Edit tour

Windows Analysis Report
http://d1lkfzu2puirk6.cloudfront.net/api/poddbs

Overview

General Information

Sample URL:http://d1lkfzu2puirk6.cloudfront.net/api/poddbs
Analysis ID:1672182
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3000 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,12402582583480906827,17708485085395737827,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6772 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1lkfzu2puirk6.cloudfront.net/api/poddbs" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://d1lkfzu2puirk6.cloudfront.net/api/poddbsHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.168.153.158:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.168.153.23:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 131.253.33.254:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /api/poddbs HTTP/1.1Host: d1lkfzu2puirk6.cloudfront.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: d1lkfzu2puirk6.cloudfront.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://d1lkfzu2puirk6.cloudfront.net/api/poddbsAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: d1lkfzu2puirk6.cloudfront.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: d1lkfzu2puirk6.cloudfront.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeDate: Wed, 23 Apr 2025 14:59:35 GMTServer: nginx/1.22.1P3P: CP="NID DSP ALL COR"X-Cache: Error from cloudfrontVia: 1.1 87de21072955226db6ff28a965e6e400.cloudfront.net (CloudFront)X-Amz-Cf-Pop: LAX54-P3X-Amz-Cf-Id: wrwAvcT5kOiuSm3PJsJcwlipp3r_gx4sTH5JvEXG7QGRtE9EaFhkLA==
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.168.153.158:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.168.153.23:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 131.253.33.254:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: classification engineClassification label: clean0.win@22/5@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,12402582583480906827,17708485085395737827,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1lkfzu2puirk6.cloudfront.net/api/poddbs"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,12402582583480906827,17708485085395737827,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1672182 URL: http://d1lkfzu2puirk6.cloud... Startdate: 23/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49292 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 192.178.49.196, 443, 49727, 49741 GOOGLEUS United States 10->15 17 3.168.153.158, 443, 49730, 49732 AMAZON-02US United States 10->17 19 2 other IPs or domains 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://d1lkfzu2puirk6.cloudfront.net/api/poddbs0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://d1lkfzu2puirk6.cloudfront.net/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
d1lkfzu2puirk6.cloudfront.net
3.168.153.216
truefalse
    high
    www.google.com
    192.178.49.196
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://d1lkfzu2puirk6.cloudfront.net/api/poddbsfalse
        unknown
        https://d1lkfzu2puirk6.cloudfront.net/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        3.168.153.158
        unknownUnited States
        16509AMAZON-02USfalse
        192.178.49.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        3.168.153.216
        d1lkfzu2puirk6.cloudfront.netUnited States
        16509AMAZON-02USfalse
        3.168.153.23
        unknownUnited States
        16509AMAZON-02USfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1672182
        Start date and time:2025-04-23 16:58:30 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 2s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://d1lkfzu2puirk6.cloudfront.net/api/poddbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:20
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@22/5@8/5
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 192.178.49.195, 142.250.101.84, 192.178.49.174, 142.250.69.14, 23.220.73.6, 184.29.183.29, 172.202.163.200
        • Excluded domains from analysis (whitelisted): a-ring-fallback.msedge.net, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, ctldl.windowsupdate.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: http://d1lkfzu2puirk6.cloudfront.net/api/poddbs
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
        Category:downloaded
        Size (bytes):198
        Entropy (8bit):1.23143406345007
        Encrypted:false
        SSDEEP:3:2oXllvlNl/FXltlBe/h/555555555555555n:2Y1UJ555555555555555n
        MD5:C6ACEDAFF906029FC5455D9EC52C7F42
        SHA1:92CBD806CA421AA2C9FF5E1FF76BBC20913A2F81
        SHA-256:9DEB629637088856FE61DC868BF40A7D21ED942E4117659F3D6C3408F59B906B
        SHA-512:7A8D002CA6B607E38860AD4485493E109CB7D3BEF241B0E5BF2A65C2E316E6185DED8EC74E3FCBD78745AB302C6D876657ABC178EE028D1B8B9A5572F429D972
        Malicious:false
        Reputation:low
        URL:https://d1lkfzu2puirk6.cloudfront.net/favicon.ico
        Preview:......................(....... .......................................................................................................................................................................
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):1805
        Entropy (8bit):4.922872471495283
        Encrypted:false
        SSDEEP:48:438QSnSedY/T3pxVJlE38lqy8JhwH6h/lnIiPlpjAnB:s8fdYljJlE38lqy8JyH6giPfAnB
        MD5:E367A39DC097FBADD1361C7B5495C739
        SHA1:C1C5B96FF6C42561484112659B5A42C4BEA6A24F
        SHA-256:1F802157F642E52164EE02CC68D0B21C7582F82271E8C2DF57D1A9A28A39076F
        SHA-512:0C74AC9EC70CA1EEC236475CEC256E87A598C88666578CBF40EA9AE686BA0D6FE7BC7634C61AA524589012CAD64CE09B0EF768CA4F770325BD06DC213CAA3066
        Malicious:false
        Reputation:low
        URL:https://d1lkfzu2puirk6.cloudfront.net/api/poddbs
        Preview:.<!DOCTYPE html>.<html>.<head>. <title>The resource cannot be found.</title>. <meta name="viewport" content="width=device-width" />. <style>. body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}. p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}. b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}. H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }. H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }. pre {font-family:"Consolas","Lucida Console",Monospace;font-size:11pt;margin:0;padding:0.5em;line-height:14pt}. .marker {font-weight: bold; color: black;text-decoration: none;}. .version {color: gray;}. .error {margin-bottom: 10px;}. .expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }. @media screen and (max-width: 639px) {. pre { width: 4
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:MS Windows icon resource - 1 icon, 16x16, 2 colors
        Category:dropped
        Size (bytes):198
        Entropy (8bit):1.23143406345007
        Encrypted:false
        SSDEEP:3:2oXllvlNl/FXltlBe/h/555555555555555n:2Y1UJ555555555555555n
        MD5:C6ACEDAFF906029FC5455D9EC52C7F42
        SHA1:92CBD806CA421AA2C9FF5E1FF76BBC20913A2F81
        SHA-256:9DEB629637088856FE61DC868BF40A7D21ED942E4117659F3D6C3408F59B906B
        SHA-512:7A8D002CA6B607E38860AD4485493E109CB7D3BEF241B0E5BF2A65C2E316E6185DED8EC74E3FCBD78745AB302C6D876657ABC178EE028D1B8B9A5572F429D972
        Malicious:false
        Reputation:low
        Preview:......................(....... .......................................................................................................................................................................
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 61
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 23, 2025 16:59:21.311882973 CEST4968180192.168.2.42.17.190.73
        Apr 23, 2025 16:59:28.958380938 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:29.273367882 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:30.012365103 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:31.076607943 CEST4968180192.168.2.42.17.190.73
        Apr 23, 2025 16:59:31.264127970 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:33.670932055 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:34.381654978 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:34.381699085 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:34.381777048 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:34.381936073 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:34.381952047 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:34.701937914 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:34.702013016 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:34.703741074 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:34.703752995 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:34.703964949 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:34.749056101 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:35.209485054 CEST4972880192.168.2.43.168.153.216
        Apr 23, 2025 16:59:35.209604025 CEST4972980192.168.2.43.168.153.216
        Apr 23, 2025 16:59:35.224950075 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.224977970 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.225131989 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.225231886 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.225238085 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.358241081 CEST80497283.168.153.216192.168.2.4
        Apr 23, 2025 16:59:35.358262062 CEST80497293.168.153.216192.168.2.4
        Apr 23, 2025 16:59:35.358407021 CEST4972880192.168.2.43.168.153.216
        Apr 23, 2025 16:59:35.361531019 CEST4972980192.168.2.43.168.153.216
        Apr 23, 2025 16:59:35.530517101 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.530622959 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.531742096 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.531754017 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.531955004 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.532274961 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.576275110 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.901103020 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.901125908 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.901173115 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:35.901200056 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.901375055 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:35.901422977 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.187617064 CEST49730443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.187657118 CEST443497303.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.359922886 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.359961033 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.360019922 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.360177040 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.360191107 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.661715984 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.662166119 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.662187099 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.662549973 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:36.662555933 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:36.827833891 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:37.032402039 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:37.032546043 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:37.032596111 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:37.035542011 CEST49732443192.168.2.43.168.153.158
        Apr 23, 2025 16:59:37.035559893 CEST443497323.168.153.158192.168.2.4
        Apr 23, 2025 16:59:37.139981031 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:37.208942890 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.208982944 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.209060907 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.209299088 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.209312916 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.511668921 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.511734009 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.512250900 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.512264967 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.512485027 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.512764931 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.556281090 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.749154091 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:37.881083965 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.881588936 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:37.881639957 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.882258892 CEST49734443192.168.2.43.168.153.23
        Apr 23, 2025 16:59:37.882277966 CEST443497343.168.153.23192.168.2.4
        Apr 23, 2025 16:59:38.483503103 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:38.952271938 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:40.440387964 CEST49708443192.168.2.452.113.196.254
        Apr 23, 2025 16:59:40.580276012 CEST4434970852.113.196.254192.168.2.4
        Apr 23, 2025 16:59:40.611203909 CEST49735443192.168.2.4131.253.33.254
        Apr 23, 2025 16:59:40.611244917 CEST44349735131.253.33.254192.168.2.4
        Apr 23, 2025 16:59:40.611453056 CEST49735443192.168.2.4131.253.33.254
        Apr 23, 2025 16:59:40.611892939 CEST49735443192.168.2.4131.253.33.254
        Apr 23, 2025 16:59:40.611907959 CEST44349735131.253.33.254192.168.2.4
        Apr 23, 2025 16:59:41.106271982 CEST44349735131.253.33.254192.168.2.4
        Apr 23, 2025 16:59:41.106352091 CEST49735443192.168.2.4131.253.33.254
        Apr 23, 2025 16:59:41.358341932 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:44.728082895 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:44.728141069 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:44.728395939 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:45.160317898 CEST49727443192.168.2.4192.178.49.196
        Apr 23, 2025 16:59:45.160334110 CEST44349727192.178.49.196192.168.2.4
        Apr 23, 2025 16:59:46.173078060 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 16:59:48.100894928 CEST49671443192.168.2.4204.79.197.203
        Apr 23, 2025 16:59:55.785007954 CEST49678443192.168.2.420.189.173.27
        Apr 23, 2025 17:00:05.508969069 CEST80497283.168.153.216192.168.2.4
        Apr 23, 2025 17:00:05.509052992 CEST4972880192.168.2.43.168.153.216
        Apr 23, 2025 17:00:05.512780905 CEST80497293.168.153.216192.168.2.4
        Apr 23, 2025 17:00:05.512839079 CEST4972980192.168.2.43.168.153.216
        Apr 23, 2025 17:00:06.172296047 CEST4972880192.168.2.43.168.153.216
        Apr 23, 2025 17:00:06.172367096 CEST4972980192.168.2.43.168.153.216
        Apr 23, 2025 17:00:06.321146965 CEST80497293.168.153.216192.168.2.4
        Apr 23, 2025 17:00:06.321168900 CEST80497283.168.153.216192.168.2.4
        Apr 23, 2025 17:00:34.297816038 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:34.297882080 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:34.297979116 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:34.298142910 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:34.298161983 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:34.611377001 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:34.611764908 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:34.611809015 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:44.602626085 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:44.602677107 CEST44349741192.178.49.196192.168.2.4
        Apr 23, 2025 17:00:44.602721930 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:45.173784971 CEST49741443192.168.2.4192.178.49.196
        Apr 23, 2025 17:00:45.173816919 CEST44349741192.178.49.196192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 23, 2025 16:59:30.274226904 CEST53623741.1.1.1192.168.2.4
        Apr 23, 2025 16:59:30.275917053 CEST53526631.1.1.1192.168.2.4
        Apr 23, 2025 16:59:31.100042105 CEST53568501.1.1.1192.168.2.4
        Apr 23, 2025 16:59:31.378484964 CEST53570841.1.1.1192.168.2.4
        Apr 23, 2025 16:59:34.235397100 CEST5283653192.168.2.41.1.1.1
        Apr 23, 2025 16:59:34.235588074 CEST6340453192.168.2.41.1.1.1
        Apr 23, 2025 16:59:34.376482010 CEST53528361.1.1.1192.168.2.4
        Apr 23, 2025 16:59:34.376502037 CEST53634041.1.1.1192.168.2.4
        Apr 23, 2025 16:59:35.058979988 CEST6435953192.168.2.41.1.1.1
        Apr 23, 2025 16:59:35.059143066 CEST6164153192.168.2.41.1.1.1
        Apr 23, 2025 16:59:35.072741985 CEST4929253192.168.2.41.1.1.1
        Apr 23, 2025 16:59:35.072947025 CEST6511953192.168.2.41.1.1.1
        Apr 23, 2025 16:59:35.202111006 CEST53616411.1.1.1192.168.2.4
        Apr 23, 2025 16:59:35.208364964 CEST53643591.1.1.1192.168.2.4
        Apr 23, 2025 16:59:35.212904930 CEST53492921.1.1.1192.168.2.4
        Apr 23, 2025 16:59:35.223685026 CEST53651191.1.1.1192.168.2.4
        Apr 23, 2025 16:59:37.052498102 CEST6237353192.168.2.41.1.1.1
        Apr 23, 2025 16:59:37.052757978 CEST6401353192.168.2.41.1.1.1
        Apr 23, 2025 16:59:37.194952011 CEST53623731.1.1.1192.168.2.4
        Apr 23, 2025 16:59:37.208075047 CEST53640131.1.1.1192.168.2.4
        Apr 23, 2025 16:59:48.497946978 CEST53537241.1.1.1192.168.2.4
        Apr 23, 2025 17:00:07.427350044 CEST53593161.1.1.1192.168.2.4
        Apr 23, 2025 17:00:29.661499023 CEST53595421.1.1.1192.168.2.4
        Apr 23, 2025 17:00:30.342803955 CEST53610211.1.1.1192.168.2.4
        Apr 23, 2025 17:00:32.983901024 CEST53614831.1.1.1192.168.2.4
        Apr 23, 2025 17:00:36.395941973 CEST138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 23, 2025 16:59:34.235397100 CEST192.168.2.41.1.1.10xe58cStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:34.235588074 CEST192.168.2.41.1.1.10xab4dStandard query (0)www.google.com65IN (0x0001)false
        Apr 23, 2025 16:59:35.058979988 CEST192.168.2.41.1.1.10x7e6dStandard query (0)d1lkfzu2puirk6.cloudfront.netA (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.059143066 CEST192.168.2.41.1.1.10x1117Standard query (0)d1lkfzu2puirk6.cloudfront.net65IN (0x0001)false
        Apr 23, 2025 16:59:35.072741985 CEST192.168.2.41.1.1.10x8310Standard query (0)d1lkfzu2puirk6.cloudfront.netA (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.072947025 CEST192.168.2.41.1.1.10xee8eStandard query (0)d1lkfzu2puirk6.cloudfront.net65IN (0x0001)false
        Apr 23, 2025 16:59:37.052498102 CEST192.168.2.41.1.1.10x65baStandard query (0)d1lkfzu2puirk6.cloudfront.netA (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:37.052757978 CEST192.168.2.41.1.1.10x98dbStandard query (0)d1lkfzu2puirk6.cloudfront.net65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 23, 2025 16:59:34.376482010 CEST1.1.1.1192.168.2.40xe58cNo error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:34.376502037 CEST1.1.1.1192.168.2.40xab4dNo error (0)www.google.com65IN (0x0001)false
        Apr 23, 2025 16:59:35.208364964 CEST1.1.1.1192.168.2.40x7e6dNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.216A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.208364964 CEST1.1.1.1192.168.2.40x7e6dNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.170A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.208364964 CEST1.1.1.1192.168.2.40x7e6dNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.158A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.208364964 CEST1.1.1.1192.168.2.40x7e6dNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.23A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.212904930 CEST1.1.1.1192.168.2.40x8310No error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.158A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.212904930 CEST1.1.1.1192.168.2.40x8310No error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.170A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.212904930 CEST1.1.1.1192.168.2.40x8310No error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.216A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:35.212904930 CEST1.1.1.1192.168.2.40x8310No error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.23A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:37.194952011 CEST1.1.1.1192.168.2.40x65baNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.23A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:37.194952011 CEST1.1.1.1192.168.2.40x65baNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.170A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:37.194952011 CEST1.1.1.1192.168.2.40x65baNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.158A (IP address)IN (0x0001)false
        Apr 23, 2025 16:59:37.194952011 CEST1.1.1.1192.168.2.40x65baNo error (0)d1lkfzu2puirk6.cloudfront.net3.168.153.216A (IP address)IN (0x0001)false
        • d1lkfzu2puirk6.cloudfront.net
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.4497303.168.153.1584433000C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-23 14:59:35 UTC689OUTGET /api/poddbs HTTP/1.1
        Host: d1lkfzu2puirk6.cloudfront.net
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-23 14:59:35 UTC397INHTTP/1.1 404 Not Found
        Content-Type: text/html; charset=utf-8
        Transfer-Encoding: chunked
        Connection: close
        Date: Wed, 23 Apr 2025 14:59:35 GMT
        Server: nginx/1.22.1
        P3P: CP="NID DSP ALL COR"
        X-Cache: Error from cloudfront
        Via: 1.1 87de21072955226db6ff28a965e6e400.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: LAX54-P3
        X-Amz-Cf-Id: wrwAvcT5kOiuSm3PJsJcwlipp3r_gx4sTH5JvEXG7QGRtE9EaFhkLA==
        2025-04-23 14:59:35 UTC1812INData Raw: 37 30 64 0d 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 68 65 20 72 65 73 6f 75 72 63 65 20 63 61 6e 6e 6f 74 20 62 65 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 20 2f 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 56 65 72 64 61 6e 61 22 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 6e 6f 72 6d 61 6c 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 2e 37 65 6d 3b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 0a 20 20 20 20 20 20 20 20 20 70 20 7b 66 6f
        Data Ascii: 70d<!DOCTYPE html><html><head> <title>The resource cannot be found.</title> <meta name="viewport" content="width=device-width" /> <style> body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} p {fo
        2025-04-23 14:59:35 UTC5INData Raw: 30 0d 0a 0d 0a
        Data Ascii: 0


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.4497323.168.153.1584433000C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-23 14:59:36 UTC631OUTGET /favicon.ico HTTP/1.1
        Host: d1lkfzu2puirk6.cloudfront.net
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://d1lkfzu2puirk6.cloudfront.net/api/poddbs
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-23 14:59:37 UTC436INHTTP/1.1 200 OK
        Content-Type: image/x-icon
        Content-Length: 198
        Connection: close
        Date: Wed, 23 Apr 2025 14:59:36 GMT
        Last-Modified: Tue, 22 Apr 2025 08:58:26 GMT
        Server: nginx/1.22.1
        Accept-Ranges: bytes
        ETag: "1dbb364b574e5c6"
        X-Cache: Miss from cloudfront
        Via: 1.1 d292d8a28a3cd03aa54182acef12b2ee.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: LAX54-P3
        X-Amz-Cf-Id: fkIt4z8Fs9xNE3YJdyQg45cfk1MQ9oOOZbAPTM6eTKy3WAEdT6rcJA==
        2025-04-23 14:59:37 UTC198INData Raw: 00 00 01 00 01 00 10 10 02 00 01 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00
        Data Ascii: (


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.4497343.168.153.234433000C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-23 14:59:37 UTC404OUTGET /favicon.ico HTTP/1.1
        Host: d1lkfzu2puirk6.cloudfront.net
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: */*
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: cors
        Sec-Fetch-Dest: empty
        Sec-Fetch-Storage-Access: active
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-23 14:59:37 UTC436INHTTP/1.1 200 OK
        Content-Type: image/x-icon
        Content-Length: 198
        Connection: close
        Date: Wed, 23 Apr 2025 14:59:37 GMT
        Last-Modified: Tue, 22 Apr 2025 08:58:26 GMT
        Server: nginx/1.26.3
        Accept-Ranges: bytes
        ETag: "1dbb364b574e5c6"
        X-Cache: Miss from cloudfront
        Via: 1.1 933a1f24e25b892ac8dcf0df624577bc.cloudfront.net (CloudFront)
        X-Amz-Cf-Pop: LAX54-P3
        X-Amz-Cf-Id: p45ofdLnp5mpk5hfPRU3Q9dTLtQkS0Ifm4ELetTAaCZd36fmnb59fA==
        2025-04-23 14:59:37 UTC198INData Raw: 00 00 01 00 01 00 10 10 02 00 01 00 01 00 b0 00 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00
        Data Ascii: (


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:1
        Start time:10:59:24
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:10:59:28
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,12402582583480906827,17708485085395737827,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:10:59:33
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://d1lkfzu2puirk6.cloudfront.net/api/poddbs"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly