Edit tour

Windows Analysis Report
http://aircraft-database.com/favicon.ico

Overview

General Information

Sample URL:http://aircraft-database.com/favicon.ico
Analysis ID:1672219
Infos:

Detection

Score:0
Range:0 - 100
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6684 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3876 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 3620 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aircraft-database.com/favicon.ico" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aircraft-database.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aircraft-database.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aircraft-database.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aircraft-database.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: aircraft-database.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: aircraft-database.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.190.63.222:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: classification engineClassification label: clean0.win@28/0@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3876 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aircraft-database.com/favicon.ico"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3876 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1672219 URL: http://aircraft-database.co... Startdate: 23/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 192.168.2.5, 138, 443, 49675 unknown unknown 5->15 17 192.168.2.6 unknown unknown 5->17 10 chrome.exe 5->10         started        13 chrome.exe 5->13         started        process4 dnsIp5 19 aircraft-database.com 64.190.63.222, 443, 49702, 49703 NBS11696US United States 10->19 21 www.google.com 192.178.49.196, 443, 49701, 49716 GOOGLEUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://aircraft-database.com/favicon.ico0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://aircraft-database.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
aircraft-database.com
64.190.63.222
truefalse
    unknown
    www.google.com
    192.178.49.196
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://aircraft-database.com/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      192.178.49.196
      www.google.comUnited States
      15169GOOGLEUSfalse
      64.190.63.222
      aircraft-database.comUnited States
      11696NBS11696USfalse
      IP
      192.168.2.6
      192.168.2.5
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1672219
      Start date and time:2025-04-23 17:28:13 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 3s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://aircraft-database.com/favicon.ico
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:9
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@28/0@8/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 184.29.183.29, 199.232.214.172, 142.250.68.238, 192.178.49.195, 142.250.101.84, 142.250.69.14, 23.220.73.19, 52.149.20.212, 150.171.28.254
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, c.pki.goog
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtOpenFile calls found.
      • VT rate limit hit for: http://aircraft-database.com/favicon.ico
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info

      Download Network PCAP: filteredfull

      • Total Packets: 76
      • 443 (HTTPS)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Apr 23, 2025 17:29:03.247509956 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:03.559708118 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:04.169075966 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:04.215950012 CEST49672443192.168.2.5204.79.197.203
      Apr 23, 2025 17:29:05.372178078 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:07.778486967 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:12.637804031 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:14.013221979 CEST49672443192.168.2.5204.79.197.203
      Apr 23, 2025 17:29:17.187043905 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:17.187098026 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:17.187329054 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:17.187484026 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:17.187496901 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:17.507673025 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:17.507791996 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:17.509074926 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:17.509083986 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:17.509357929 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:17.559710979 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:19.415019989 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.415071964 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:19.415138960 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.415360928 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.415374994 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:19.598902941 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.598942041 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:19.599045992 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.599212885 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.599247932 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:19.599324942 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.599445105 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.599461079 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:19.599509001 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:19.599519014 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.010919094 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.011113882 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.012458086 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.012469053 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.012758970 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.013072014 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.060292959 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.189081907 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.189239979 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.189399958 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.189469099 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.214498997 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.214518070 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.214848995 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.215241909 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.215267897 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.215625048 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.258594990 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.258616924 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.629708052 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.629801035 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:20.629858971 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.630450010 CEST49702443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:20.630470991 CEST4434970264.190.63.222192.168.2.5
      Apr 23, 2025 17:29:22.249061108 CEST49676443192.168.2.520.189.173.14
      Apr 23, 2025 17:29:25.117449999 CEST49675443192.168.2.52.23.227.208
      Apr 23, 2025 17:29:25.117497921 CEST443496752.23.227.208192.168.2.5
      Apr 23, 2025 17:29:27.489435911 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:27.489509106 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:27.489717960 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:28.406032085 CEST49701443192.168.2.5192.178.49.196
      Apr 23, 2025 17:29:28.406053066 CEST44349701192.178.49.196192.168.2.5
      Apr 23, 2025 17:29:32.124056101 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.124106884 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.124185085 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.124309063 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.124316931 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.124363899 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.126737118 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.126754045 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.126837969 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.126849890 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.715409040 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.715775967 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.715806961 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.715935946 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.715941906 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.718311071 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:32.718548059 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:32.718558073 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:33.338124037 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:33.338195086 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:33.338257074 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:33.338809013 CEST49708443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:33.338825941 CEST4434970864.190.63.222192.168.2.5
      Apr 23, 2025 17:29:35.478538990 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:35.478598118 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:35.478652000 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:35.478833914 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:35.478903055 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:35.478977919 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:36.426115990 CEST49704443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:36.426142931 CEST4434970464.190.63.222192.168.2.5
      Apr 23, 2025 17:29:36.426300049 CEST49703443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:36.426338911 CEST4434970364.190.63.222192.168.2.5
      Apr 23, 2025 17:29:48.008413076 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:48.008491039 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:29:48.008557081 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:48.406277895 CEST49707443192.168.2.564.190.63.222
      Apr 23, 2025 17:29:48.406303883 CEST4434970764.190.63.222192.168.2.5
      Apr 23, 2025 17:30:06.753159046 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.753196001 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:06.753263950 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.753685951 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.753711939 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:06.753772020 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.754024029 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.754036903 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:06.754354954 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:06.754369974 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.342134953 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.343413115 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:07.343436003 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.343580961 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:07.343585968 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.348942995 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.349237919 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:07.349261999 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.964930058 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.965012074 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:07.965230942 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:08.057596922 CEST49710443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:08.057627916 CEST4434971064.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.074325085 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.074366093 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.074450970 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.074628115 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.074642897 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.090150118 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.090167999 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.382605076 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.382690907 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.382900000 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.383116007 CEST49711443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.383132935 CEST4434971164.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.663645029 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.663981915 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.664005041 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:09.664400101 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:09.664412975 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:10.285499096 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:10.285559893 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:10.285674095 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:10.286329031 CEST49712443192.168.2.564.190.63.222
      Apr 23, 2025 17:30:10.286344051 CEST4434971264.190.63.222192.168.2.5
      Apr 23, 2025 17:30:17.110842943 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:17.110902071 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:17.111012936 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:17.111236095 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:17.111248970 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:17.425767899 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:17.426070929 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:17.426111937 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:27.408891916 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:27.408960104 CEST44349716192.178.49.196192.168.2.5
      Apr 23, 2025 17:30:27.409010887 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:27.409517050 CEST49716443192.168.2.5192.178.49.196
      Apr 23, 2025 17:30:27.409538984 CEST44349716192.178.49.196192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Apr 23, 2025 17:29:12.671426058 CEST53580901.1.1.1192.168.2.5
      Apr 23, 2025 17:29:12.839936972 CEST53589731.1.1.1192.168.2.5
      Apr 23, 2025 17:29:13.988475084 CEST53569711.1.1.1192.168.2.5
      Apr 23, 2025 17:29:17.045322895 CEST5883853192.168.2.51.1.1.1
      Apr 23, 2025 17:29:17.045511007 CEST6345753192.168.2.51.1.1.1
      Apr 23, 2025 17:29:17.185688972 CEST53634571.1.1.1192.168.2.5
      Apr 23, 2025 17:29:17.185720921 CEST53588381.1.1.1192.168.2.5
      Apr 23, 2025 17:29:18.949131012 CEST6546053192.168.2.51.1.1.1
      Apr 23, 2025 17:29:18.949326992 CEST5377653192.168.2.51.1.1.1
      Apr 23, 2025 17:29:18.960117102 CEST5868353192.168.2.51.1.1.1
      Apr 23, 2025 17:29:18.960587978 CEST5450053192.168.2.51.1.1.1
      Apr 23, 2025 17:29:19.413847923 CEST53545001.1.1.1192.168.2.5
      Apr 23, 2025 17:29:19.413976908 CEST53586831.1.1.1192.168.2.5
      Apr 23, 2025 17:29:19.414635897 CEST53654601.1.1.1192.168.2.5
      Apr 23, 2025 17:29:19.423927069 CEST53537761.1.1.1192.168.2.5
      Apr 23, 2025 17:29:19.424880981 CEST6323753192.168.2.51.1.1.1
      Apr 23, 2025 17:29:19.425090075 CEST5452853192.168.2.51.1.1.1
      Apr 23, 2025 17:29:19.574726105 CEST53632371.1.1.1192.168.2.5
      Apr 23, 2025 17:29:19.598264933 CEST53545281.1.1.1192.168.2.5
      Apr 23, 2025 17:29:31.051181078 CEST53646681.1.1.1192.168.2.5
      Apr 23, 2025 17:29:49.971605062 CEST53633021.1.1.1192.168.2.5
      Apr 23, 2025 17:30:06.521204948 CEST138138192.168.2.5192.168.2.255
      Apr 23, 2025 17:30:12.441334009 CEST53515551.1.1.1192.168.2.5
      Apr 23, 2025 17:30:12.942511082 CEST53529231.1.1.1192.168.2.5
      Apr 23, 2025 17:30:15.751574993 CEST53624301.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Apr 23, 2025 17:29:17.045322895 CEST192.168.2.51.1.1.10x6d5eStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:17.045511007 CEST192.168.2.51.1.1.10xbfedStandard query (0)www.google.com65IN (0x0001)false
      Apr 23, 2025 17:29:18.949131012 CEST192.168.2.51.1.1.10xfafcStandard query (0)aircraft-database.comA (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:18.949326992 CEST192.168.2.51.1.1.10x856aStandard query (0)aircraft-database.com65IN (0x0001)false
      Apr 23, 2025 17:29:18.960117102 CEST192.168.2.51.1.1.10x3820Standard query (0)aircraft-database.comA (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:18.960587978 CEST192.168.2.51.1.1.10xe44eStandard query (0)aircraft-database.com65IN (0x0001)false
      Apr 23, 2025 17:29:19.424880981 CEST192.168.2.51.1.1.10xd013Standard query (0)aircraft-database.comA (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:19.425090075 CEST192.168.2.51.1.1.10x2d83Standard query (0)aircraft-database.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Apr 23, 2025 17:29:17.185688972 CEST1.1.1.1192.168.2.50xbfedNo error (0)www.google.com65IN (0x0001)false
      Apr 23, 2025 17:29:17.185720921 CEST1.1.1.1192.168.2.50x6d5eNo error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:19.413976908 CEST1.1.1.1192.168.2.50x3820No error (0)aircraft-database.com64.190.63.222A (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:19.414635897 CEST1.1.1.1192.168.2.50xfafcNo error (0)aircraft-database.com64.190.63.222A (IP address)IN (0x0001)false
      Apr 23, 2025 17:29:19.574726105 CEST1.1.1.1192.168.2.50xd013No error (0)aircraft-database.com64.190.63.222A (IP address)IN (0x0001)false
      • aircraft-database.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.54970264.190.63.2224435444C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2025-04-23 15:29:20 UTC682OUTGET /favicon.ico HTTP/1.1
      Host: aircraft-database.com
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Accept-Encoding: gzip, deflate, br, zstd
      Accept-Language: en-US,en;q=0.9
      2025-04-23 15:29:20 UTC128INHTTP/1.1 441 status code 441
      Content-Length: 0
      Date: Wed, 23 Apr 2025 15:29:20 GMT
      Server: Parking/1.0
      Connection: close


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.54970864.190.63.2224435444C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2025-04-23 15:29:32 UTC714OUTGET /favicon.ico HTTP/1.1
      Host: aircraft-database.com
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: cross-site
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br, zstd
      Accept-Language: en-US,en;q=0.9
      2025-04-23 15:29:33 UTC128INHTTP/1.1 441 status code 441
      Content-Length: 0
      Date: Wed, 23 Apr 2025 15:29:33 GMT
      Server: Parking/1.0
      Connection: close


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.54971064.190.63.2224435444C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2025-04-23 15:30:07 UTC714OUTGET /favicon.ico HTTP/1.1
      Host: aircraft-database.com
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: cross-site
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br, zstd
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.54971164.190.63.2224435444C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2025-04-23 15:30:09 UTC694OUTGET /favicon.ico HTTP/1.1
      Host: aircraft-database.com
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: cross-site
      Sec-Fetch-Mode: navigate
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br, zstd
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.54971264.190.63.2224435444C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2025-04-23 15:30:09 UTC694OUTGET /favicon.ico HTTP/1.1
      Host: aircraft-database.com
      Connection: keep-alive
      Cache-Control: max-age=0
      sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: cross-site
      Sec-Fetch-Mode: navigate
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br, zstd
      Accept-Language: en-US,en;q=0.9
      2025-04-23 15:30:10 UTC128INHTTP/1.1 441 status code 441
      Content-Length: 0
      Date: Wed, 23 Apr 2025 15:30:10 GMT
      Server: Parking/1.0
      Connection: close


      020406080s020406080100

      Click to jump to process

      020406080s0.0050100MB

      Click to jump to process

      Target ID:0
      Start time:11:29:06
      Start date:23/04/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff608e70000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:1
      Start time:11:29:10
      Start date:23/04/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
      Imagebase:0x7ff608e70000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:11:29:13
      Start date:23/04/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2040,i,16281690410798685253,16250520817052865422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3876 /prefetch:8
      Imagebase:0x7ff608e70000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:5
      Start time:11:29:17
      Start date:23/04/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aircraft-database.com/favicon.ico"
      Imagebase:0x7ff608e70000
      File size:3'388'000 bytes
      MD5 hash:E81F54E6C1129887AEA47E7D092680BF
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

      No disassembly