
      unknown
      logistikinfozentrum-gls.online
      186.2.171.5
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://logistikinfozentrum-gls.online/favicon.icofalse
        • Avira URL Cloud: malware
        unknown
        https://logistikinfozentrum-gls.online/false
          unknown
          https://ragnar.tmadev.co.uk/.well-known/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.69.4
            www.google.comUnited States
            15169GOOGLEUSfalse
            162.55.128.254
            ragnar.tmadev.co.ukUnited States
            35893ACPCAfalse
            186.2.171.5
            logistikinfozentrum-gls.onlineBelize
            262254DDOS-GUARDCORPBZfalse
            IP
            192.168.2.6
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1671086
            Start date and time:2025-04-22 15:58:07 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 5s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://ragnar.tmadev.co.uk/.well-known/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:14
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@24/4@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.68.238, 142.250.68.227, 142.251.2.84, 142.250.69.14, 23.220.73.19, 192.178.49.195, 142.250.69.3, 184.29.183.29, 4.175.87.197
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://ragnar.tmadev.co.uk/.well-known/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):318
            Entropy (8bit):5.067491213927104
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwIgsozEr6VyF02xxdGzsQWrbEHcLgWugszvjsKtgsg93wzRbKqD:J0+oxBgsozR4F0+dgsQoIfWugszvjsKn
            MD5:FA172C77ABD7B03605D83CD1AE373657
            SHA1:9785FB3254695C25C621EB4CD81CF7A2A3C8258F
            SHA-256:B0C7E6712ECBF97A1E3A14F19E3AED5DBD6553F21A2852565BFC5518925713DB
            SHA-512:0E717CAA53962B18936301F4BAD2B5F818D74628B09399ADA500571FF9A7134017A1061DBE074C14AA2FCE728EE56A2D76422665F98C8A25FE7B70659CC75E45
            Malicious:false
            Reputation:low
            URL:https://logistikinfozentrum-gls.online/
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access this resource.</p>.<p>Additionally, a 403 Forbidden.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):315
            Entropy (8bit):5.0572271090563765
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
            MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
            SHA1:A82190FC530C265AA40A045C21770D967F4767B8
            SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
            SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
            Malicious:false
            Reputation:low
            URL:https://logistikinfozentrum-gls.online/favicon.ico
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 67
            • 443 (HTTPS)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 15:58:59.570014000 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:58:59.882246971 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:00.491667032 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:01.694943905 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:04.101089001 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:08.318600893 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:08.694678068 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:08.913444042 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:09.397785902 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:10.601027966 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:13.088937044 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:17.543000937 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:17.543036938 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:17.543171883 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:17.543391943 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:17.543406963 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:17.861464024 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:17.861599922 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:17.862812042 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:17.862822056 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:17.863060951 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:17.899916887 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:17.908740997 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:18.524892092 CEST49672443192.168.2.6204.79.197.203
            Apr 22, 2025 15:59:19.569202900 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.569231987 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:19.569303989 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.569677114 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.569715023 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:19.569849968 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.572469950 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.572480917 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:19.572592020 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:19.572604895 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.141993999 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.142471075 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.143702030 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.143711090 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.143717051 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.143806934 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.143951893 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.144455910 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.144457102 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.144463062 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.144674063 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.188283920 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.191975117 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.821580887 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.821643114 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:20.824835062 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.982234955 CEST49699443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:20.982255936 CEST44349699162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:21.197952986 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.198008060 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:21.198079109 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.198263884 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.198276997 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:21.745629072 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:21.745702982 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.746792078 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.746814966 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:21.747047901 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:21.747350931 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:21.788275957 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:22.450702906 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:22.450786114 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:22.450843096 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:22.452493906 CEST49703443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:22.452507973 CEST44349703186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:22.551117897 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:22.551170111 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:22.551234007 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:22.551392078 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:22.551407099 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.094294071 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.097397089 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:23.097418070 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.097681999 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:23.097688913 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.676039934 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.676126957 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:23.676177025 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:23.680114985 CEST49704443192.168.2.6186.2.171.5
            Apr 22, 2025 15:59:23.680131912 CEST44349704186.2.171.5192.168.2.6
            Apr 22, 2025 15:59:27.508027077 CEST49678443192.168.2.620.42.65.91
            Apr 22, 2025 15:59:27.849531889 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:27.849595070 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:27.849754095 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:28.479163885 CEST49695443192.168.2.6142.250.69.4
            Apr 22, 2025 15:59:28.479199886 CEST44349695142.250.69.4192.168.2.6
            Apr 22, 2025 15:59:32.121539116 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:32.121597052 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 15:59:32.121711969 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:32.500653982 CEST49698443192.168.2.6162.55.128.254
            Apr 22, 2025 15:59:32.500684977 CEST44349698162.55.128.254192.168.2.6
            Apr 22, 2025 16:00:17.462038994 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:17.462101936 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:17.462171078 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:17.462330103 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:17.462343931 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:17.777623892 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:17.777959108 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:17.777988911 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:18.742322922 CEST443496812.23.227.215192.168.2.6
            Apr 22, 2025 16:00:18.742432117 CEST443496812.23.227.215192.168.2.6
            Apr 22, 2025 16:00:18.742638111 CEST49681443192.168.2.62.23.227.215
            Apr 22, 2025 16:00:18.742638111 CEST49681443192.168.2.62.23.227.215
            Apr 22, 2025 16:00:27.786111116 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:27.786189079 CEST44349710142.250.69.4192.168.2.6
            Apr 22, 2025 16:00:27.786365032 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:28.478626013 CEST49710443192.168.2.6142.250.69.4
            Apr 22, 2025 16:00:28.478645086 CEST44349710142.250.69.4192.168.2.6
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 15:59:13.485788107 CEST53507301.1.1.1192.168.2.6
            Apr 22, 2025 15:59:13.486788034 CEST53508631.1.1.1192.168.2.6
            Apr 22, 2025 15:59:14.484962940 CEST53584871.1.1.1192.168.2.6
            Apr 22, 2025 15:59:14.577837944 CEST53554731.1.1.1192.168.2.6
            Apr 22, 2025 15:59:17.401338100 CEST5870453192.168.2.61.1.1.1
            Apr 22, 2025 15:59:17.401338100 CEST6114153192.168.2.61.1.1.1
            Apr 22, 2025 15:59:17.541589022 CEST53587041.1.1.1192.168.2.6
            Apr 22, 2025 15:59:17.541965008 CEST53611411.1.1.1192.168.2.6
            Apr 22, 2025 15:59:18.905441046 CEST5156653192.168.2.61.1.1.1
            Apr 22, 2025 15:59:18.905791998 CEST5332553192.168.2.61.1.1.1
            Apr 22, 2025 15:59:19.555872917 CEST53533251.1.1.1192.168.2.6
            Apr 22, 2025 15:59:19.568566084 CEST53515661.1.1.1192.168.2.6
            Apr 22, 2025 15:59:20.997379065 CEST5299553192.168.2.61.1.1.1
            Apr 22, 2025 15:59:20.997637033 CEST6386253192.168.2.61.1.1.1
            Apr 22, 2025 15:59:21.184223890 CEST53638621.1.1.1192.168.2.6
            Apr 22, 2025 15:59:21.197176933 CEST53529951.1.1.1192.168.2.6
            Apr 22, 2025 15:59:31.508889914 CEST53541691.1.1.1192.168.2.6
            Apr 22, 2025 15:59:50.324287891 CEST53647311.1.1.1192.168.2.6
            Apr 22, 2025 16:00:06.233124971 CEST138138192.168.2.6192.168.2.255
            Apr 22, 2025 16:00:12.909070015 CEST53525451.1.1.1192.168.2.6
            Apr 22, 2025 16:00:13.137152910 CEST53550131.1.1.1192.168.2.6
            Apr 22, 2025 16:00:16.102293015 CEST53545421.1.1.1192.168.2.6
            TimestampSource IPDest IPChecksumCodeType
            Apr 22, 2025 15:59:14.485017061 CEST192.168.2.61.1.1.1c1fb(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 22, 2025 15:59:17.401338100 CEST192.168.2.61.1.1.10x1f0aStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 15:59:17.401338100 CEST192.168.2.61.1.1.10x890fStandard query (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 15:59:18.905441046 CEST192.168.2.61.1.1.10x847dStandard query (0)ragnar.tmadev.co.ukA (IP address)IN (0x0001)false
            Apr 22, 2025 15:59:18.905791998 CEST192.168.2.61.1.1.10xb98eStandard query (0)ragnar.tmadev.co.uk65IN (0x0001)false
            Apr 22, 2025 15:59:20.997379065 CEST192.168.2.61.1.1.10xf986Standard query (0)logistikinfozentrum-gls.onlineA (IP address)IN (0x0001)false
            Apr 22, 2025 15:59:20.997637033 CEST192.168.2.61.1.1.10x988eStandard query (0)logistikinfozentrum-gls.online65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 22, 2025 15:59:17.541589022 CEST1.1.1.1192.168.2.60x1f0aNo error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
            Apr 22, 2025 15:59:17.541965008 CEST1.1.1.1192.168.2.60x890fNo error (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 15:59:19.568566084 CEST1.1.1.1192.168.2.60x847dNo error (0)ragnar.tmadev.co.uk162.55.128.254A (IP address)IN (0x0001)false
            Apr 22, 2025 15:59:21.197176933 CEST1.1.1.1192.168.2.60xf986No error (0)logistikinfozentrum-gls.online186.2.171.5A (IP address)IN (0x0001)false
            • ragnar.tmadev.co.uk
            • logistikinfozentrum-gls.online
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.649699162.55.128.2544433880C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 13:59:20 UTC681OUTGET /.well-known/ HTTP/1.1
            Host: ragnar.tmadev.co.uk
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 13:59:20 UTC454INHTTP/1.1 302 Found
            Connection: close
            x-powered-by: PHP/8.2.14
            location: https://logistikinfozentrum-gls.online
            content-type: text/html; charset=UTF-8
            content-length: 0
            date: Tue, 22 Apr 2025 13:59:20 GMT
            cache-control: no-cache, no-store, must-revalidate, max-age=0
            alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.649703186.2.171.54433880C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 13:59:21 UTC680OUTGET / HTTP/1.1
            Host: logistikinfozentrum-gls.online
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 13:59:22 UTC675INHTTP/1.1 403 Forbidden
            Server: ddos-guard
            Connection: close
            Set-Cookie: __ddg8_=AR43cFQiC6tBYYoz; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMT
            Set-Cookie: __ddg10_=1745330362; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMT
            Set-Cookie: __ddg9_=173.244.56.186; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:22 GMT
            Set-Cookie: __ddg1_=bVE6AIHyT8bfajHrYTLy; Domain=.logistikinfozentrum-gls.online; HttpOnly; Path=/; Expires=Wed, 22-Apr-2026 13:59:22 GMT
            Date: Tue, 22 Apr 2025 13:59:22 GMT
            Content-Length: 318
            Content-Type: text/html; charset=iso-8859-1
            2025-04-22 13:59:22 UTC318INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><p>Additionally, a 403 Forbiddenerror was encountered while trying to


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.649704186.2.171.54433880C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 13:59:23 UTC732OUTGET /favicon.ico HTTP/1.1
            Host: logistikinfozentrum-gls.online
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://logistikinfozentrum-gls.online/
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            Cookie: __ddg8_=AR43cFQiC6tBYYoz; __ddg10_=1745330362; __ddg9_=173.244.56.186; __ddg1_=bVE6AIHyT8bfajHrYTLy
            2025-04-22 13:59:23 UTC536INHTTP/1.1 404 Not Found
            Server: ddos-guard
            Connection: close
            Set-Cookie: __ddg8_=xQv5hAgS9nbQ103d; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMT
            Set-Cookie: __ddg10_=1745330363; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMT
            Set-Cookie: __ddg9_=173.244.56.186; Domain=.logistikinfozentrum-gls.online; Path=/; Expires=Tue, 22-Apr-2025 14:19:23 GMT
            Date: Tue, 22 Apr 2025 13:59:23 GMT
            Content-Length: 315
            Content-Type: text/html; charset=iso-8859-1
            2025-04-22 13:59:23 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:09:59:05
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff63b000000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:09:59:11
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2104,i,10223845786539962517,12020072481281899686,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2132 /prefetch:3
            Imagebase:0x7ff63b000000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:11
            Start time:09:59:18
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ragnar.tmadev.co.uk/.well-known/"
            Imagebase:0x7ff63b000000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly