Edit tour

Windows Analysis Report
https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small

Overview

General Information

Sample URL:https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small
Analysis ID:1673864
Infos:

Detection

Score:20
Range:0 - 100
Confidence:100%

Signatures

AI detected suspicious URL

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1760 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1128 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2096,i,535839618176901581,15943560536411657664,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2240 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6860 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://twimg.comJoe Sandbox AI: The URL 'twimg.com' is visually and structurally similar to 'twitter.com', a well-known brand. The legitimate URL for Twitter is 'twitter.com', and 'twimg.com' could be perceived as a shortened or alternative version of the brand's name. The use of 'twimg' could suggest a connection to Twitter's image hosting or media services, which might confuse users into thinking it is an official Twitter domain. The similarity score is high due to the truncation of the brand name and the potential for user confusion. The likelihood of typosquatting is also high, as the domain could be used to deceive users into believing they are interacting with a Twitter-related service.
Source: https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=smallHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /media/GoH5SztXEAA5W_k?format=png&name=small HTTP/1.1Host: pbs.twimg.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: pbs.twimg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=smallAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: pbs.twimg.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: pbs.twimg.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownHTTPS traffic detected: 192.178.49.164:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.20.159:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: classification engineClassification label: sus20.win@21/5@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2096,i,535839618176901581,15943560536411657664,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2240 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2096,i,535839618176901581,15943560536411657664,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2240 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1673864 URL: https://pbs.twimg.com/media... Startdate: 25/04/2025 Architecture: WINDOWS Score: 20 22 AI detected suspicious URL 2->22 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49708 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 www.google.com 192.178.49.164, 443, 49728, 49740 GOOGLEUS United States 11->16 18 dualstack.twimg.twitter.map.fastly.net 151.101.20.159, 443, 49730, 49731 FASTLYUS United States 11->18 20 pbs.twimg.com 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dualstack.twimg.twitter.map.fastly.net
151.101.20.159
truefalse
    high
    www.google.com
    192.178.49.164
    truefalse
      high
      pbs.twimg.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=smallfalse
          high
          https://pbs.twimg.com/favicon.icofalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            192.178.49.164
            www.google.comUnited States
            15169GOOGLEUSfalse
            151.101.20.159
            dualstack.twimg.twitter.map.fastly.netUnited States
            54113FASTLYUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1673864
            Start date and time:2025-04-25 08:42:19 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 5s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:20
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:SUS
            Classification:sus20.win@21/5@6/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 192.178.49.174, 142.250.68.227, 142.250.101.84, 192.178.49.206, 192.178.49.163, 184.29.183.29, 131.253.33.254, 20.12.23.50
            • Excluded domains from analysis (whitelisted): a-ring-fallback.msedge.net, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
            • VT rate limit hit for: https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&amp;name=small
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):549
            Entropy (8bit):7.471916944420736
            Encrypted:false
            SSDEEP:12:6v/7i/i1SlUUPqHhJYMablwuOa6vz5xtnSDnkXMYvJmJSt/6znV:AwbSBa8zXtnBZAJ9
            MD5:9D99A2372BBD5B28EF4B2EAECAC8C805
            SHA1:6503A35C95CDF2D08ED83E17AE81C8B0E58F49C2
            SHA-256:CC4939AF5D16855F2BEA8322DBF33461EBC6BFD092FA3E2291D87D3D83EBD8ED
            SHA-512:7EFBA58D391137EA50C0ED95025316E404CE8FED549C386F2D3316D91797CD39E5447DB9B0FFDB0EBADBAF1F38766743603C140B8DFB956ECCC144AA78CFF766
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR... ... .....szz.....IDATx..W1..0..w.%t.<.:J.@I.%.......t..R.......L..fN....;.&....lbk.d. "C5...l.......1..F#....r....j...f..... u....c.|.^.........a2p.X..t:M.....|.Z.....7.M2A..K..n.!..|>O..t!.?`)...I..0{\)....Rb.. .=r......%fK..}..%.,c\J.).q0..D+!`.j'.0.@..v....1...c..G.....+.........`....w....=.O...f...aH..%...15.M:.N.k^...e.D..[....&.]...D.s.h]..*#..n.s......ppL.%)...........2..........}2....9...l.y...s:...e...vN.:.t....{....\..x<....wj..IG..S...<u:.d...._fw.WNZ........v.?.ZLm..]J....IEND.B`.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):549
            Entropy (8bit):7.471916944420736
            Encrypted:false
            SSDEEP:12:6v/7i/i1SlUUPqHhJYMablwuOa6vz5xtnSDnkXMYvJmJSt/6znV:AwbSBa8zXtnBZAJ9
            MD5:9D99A2372BBD5B28EF4B2EAECAC8C805
            SHA1:6503A35C95CDF2D08ED83E17AE81C8B0E58F49C2
            SHA-256:CC4939AF5D16855F2BEA8322DBF33461EBC6BFD092FA3E2291D87D3D83EBD8ED
            SHA-512:7EFBA58D391137EA50C0ED95025316E404CE8FED549C386F2D3316D91797CD39E5447DB9B0FFDB0EBADBAF1F38766743603C140B8DFB956ECCC144AA78CFF766
            Malicious:false
            Reputation:low
            URL:https://pbs.twimg.com/favicon.ico
            Preview:.PNG........IHDR... ... .....szz.....IDATx..W1..0..w.%t.<.:J.@I.%.......t..R.......L..fN....;.&....lbk.d. "C5...l.......1..F#....r....j...f..... u....c.|.^.........a2p.X..t:M.....|.Z.....7.M2A..K..n.!..|>O..t!.?`)...I..0{\)....Rb.. .=r......%fK..}..%.,c\J.).q0..D+!`.j'.0.@..v....1...c..G.....+.........`....w....=.O...f...aH..%...15.M:.N.k^...e.D..[....&.]...D.s.h]..*#..n.s......ppL.%)...........2..........}2....9...l.y...s:...e...vN.:.t....{....\..x<....wj..IG..S...<u:.d...._fw.WNZ........v.?.ZLm..]J....IEND.B`.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 500 x 500, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):256775
            Entropy (8bit):7.995300026750047
            Encrypted:true
            SSDEEP:6144:pToAfia4NMUOQtp9eyx5iFBfFtSGkzvl18JZMpQAp:e4CNlOczqBffkzvl1eVg
            MD5:02D404019C5CEA1AE70543EFC6A1040C
            SHA1:7CF45AD9FFFDA965DA12902F55CAA194018E0F9C
            SHA-256:8215BFDE7D21989467313A5881BBEF37B7189715A7F87B8BCFDCA4933AD45AFB
            SHA-512:14F55E82804922F08E3C151593505556885A32F258CF2730A4D190C8362F8BE0427ACE5972B85F933C2B7607DC9048A2F5FCD1EB957B87D7EACFB2EFDB1532D4
            Malicious:false
            Reputation:low
            URL:https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small
            Preview:.PNG........IHDR....................sRGB....... .IDATx^...$.u....YYY..w.L..3.[.x....mieZ..A.b.c..$K+JZ.(..h/.+x....)..HJ.x..\.3.....................3.P.a.;.......Q..........Y .@d.....".|.[...?...".D..,.Y .@d.D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D......".D..,.Y.>.@....E.N!.@d.....".D.......s....s+t..@&-...@.4.t.0........N.2m.o9N.6..8.i..i8........}#a$.>....F..|.`....4..k........``...!.....n.....nw....q=..Z......1.4|..K>.0f.>l._.....3..n...L.;.X..O.].2=.4..\.,...i.m..>.%..}.....u.@..L:e.Q..}.rO..5.C>.="....@...-..}......&.f.R..r4.f."..l..5:f.,......l....pL.\..<.<k00..0L..m..L...[..........}..<..a....kx.gx.gx.oZ.e......n7..n.......].u]c0p..2..-.7lw...k..k..k{.....>...e.&...={.1....\ng.0.....CuL..=.>l.~.o..5..,.......t....5..g.<..,.0<.0<_.7<..~}.......y|.O{...6|.f
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 101
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2025 08:43:11.711918116 CEST4968180192.168.2.42.17.190.73
            Apr 25, 2025 08:43:18.265646935 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:18.680692911 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:19.383773088 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:20.680520058 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:21.320836067 CEST4968180192.168.2.42.17.190.73
            Apr 25, 2025 08:43:23.087162018 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:24.480056047 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:24.480106115 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:24.480182886 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:24.480372906 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:24.480384111 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:24.800939083 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:24.801040888 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:24.802407980 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:24.802418947 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:24.802712917 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:24.852154016 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:25.537543058 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.537596941 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:25.537656069 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.537849903 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.537861109 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:25.605034113 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.605078936 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:25.605143070 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.607402086 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:25.607413054 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.063056946 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.063127041 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.127115965 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.127218008 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.144373894 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.144406080 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.145070076 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.145092010 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.145117998 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.145332098 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.145744085 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.188275099 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.194592953 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.300000906 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:26.319308043 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.319855928 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.319917917 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.319942951 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.320029020 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.320080042 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.320087910 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.325608015 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.325644970 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.325683117 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.325696945 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.325733900 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.331435919 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.337768078 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.337821007 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.337821007 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.337831020 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.337863922 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.343239069 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.349180937 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.349217892 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.349230051 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.349237919 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.349273920 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.355115891 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.361032963 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.361068964 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.361104012 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.361110926 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.361151934 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.366923094 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.372905970 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.372947931 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.372976065 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.372982979 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.373111010 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.378736019 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.384649038 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.384687901 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.384707928 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.384713888 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.384763956 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.490653992 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.493495941 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.493532896 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.493541002 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.493557930 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.493598938 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.498944044 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.504328012 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.504369974 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.504415989 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.504425049 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.504483938 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.509005070 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.533411026 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.533433914 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.533478975 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.533489943 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.533519030 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.533548117 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.552290916 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.552313089 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.552351952 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.552361012 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.552402973 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.570403099 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.570422888 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.570518017 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.570524931 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.602268934 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:26.617518902 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.668493986 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.668508053 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.668544054 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.668606043 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.668618917 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.668653011 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.684518099 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.684535980 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.684600115 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.684614897 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.684640884 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.689502954 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.689733028 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.689740896 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.689819098 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.702613115 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.702636957 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.702706099 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.702718019 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.702770948 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.715358973 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.715378046 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.715476036 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.715486050 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.715605021 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.728183985 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.728204966 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.728246927 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.728257895 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.728303909 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.728316069 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.738969088 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.738985062 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.739037991 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.739046097 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.739074945 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.739099979 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.750047922 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.750066996 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.750128984 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.750137091 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.750235081 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.759953022 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.759970903 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.760010958 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.760016918 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.760071993 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.834079027 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.834110022 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.834152937 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.834167957 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.834218979 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.834218979 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.839258909 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.839298964 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.839332104 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.839353085 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.839402914 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.848875999 CEST49730443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.848893881 CEST44349730151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:26.941246033 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:26.988272905 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.186032057 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.186145067 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.186192989 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.187982082 CEST49731443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.187998056 CEST44349731151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.213392019 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:27.338229895 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.338274002 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.338571072 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.338726044 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.338736057 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.685331106 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.685406923 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.688144922 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.688163042 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.688472986 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.688743114 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:27.732285023 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:27.898714066 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:28.028759956 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:28.028865099 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:28.028913021 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:28.029874086 CEST49733443192.168.2.4151.101.20.159
            Apr 25, 2025 08:43:28.029892921 CEST44349733151.101.20.159192.168.2.4
            Apr 25, 2025 08:43:28.414331913 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:30.539134979 CEST49708443192.168.2.452.113.196.254
            Apr 25, 2025 08:43:30.679176092 CEST4434970852.113.196.254192.168.2.4
            Apr 25, 2025 08:43:30.821115971 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:34.778472900 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:34.778527021 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:34.778681993 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:35.135997057 CEST49728443192.168.2.4192.178.49.164
            Apr 25, 2025 08:43:35.136023045 CEST44349728192.178.49.164192.168.2.4
            Apr 25, 2025 08:43:35.633632898 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:43:37.509505033 CEST49671443192.168.2.4204.79.197.203
            Apr 25, 2025 08:43:45.240571976 CEST49678443192.168.2.420.189.173.27
            Apr 25, 2025 08:44:04.384438038 CEST4971280192.168.2.4192.178.49.195
            Apr 25, 2025 08:44:04.384438992 CEST4971180192.168.2.4199.232.210.172
            Apr 25, 2025 08:44:04.384469032 CEST4971380192.168.2.4199.232.210.172
            Apr 25, 2025 08:44:04.531964064 CEST8049713199.232.210.172192.168.2.4
            Apr 25, 2025 08:44:04.531987906 CEST8049712192.178.49.195192.168.2.4
            Apr 25, 2025 08:44:04.532052040 CEST4971280192.168.2.4192.178.49.195
            Apr 25, 2025 08:44:04.532334089 CEST8049713199.232.210.172192.168.2.4
            Apr 25, 2025 08:44:04.532373905 CEST4971380192.168.2.4199.232.210.172
            Apr 25, 2025 08:44:04.533548117 CEST8049711199.232.210.172192.168.2.4
            Apr 25, 2025 08:44:04.533570051 CEST8049711199.232.210.172192.168.2.4
            Apr 25, 2025 08:44:04.533641100 CEST4971180192.168.2.4199.232.210.172
            Apr 25, 2025 08:44:24.400017977 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:24.400078058 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:24.400279045 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:24.400316000 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:24.400321960 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:24.714744091 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:24.715039968 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:24.715076923 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:34.699225903 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:34.699287891 CEST44349740192.178.49.164192.168.2.4
            Apr 25, 2025 08:44:34.699433088 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:35.136444092 CEST49740443192.168.2.4192.178.49.164
            Apr 25, 2025 08:44:35.136492968 CEST44349740192.178.49.164192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2025 08:43:20.409414053 CEST53599791.1.1.1192.168.2.4
            Apr 25, 2025 08:43:20.411633015 CEST53509361.1.1.1192.168.2.4
            Apr 25, 2025 08:43:21.672008038 CEST53581321.1.1.1192.168.2.4
            Apr 25, 2025 08:43:24.338026047 CEST6117853192.168.2.41.1.1.1
            Apr 25, 2025 08:43:24.338184118 CEST5441353192.168.2.41.1.1.1
            Apr 25, 2025 08:43:24.478684902 CEST53611781.1.1.1192.168.2.4
            Apr 25, 2025 08:43:24.478710890 CEST53544131.1.1.1192.168.2.4
            Apr 25, 2025 08:43:25.396217108 CEST6095953192.168.2.41.1.1.1
            Apr 25, 2025 08:43:25.396656036 CEST5290653192.168.2.41.1.1.1
            Apr 25, 2025 08:43:25.536827087 CEST53529061.1.1.1192.168.2.4
            Apr 25, 2025 08:43:25.536894083 CEST53609591.1.1.1192.168.2.4
            Apr 25, 2025 08:43:27.194166899 CEST6278853192.168.2.41.1.1.1
            Apr 25, 2025 08:43:27.194371939 CEST5700753192.168.2.41.1.1.1
            Apr 25, 2025 08:43:27.334640026 CEST53627881.1.1.1192.168.2.4
            Apr 25, 2025 08:43:27.334665060 CEST53570071.1.1.1192.168.2.4
            Apr 25, 2025 08:43:38.675760984 CEST53550441.1.1.1192.168.2.4
            Apr 25, 2025 08:43:57.713537931 CEST53563501.1.1.1192.168.2.4
            Apr 25, 2025 08:44:19.762989044 CEST53566741.1.1.1192.168.2.4
            Apr 25, 2025 08:44:20.577056885 CEST53507671.1.1.1192.168.2.4
            Apr 25, 2025 08:44:23.119553089 CEST53597521.1.1.1192.168.2.4
            Apr 25, 2025 08:44:25.718329906 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 25, 2025 08:43:24.338026047 CEST192.168.2.41.1.1.10x5adcStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:24.338184118 CEST192.168.2.41.1.1.10xb3ebStandard query (0)www.google.com65IN (0x0001)false
            Apr 25, 2025 08:43:25.396217108 CEST192.168.2.41.1.1.10xda5dStandard query (0)pbs.twimg.comA (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:25.396656036 CEST192.168.2.41.1.1.10xf82Standard query (0)pbs.twimg.com65IN (0x0001)false
            Apr 25, 2025 08:43:27.194166899 CEST192.168.2.41.1.1.10xfbe3Standard query (0)pbs.twimg.comA (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:27.194371939 CEST192.168.2.41.1.1.10x9ddStandard query (0)pbs.twimg.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 25, 2025 08:43:24.478684902 CEST1.1.1.1192.168.2.40x5adcNo error (0)www.google.com192.178.49.164A (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:24.478710890 CEST1.1.1.1192.168.2.40xb3ebNo error (0)www.google.com65IN (0x0001)false
            Apr 25, 2025 08:43:25.536827087 CEST1.1.1.1192.168.2.40xf82No error (0)pbs.twimg.compbs.twimg.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2025 08:43:25.536894083 CEST1.1.1.1192.168.2.40xda5dNo error (0)pbs.twimg.comdualstack.twimg.twitter.map.fastly.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2025 08:43:25.536894083 CEST1.1.1.1192.168.2.40xda5dNo error (0)dualstack.twimg.twitter.map.fastly.net151.101.20.159A (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:27.334640026 CEST1.1.1.1192.168.2.40xfbe3No error (0)pbs.twimg.comdualstack.twimg.twitter.map.fastly.netCNAME (Canonical name)IN (0x0001)false
            Apr 25, 2025 08:43:27.334640026 CEST1.1.1.1192.168.2.40xfbe3No error (0)dualstack.twimg.twitter.map.fastly.net151.101.20.159A (IP address)IN (0x0001)false
            Apr 25, 2025 08:43:27.334665060 CEST1.1.1.1192.168.2.40x9ddNo error (0)pbs.twimg.compbs.twimg.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
            • pbs.twimg.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449730151.101.20.1594431128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-25 06:43:26 UTC706OUTGET /media/GoH5SztXEAA5W_k?format=png&name=small HTTP/1.1
            Host: pbs.twimg.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-25 06:43:26 UTC791INHTTP/1.1 200 OK
            Connection: close
            Content-Length: 256775
            perf: 7402827104
            cache-tag: media,media/bucket/3,media/1910081818495225856
            content-type: image/png
            cache-control: max-age=604800, must-revalidate
            last-modified: Wed, 09 Apr 2025 21:24:07 GMT
            x-transaction-id: 3a4e7a0d7e56d488
            timing-allow-origin: https://twitter.com, https://mobile.twitter.com
            strict-transport-security: max-age=631138519
            access-control-allow-origin: *
            access-control-expose-headers: Content-Length
            cross-origin-resource-policy: cross-origin
            X-Content-Type-Options: nosniff
            Accept-Ranges: bytes
            Date: Fri, 25 Apr 2025 06:43:26 GMT
            X-Cache: HIT, HIT
            x-tw-cdn: FT
            x-served-by: cache-pdk-kpdk1780104-PDK, cache-bfi-krnt7300026-BFI, cache-tw-ZZZ1
            Server-Timing: x-cache;desc=HIT, x-tw-cdn;desc=FT
            2025-04-25 06:43:26 UTC1379INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 f4 00 00 01 f4 08 06 00 00 00 cb d6 df 8a 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 20 00 49 44 41 54 78 5e ec bd 09 8c 24 e9 75 1e f8 c5 91 f7 59 59 59 f7 d5 77 f7 4c 1f d3 33 c3 9e 5b c3 a1 78 8a 14 bd 92 6d 69 65 5a b0 01 41 f2 62 05 63 bd 80 24 4b 2b 4a 5a eb b2 28 98 ba 68 2f b0 2b 78 ad 05 16 b2 29 af d6 86 48 4a a6 78 8c 86 5c 92 33 e2 cc b0 bb a7 ef fb a8 fb ca ca fb 8a 8c 88 c5 f7 fe f8 ab a2 8b 33 f4 50 14 61 b0 3b 12 a8 ce ae cc c8 c8 88 17 51 ff f7 de f7 de fb 9e 81 e8 11 59 20 b2 40 64 81 c8 02 91 05 22 0b 7c cf 5b c0 f8 9e 3f 83 e8 04 22 0b 44 16 88 2c 10 59 20 b2 40 64 01 44 80 1e dd 04 91 05 22 0b 44 16 88 2c 10 59 e0 3e b0 40 04 e8 f7 c1 45 8c 4e 21 b2 40 64 81 c8 02 91 05 22 0b
            Data Ascii: PNGIHDRsRGB IDATx^$uYYYwL3[xmieZAbc$K+JZ(h/+x)HJx\33Pa;QY @d"|[?"D,Y @dD"D,Y>@EN!@d"
            2025-04-25 06:43:26 UTC1379INData Raw: bf 2f 3f 1a 34 7d d7 83 69 5b 48 c6 13 88 25 e2 b0 0c 13 12 d7 7b 3e b1 16 44 e1 fe c0 41 af d3 45 b7 df 83 37 50 e0 cb 07 bf 33 15 4f c0 8c d9 82 da 74 0c e0 7a 70 e1 cb ef c9 4c 1a 09 3b 86 56 b7 83 fa 56 55 9e f9 7b 2a 95 42 3c 61 23 93 49 c9 3e 34 a0 13 88 e9 07 74 bb 5d f9 a1 7d 7a bd 1e 8a c5 22 a6 a6 a6 04 a8 ab d5 2a 5a ad 16 7c 77 80 44 22 b1 0d dc 7c 8f fb e1 0f ff cf 07 ed c2 6d 78 fe 3c 5f be c7 67 5e d2 81 bb 0d f2 db e7 13 76 18 b6 1d 96 d0 bd cc fd 88 a3 60 92 30 10 8c e6 3f ae 0f 38 a6 69 f6 0d 7a 7e 86 41 00 ef b8 ae 5b 4b 26 93 0b b9 6c 66 65 68 a8 f4 f2 e4 e4 f8 b9 99 7d 53 f3 23 23 7b 9b 13 13 13 dc 66 c7 90 d1 8a 11 59 e0 3b b4 40 04 e8 df a1 01 a3 8f ef 58 40 80 70 63 23 5b 31 cd 82 61 0c 4a 8d 46 23 b7 b5 55 1b 6b 34 6a c5 46 a5 96
            Data Ascii: /?4}i[H%{>DAE7P3OtzpL;VVU{*B<a#I>4t]}z"*Z|wD"|mx<_g^v`0?8iz~A[K&lfeh}S##{fY;@X@pc#[1aJF#Uk4jF
            2025-04-25 06:43:26 UTC1379INData Raw: b5 00 61 d6 82 f6 27 e3 42 26 c5 56 79 fc e5 91 91 f2 67 8e 3f f2 c8 67 4f 3d f5 d8 6b 07 0e 9c 58 65 16 e6 41 5c 67 a2 73 fe 9b 59 20 02 f4 bf 99 dd 1e b8 4f f9 fe 66 fe d5 57 cf 9f fc d2 17 bf fc 93 e7 ce 9f 7b b4 dd 6e cf a6 93 29 d2 e0 31 c9 df b2 76 8a 54 33 73 af a4 78 b9 d4 05 54 a9 8e e6 68 b4 9d 28 4e 51 ab 8c 20 77 2f a2 bb 01 5e 00 43 2a a9 76 16 5e 7d 01 84 f6 0c ed 57 17 42 e9 c5 58 2f c0 2a 67 aa 1e 61 ca 9e 0e c1 6e 20 0f bf af 01 5c 83 da ee 85 9b 00 23 64 6d 70 ae 61 40 d6 40 c3 67 0d a8 3a 5a d3 d1 a3 2e fa d2 df a3 8f 53 db 44 47 9a 1a 84 34 e8 ea f3 8a db ca 41 d0 e7 ab 23 51 82 3b 3f 4b ba 39 9c 1e d0 80 47 60 e5 4f d8 5e fa 1c c3 e7 ba 3b fd 10 7e 4f 01 b3 02 74 6d 43 1d c1 eb 73 e6 f9 e9 73 d6 80 16 ce 65 33 f1 ac 69 76 fd 5d e1 48
            Data Ascii: a'B&Vyg?gO=kXeA\gsY OfW{n)1vT3sxTh(NQ w/^C*v^}WBX/*gan \#dmpa@@g:Z.SDG4A#Q;?K9G`O^;~OtmCsse3iv]H
            2025-04-25 06:43:26 UTC1379INData Raw: a9 f1 f1 f1 b5 fb 7d 2d 8a ce ef db b7 40 04 e8 df be cd ee cb 4f 54 6e dc 28 fc e7 cf 7f fe 1f bc f4 d2 17 ff 99 e3 38 07 9c 6e cf a2 f0 c9 0e 50 31 1a 1a 08 45 ab 17 25 89 d4 83 5c e1 4e 6e 51 e5 3a 83 d4 e0 3d 15 e9 0a f8 77 22 77 d9 8f 69 81 71 b6 06 e8 dd cf d2 86 15 2c 9e dc 2f 0b 98 74 95 b1 96 e6 0a d3 a8 bb c1 5c 9c 8b c0 21 d8 ed 54 90 a5 66 df b5 a6 3b c3 51 b3 de 56 e7 9c 75 61 59 b8 92 9b 40 1e 76 36 f4 77 bf 19 f0 bc d5 4d 13 3e 37 fe ff 9b 41 4f 7d 32 1c c1 87 f7 c5 1c b4 62 38 c8 3c a8 67 b6 eb b1 7d 2f 28 8c 97 36 3d 16 ca 8b 0b 15 6c c7 f7 3d 43 e5 91 df 2c 32 0f 03 1a 01 8c ae 83 7e 66 c4 ce cf f1 59 e7 ec df cc 81 09 47 ee e1 e3 0f db 47 8e 57 1e 2a f6 67 2b 99 66 6f 74 c4 ce 23 0c e7 b4 b5 43 c5 67 ed 54 f1 fe 0b b7 bd 69 50 d4 85 8a
            Data Ascii: }-@OTn(8nP1E%\NnQ:=w"wiq,/t\!Tf;QVuaY@v6wM>7AO}2b8<g}/(6=l=C,2~fYGGW*g+fot#CgTiP
            2025-04-25 06:43:26 UTC1379INData Raw: a4 65 20 66 9b 48 c6 63 88 db 54 da 33 90 a0 d2 5d 3a 07 23 50 f0 1b 1d 9b a8 fe ec cf fe dc 07 4f 3c f6 d8 cb df ce 3d 15 6d fb 60 58 20 02 f4 07 e3 3a 7f cb b3 7c f5 d5 97 7f e0 17 7e fe e7 ff ef c5 c5 c5 61 2e 3c 8c d0 37 36 36 90 2f 16 d0 6d 77 84 8a 4e c6 53 12 4d 50 39 ab c7 42 a3 40 5d cd 1f 84 f2 7f 41 3e 71 27 9a f1 a4 27 3d 1c 81 6d 03 42 40 71 da 96 a6 8c 55 8f f9 6e 5a 93 fd ed e1 c8 4a 03 8b de d6 a5 73 61 92 12 67 2e 5e 55 79 4b 6e 37 a8 c2 ee b6 db db 39 62 5d 0d 2e 1f e0 e0 0f 46 c1 a6 09 87 ff 09 14 d7 c2 94 bc ce 7b 6a e0 e6 77 eb 16 29 29 10 0c f5 b6 87 8f 71 f7 f9 ee 3e fe b7 02 6c bd dd 9b 39 02 bb 53 12 62 47 f9 00 d9 05 45 4b bf d9 63 37 a0 86 9d 23 76 03 e8 6b a5 81 54 ef 47 db 37 9c d2 d0 af e9 e3 e4 f9 d3 ce ec 77 0f 53 df e1 5c
            Data Ascii: e fHcT3]:#PO<=m`X :|~a.<766/mwNSMP9B@]A>q''=mB@qUnZJsag.^UyKn79b].F{jw))q>l9SbGEKc7#vkTG7wS\
            2025-04-25 06:43:26 UTC1379INData Raw: a0 d8 8d ee 47 ab d5 40 a7 d7 97 68 bc da 68 a0 56 6f 62 b3 ba 25 40 4e 40 27 98 33 95 a0 a3 4b 4d af 6f 17 eb 05 3d c7 12 3d eb 42 28 2a b3 71 16 37 f5 e7 82 14 82 96 12 95 2a f6 d0 6c 6e 0e 46 91 88 55 06 8d a8 a1 2e e2 c8 c8 bc 56 15 cd e9 41 ad 32 07 2e 28 32 93 82 3d 01 90 c0 7e 41 db 9f 7c 96 e0 ab 04 f5 40 d5 34 e9 e9 0f be 53 ec 2b 82 31 4c 45 a8 3e f5 f0 63 3b e2 4e aa 48 57 a6 b5 89 6b a2 52 1f fa fa 70 94 aa 30 17 c1 e0 14 be 27 d3 d8 82 e8 b3 df ef ca 90 1b 3d ed 4c 47 ad 9a 0d 60 f1 9c 50 f3 02 66 b6 3c f3 b8 82 b9 e9 72 de 3c 76 02 98 ba fe 6a 28 8e 1b 68 df 87 d9 07 be 4f 26 46 47 ec e9 74 52 c0 8f f7 69 36 93 51 f7 47 b1 28 51 ba 06 74 71 e6 ba 9c 82 a7 96 3a cd 40 f1 5a 73 04 6b bf 3f 40 a3 d5 14 d0 e7 b5 27 d5 de e9 b4 64 4c 2c 1d 16 02
            Data Ascii: G@hhVob%@N@'3KMo==B(*q7*lnFU.VA2.(2=~A|@4S+1LE>c;NHWkRp0'=LG`Pf<r<vj(hO&FGtRi6QG(Qtq:@Zsk?@'dL,
            2025-04-25 06:43:26 UTC1379INData Raw: af bf 3f 16 14 ed 19 41 db a0 00 93 a5 b4 07 24 9f af c7 dc ea a9 77 5a ea 34 b8 ee 9a 7d 11 47 2f 00 74 89 6c 83 21 29 04 75 ed ac 09 45 4d 87 84 7d d6 a9 b8 d0 f9 c2 b2 04 b3 e7 b5 83 c0 6b ce cf 85 5b d0 08 d0 e2 80 24 94 43 47 29 e2 4c 52 39 72 fc e1 7e b8 bd 4c fc 0b a8 6e 71 aa 0c f3 1e 79 58 ee 97 6d 99 74 e4 54 51 9f 02 78 9e 87 2e 7e e3 ef 74 98 e4 77 6a ff 0f 06 db c5 93 06 6b 47 d8 4b 4e 85 3a 49 33 a9 c8 9d df 23 ce 45 2c f8 3b e1 7b 9e ca c1 8b 23 23 2d ff d4 17 50 2c 17 8b f0 a4 d0 53 18 0a e5 9c 8c 94 4b 98 9d 9d c5 e8 f8 18 b2 99 3c ba 4e df 9b 9b 9b fb 95 f7 ff e0 0f fd 66 b4 5c 45 16 f8 56 16 88 00 3d ba 3f b6 2d 50 a9 dc 28 fc e1 1f fe fb 1f fb d4 9f 7d ea 0f 9c 6e 2f 51 ab d5 76 2a 7c 39 6b 9b 45 55 5c dc 99 47 0f b4 a8 05 3c 4c 2e 4c
            Data Ascii: ?A$wZ4}G/tl!)uEM}k[$CG)LR9r~LnqyXmtTQx.~twjkGKN:I3#E,;{##-P,SK<Nf\EV=?-P(}n/Qv*|9kEU\G<L.L
            2025-04-25 06:43:26 UTC1379INData Raw: 30 e7 bd d7 6c 37 50 a9 54 e5 5e e4 39 f3 41 4d f5 ff da 83 75 1a 74 3c 59 36 20 19 87 c0 41 24 9b 22 c5 82 31 5b ba 06 34 19 c3 fc bb 66 0c 74 5b 26 85 90 e8 a4 91 61 a2 d6 bd 68 24 a4 e2 48 25 94 e3 a1 a3 fe 64 2c 85 4c 36 85 b1 e1 12 7c 57 a5 15 74 ff 3c 9f 47 46 46 24 42 cf 15 86 d8 6e e9 ed df 7f e8 9f 7f e0 87 ff de ef fc d7 ce 21 7a ff c1 b6 40 04 e8 0f f6 f5 ff a6 b3 bf 74 e6 cc a1 df fd 83 df fb b2 ef 0d c6 a4 9d 2a e8 bf e6 62 cb 68 63 d0 77 90 ce 66 84 7a 1d b8 3e d6 36 36 70 e7 ce 1d 2c 2f 2f 4b e4 a1 e9 57 82 24 c1 42 e8 5e 03 e0 42 67 b1 ca d9 54 da ea 7a a6 3a 17 cd 4e af 2d 39 73 9d 67 24 28 4b fe da 1d 20 66 c7 65 c1 96 fe 5f db 42 36 9d d9 ce 6b 12 e4 4d cf 55 33 bd 5d 4f 16 5c 16 1d f1 75 2a dc 31 0f d0 eb b6 c1 f6 26 7e 4f a3 d9 46 32
            Data Ascii: 0l7PT^9AMut<Y6 A$"1[4ft[&ah$H%d,L6|Wt<GFF$Bn!z@t*bhcwfz>66p,//KW$B^BgTz:N-9sg$(K fe_B6kMU3]O\u*1&~OF2
            2025-04-25 06:43:26 UTC1379INData Raw: cc cf 2f 22 95 49 4b b1 18 8b 1a 19 75 33 22 65 3f be d8 14 2a 47 4c a6 c1 e9 a9 c1 b7 7c 24 18 69 fb 1e 72 c5 02 3a 54 d0 13 f6 45 75 01 ea 21 ab 99 64 02 cd 6e 4f 34 c8 1d 61 73 d4 b9 c5 63 ec d1 66 db d6 ce 00 56 db 36 e0 04 4e 5c 30 fa 5c b6 27 50 f2 5e 60 3b a1 d8 c5 54 ce 56 20 b7 2f c7 92 4a c5 c4 41 f4 24 35 a3 8e 8f f6 e3 e8 dd bd 7b f7 8b 33 28 2c 83 08 f7 18 58 59 5b 93 59 04 12 ed 73 5f 81 b1 c9 86 88 d3 69 ec 08 19 e9 7b 54 9c 45 a7 0b ce 26 e0 f6 3c 27 46 dc f9 ac aa dd e0 71 0a 9b d4 52 9a ef bc 2f 25 35 e1 f9 28 14 32 c2 5a 88 28 4c 8c 32 b4 69 11 a6 e1 77 15 0a 43 32 13 81 ff 67 77 45 a5 5a 13 5b b2 2d 93 db f1 fe e5 3d 40 5a 5e e5 cf b3 e2 38 94 47 c6 90 2d e4 11 4f a4 59 b7 e1 ed dd 73 e0 a7 df f3 43 3f f4 7f 44 cb 55 64 81 08 d0 a3 7b
            Data Ascii: /"IKu3"e?*GL|$ir:TEu!dnO4ascfV6N\0\'P^`;TV /JA$5{3(,XY[Ys_i{TE&<'FqR/%5(2Z(L2iwC2gwEZ[-=@Z^8G-OYsC?DUd{
            2025-04-25 06:43:26 UTC1379INData Raw: 87 1e 3e fe 53 cf be f7 03 11 a0 47 eb f5 b7 b4 40 04 e8 d1 0d 72 8f 05 08 e8 ff fa 77 7f ff af bc be 33 cd 85 8d 54 b0 e4 1e 07 03 b0 2f 9d f4 31 9f 9b f5 06 5a 9d 36 1c c3 92 dc ae ce 8d 8b 32 18 23 5b cf 47 36 9d c6 e4 e4 24 92 41 fb 19 81 b5 be 55 47 b5 5a 91 68 4f da db 2c 4b 7a c2 25 07 4d 3e d5 83 14 a8 11 5c 08 d6 5a a4 44 fa d6 63 71 01 4b 52 fd b5 46 07 a9 84 b5 3d 2c 24 11 4f 61 6a 72 52 d2 02 04 19 46 d9 b7 6f dd 40 bf 4d b0 ae e1 e4 89 63 52 d4 b4 be b9 01 3b ce 5c af 8b 4b d7 6f e1 d0 f1 93 a8 b7 da a8 6e ac 63 79 fe 0e 6c 6f 80 43 fb f6 62 b8 98 43 2e 93 46 2e 93 15 45 39 c7 f5 90 2d 0e e1 d2 b5 6b b8 7c e5 1a 1a ad 01 a6 a7 c7 e4 dc 28 91 ab 0b f7 18 6d 92 92 26 fd ba ba d1 96 e8 3d 9f b7 44 e1 8e 0b 76 3e a3 c0 8b a0 b8 51 6d e0 c6 e2 0a
            Data Ascii: >SG@rw3T/1Z62#[G6$AUGZhO,Kz%M>\ZDcqKRF=,$OajrRFo@McR;\KoncyloCbC.F.E9-k|(m&=Dv>Qm


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449731151.101.20.1594431128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-25 06:43:26 UTC632OUTGET /favicon.ico HTTP/1.1
            Host: pbs.twimg.com
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-25 06:43:27 UTC631INHTTP/1.1 200 OK
            Connection: close
            Content-Length: 549
            perf: 7402827104
            content-type: image/x-icon
            cache-control: max-age=3600, must-revalidate
            x-transaction-id: f3211f957a5cca5e
            timing-allow-origin: https://twitter.com, https://mobile.twitter.com
            strict-transport-security: max-age=631138519
            cross-origin-resource-policy: cross-origin
            X-Content-Type-Options: nosniff
            Accept-Ranges: bytes
            Date: Fri, 25 Apr 2025 06:43:27 GMT
            X-Cache: MISS, MISS
            Vary: Accept-Encoding
            x-tw-cdn: FT
            x-served-by: cache-pdk-kpdk1780123-PDK, cache-bfi-krnt7300052-BFI, cache-tw-ZZZ1
            Server-Timing: x-cache;desc=MISS, x-tw-cdn;desc=FT
            2025-04-25 06:43:27 UTC549INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 06 00 00 00 73 7a 7a f4 00 00 01 ec 49 44 41 54 78 01 ed 57 31 92 c2 30 0c 14 77 0d 25 74 94 3c 01 3a 4a 9e 40 49 07 25 1d f0 02 f2 03 f8 01 74 94 d0 52 d1 d2 f1 04 f8 01 a4 4c e5 cb 66 4e 19 9f a2 04 3b e4 26 0d 9a 11 93 6c 62 6b e3 95 64 d3 20 22 43 35 da 17 d5 6c 1f 02 19 02 87 c3 81 8c 31 aa 8f 46 23 f2 b5 eb f5 fa 72 ac b1 bd d5 6a 99 db ed 66 1e 8f 87 09 82 20 75 dc c3 bb dd ae 91 63 f2 7c bd 5e 1b 18 c6 17 bc 97 05 87 c3 61 32 70 b1 58 a4 d8 74 3a 4d b0 f3 f9 ec 14 7c b5 5a b9 04 d7 09 c0 37 9b 4d 32 41 af d7 4b b1 dd 6e 97 21 a6 f9 7c 3e 4f de 8b e5 74 21 ab 3f 60 29 e0 b8 96 f2 e4 49 01 c2 30 7b 5c 29 02 b6 14 d0 52 62 9a 14 20 c5 a4 3d 72 a5 f8 05 96 02 81 25 66 4b c1 c1
            Data Ascii: PNGIHDR szzIDATxW10w%t<:J@I%tRLfN;&lbkd "C5l1F#rjf uc|^a2pXt:M|Z7M2AKn!|>Ot!?`)I0{\)Rb =r%fK


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449733151.101.20.1594431128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-25 06:43:27 UTC388OUTGET /favicon.ico HTTP/1.1
            Host: pbs.twimg.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Sec-Fetch-Storage-Access: active
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-25 06:43:28 UTC629INHTTP/1.1 200 OK
            Connection: close
            Content-Length: 549
            perf: 7402827104
            content-type: image/x-icon
            cache-control: max-age=3600, must-revalidate
            x-transaction-id: f3211f957a5cca5e
            timing-allow-origin: https://twitter.com, https://mobile.twitter.com
            strict-transport-security: max-age=631138519
            cross-origin-resource-policy: cross-origin
            X-Content-Type-Options: nosniff
            Accept-Ranges: bytes
            Date: Fri, 25 Apr 2025 06:43:27 GMT
            X-Cache: MISS, HIT
            Vary: Accept-Encoding
            x-tw-cdn: FT
            x-served-by: cache-pdk-kpdk1780123-PDK, cache-bfi-krnt7300100-BFI, cache-tw-ZZZ1
            Server-Timing: x-cache;desc=HIT, x-tw-cdn;desc=FT
            2025-04-25 06:43:28 UTC549INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 06 00 00 00 73 7a 7a f4 00 00 01 ec 49 44 41 54 78 01 ed 57 31 92 c2 30 0c 14 77 0d 25 74 94 3c 01 3a 4a 9e 40 49 07 25 1d f0 02 f2 03 f8 01 74 94 d0 52 d1 d2 f1 04 f8 01 a4 4c e5 cb 66 4e 19 9f a2 04 3b e4 26 0d 9a 11 93 6c 62 6b e3 95 64 d3 20 22 43 35 da 17 d5 6c 1f 02 19 02 87 c3 81 8c 31 aa 8f 46 23 f2 b5 eb f5 fa 72 ac b1 bd d5 6a 99 db ed 66 1e 8f 87 09 82 20 75 dc c3 bb dd ae 91 63 f2 7c bd 5e 1b 18 c6 17 bc 97 05 87 c3 61 32 70 b1 58 a4 d8 74 3a 4d b0 f3 f9 ec 14 7c b5 5a b9 04 d7 09 c0 37 9b 4d 32 41 af d7 4b b1 dd 6e 97 21 a6 f9 7c 3e 4f de 8b e5 74 21 ab 3f 60 29 e0 b8 96 f2 e4 49 01 c2 30 7b 5c 29 02 b6 14 d0 52 62 9a 14 20 c5 a4 3d 72 a5 f8 05 96 02 81 25 66 4b c1 c1
            Data Ascii: PNGIHDR szzIDATxW10w%t<:J@I%tRLfN;&lbkd "C5l1F#rjf uc|^a2pXt:M|Z7M2AKn!|>Ot!?`)I0{\)Rb =r%fK


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:02:43:15
            Start date:25/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:02:43:18
            Start date:25/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2096,i,535839618176901581,15943560536411657664,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2240 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:02:43:24
            Start date:25/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pbs.twimg.com/media/GoH5SztXEAA5W_k?format=png&name=small"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly