Edit tour

Windows Analysis Report
https://vetero-air-spb.ru/wp-includes/page

Overview

General Information

Sample URL:https://vetero-air-spb.ru/wp-includes/page
Analysis ID:1675802
Infos:

Detection

Score:0
Range:0 - 100
Confidence:100%

Signatures

Detected suspicious crossdomain redirect

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5156 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2068,i,7477291261038422964,12150219640225577417,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6340 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vetero-air-spb.ru/wp-includes/page" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 142.250.217.132:443 -> 192.168.2.7:49691 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.236.16.69:443 -> 192.168.2.7:49692 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.236.16.69:443 -> 192.168.2.7:49693 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.7:49694 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.7:49699 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: vetero-air-spb.ru to https://pave-eg.com/pave/public/wp?ref=b701995f37
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: vetero-air-spb.ru to https://pave-eg.com/pave/public/wp?ref=2b6c42880c
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: pave-eg.com to https://additionalfeatures.digital/cap/
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.98.62
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.215.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.189.3
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /wp-includes/page HTTP/1.1Host: vetero-air-spb.ruConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/page/ HTTP/1.1Host: vetero-air-spb.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pave/public/wp?ref=b701995f37 HTTP/1.1Host: pave-eg.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pave/public/wp/?ref=b701995f37 HTTP/1.1Host: pave-eg.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/page/ HTTP/1.1Host: vetero-air-spb.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pave/public/wp?ref=2b6c42880c HTTP/1.1Host: pave-eg.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pave/public/wp/?ref=2b6c42880c HTTP/1.1Host: pave-eg.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/page/ HTTP/1.1Host: vetero-air-spb.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: vetero-air-spb.ru
Source: global trafficDNS traffic detected: DNS query: pave-eg.com
Source: global trafficDNS traffic detected: DNS query: additionalfeatures.digital
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownHTTPS traffic detected: 142.250.217.132:443 -> 192.168.2.7:49691 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.236.16.69:443 -> 192.168.2.7:49692 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.236.16.69:443 -> 192.168.2.7:49693 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.7:49694 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.7:49699 version: TLS 1.2
Source: classification engineClassification label: clean0.win@27/0@32/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2068,i,7477291261038422964,12150219640225577417,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vetero-air-spb.ru/wp-includes/page"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2068,i,7477291261038422964,12150219640225577417,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1675802 URL: https://vetero-air-spb.ru/w... Startdate: 28/04/2025 Architecture: WINDOWS Score: 0 14 additionalfeatures.digital 2->14 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.7, 443, 49672, 49691 unknown unknown 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 142.250.217.132, 443, 49691, 49717 GOOGLEUS United States 11->18 20 pave-eg.com 104.21.80.1, 443, 49694, 49695 CLOUDFLARENETUS United States 11->20 22 3 other IPs or domains 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://vetero-air-spb.ru/wp-includes/page0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://pave-eg.com/pave/public/wp?ref=b701995f370%Avira URL Cloudsafe
https://pave-eg.com/pave/public/wp/?ref=b701995f370%Avira URL Cloudsafe
http://vetero-air-spb.ru/wp-includes/page/0%Avira URL Cloudsafe
https://pave-eg.com/pave/public/wp/?ref=2b6c42880c0%Avira URL Cloudsafe
https://pave-eg.com/pave/public/wp?ref=2b6c42880c0%Avira URL Cloudsafe
https://vetero-air-spb.ru/wp-includes/page/0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.189.14
truefalse
    high
    pave-eg.com
    104.21.80.1
    truefalse
      unknown
      www.google.com
      142.250.217.132
      truefalse
        high
        vetero-air-spb.ru
        87.236.16.69
        truefalse
          unknown
          additionalfeatures.digital
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://pave-eg.com/pave/public/wp?ref=b701995f37false
            • Avira URL Cloud: safe
            unknown
            https://pave-eg.com/pave/public/wp/?ref=2b6c42880cfalse
            • Avira URL Cloud: safe
            unknown
            http://c.pki.goog/r/r4.crlfalse
              high
              http://vetero-air-spb.ru/wp-includes/page/false
              • Avira URL Cloud: safe
              unknown
              https://vetero-air-spb.ru/wp-includes/page/false
              • Avira URL Cloud: safe
              unknown
              https://pave-eg.com/pave/public/wp/?ref=b701995f37false
              • Avira URL Cloud: safe
              unknown
              https://pave-eg.com/pave/public/wp?ref=2b6c42880cfalse
              • Avira URL Cloud: safe
              unknown
              https://vetero-air-spb.ru/wp-includes/pagefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.217.132
                www.google.comUnited States
                15169GOOGLEUSfalse
                87.236.16.69
                vetero-air-spb.ruRussian Federation
                198610BEGET-ASRUfalse
                104.21.80.1
                pave-eg.comUnited States
                13335CLOUDFLARENETUSfalse
                IP
                192.168.2.7
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1675802
                Start date and time:2025-04-28 03:36:44 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 53s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://vetero-air-spb.ru/wp-includes/page
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:14
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@27/0@32/4
                • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, TextInputHost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.176.14, 142.250.176.3, 142.250.68.238, 142.250.141.84, 172.217.12.142, 192.178.49.206, 199.232.210.172, 142.250.189.14, 142.250.188.238, 142.251.40.35, 142.250.69.3, 4.175.87.197, 184.29.183.29
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: https://vetero-air-spb.ru/wp-includes/page
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 140
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Apr 28, 2025 03:37:34.416807890 CEST49673443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:34.416975975 CEST49675443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:34.416976929 CEST49674443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:41.401449919 CEST49677443192.168.2.72.18.98.62
                Apr 28, 2025 03:37:41.401506901 CEST4967680192.168.2.723.199.215.203
                Apr 28, 2025 03:37:43.920357943 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:43.920394897 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:43.920622110 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:43.920622110 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:43.920655012 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:44.026949883 CEST49673443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:44.026989937 CEST49675443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:44.027090073 CEST49674443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:44.234013081 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:44.234096050 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:44.235518932 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:44.235526085 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:44.235752106 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:44.276949883 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:45.652818918 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.652856112 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:45.653008938 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.653587103 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.653619051 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:45.653728008 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.654344082 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.654359102 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:45.654489994 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:45.654500961 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.295857906 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.295937061 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.297087908 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.297102928 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.297378063 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.297679901 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.299649000 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.299735069 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.300570965 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.300582886 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.301043034 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.341099977 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:46.344268084 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.997097969 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.997191906 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:46.997237921 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:47.000956059 CEST49692443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:47.000976086 CEST4434969287.236.16.69192.168.2.7
                Apr 28, 2025 03:37:47.009433031 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:47.052284956 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:47.897717953 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:47.897809982 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:47.897870064 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:47.898148060 CEST49693443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:47.898169994 CEST4434969387.236.16.69192.168.2.7
                Apr 28, 2025 03:37:48.085171938 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.085222960 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:48.085477114 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.085477114 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.085510969 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:48.400194883 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:48.400285006 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.402610064 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.402616978 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:48.402895927 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:48.403600931 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:48.444277048 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.223381042 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.223520994 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.223577976 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.227679014 CEST49694443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.227701902 CEST44349694104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.231690884 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.231730938 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.231867075 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.232008934 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.232023954 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.538002968 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.538269043 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.538281918 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:49.538577080 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:49.538582087 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:50.012362003 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:50.012465000 CEST44349695104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:50.012530088 CEST49695443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:50.681031942 CEST4969680192.168.2.787.236.16.69
                Apr 28, 2025 03:37:50.811532021 CEST4969780192.168.2.787.236.16.69
                Apr 28, 2025 03:37:50.997855902 CEST804969687.236.16.69192.168.2.7
                Apr 28, 2025 03:37:50.998428106 CEST4969680192.168.2.787.236.16.69
                Apr 28, 2025 03:37:50.998857021 CEST4969680192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.128583908 CEST804969787.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.128714085 CEST4969780192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.315649033 CEST804969687.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.315960884 CEST804969687.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.318984985 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.319029093 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.319205046 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.319367886 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.319380045 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.357371092 CEST4969680192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.959996939 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.960481882 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.960511923 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:51.960686922 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:51.960697889 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:52.623692989 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:52.623814106 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:52.623886108 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:52.624154091 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:52.624176025 CEST4434969887.236.16.69192.168.2.7
                Apr 28, 2025 03:37:52.624191046 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:52.624221087 CEST49698443192.168.2.787.236.16.69
                Apr 28, 2025 03:37:52.626115084 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:52.626154900 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:52.626239061 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:52.626375914 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:52.626388073 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:52.961015940 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:52.961085081 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:52.961585045 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:52.961595058 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:52.961808920 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:52.962181091 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.004270077 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:53.743002892 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:53.743124008 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:53.743218899 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.743551970 CEST49699443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.743567944 CEST44349699104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:53.746206999 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.746263981 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:53.746362925 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.746507883 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:53.746522903 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.053576946 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.054615021 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:54.054641008 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.054768085 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:54.054774046 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.223099947 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:54.223160028 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:54.223222971 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:54.609268904 CEST49691443192.168.2.7142.250.217.132
                Apr 28, 2025 03:37:54.609297991 CEST44349691142.250.217.132192.168.2.7
                Apr 28, 2025 03:37:54.893146992 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.893239975 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:54.893402100 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:54.893908978 CEST49700443192.168.2.7104.21.80.1
                Apr 28, 2025 03:37:54.893923044 CEST44349700104.21.80.1192.168.2.7
                Apr 28, 2025 03:37:55.393505096 CEST49672443192.168.2.72.23.227.208
                Apr 28, 2025 03:37:55.393558979 CEST443496722.23.227.208192.168.2.7
                Apr 28, 2025 03:37:56.892504930 CEST4970580192.168.2.7142.250.189.3
                Apr 28, 2025 03:37:57.040499926 CEST8049705142.250.189.3192.168.2.7
                Apr 28, 2025 03:37:57.040590048 CEST4970580192.168.2.7142.250.189.3
                Apr 28, 2025 03:37:57.040858030 CEST4970580192.168.2.7142.250.189.3
                Apr 28, 2025 03:37:57.188287020 CEST8049705142.250.189.3192.168.2.7
                Apr 28, 2025 03:37:57.188756943 CEST8049705142.250.189.3192.168.2.7
                Apr 28, 2025 03:37:57.229779005 CEST4970580192.168.2.7142.250.189.3
                Apr 28, 2025 03:38:08.621395111 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:08.933361053 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:09.542745113 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:10.745834112 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:11.351025105 CEST804969787.236.16.69192.168.2.7
                Apr 28, 2025 03:38:11.351105928 CEST4969780192.168.2.787.236.16.69
                Apr 28, 2025 03:38:11.607480049 CEST4969780192.168.2.787.236.16.69
                Apr 28, 2025 03:38:11.923996925 CEST804969787.236.16.69192.168.2.7
                Apr 28, 2025 03:38:13.152340889 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:17.187150955 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:17.496025085 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:17.964777946 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:18.106492996 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:19.306830883 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:21.714240074 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:26.526648045 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:27.573537111 CEST49671443192.168.2.7204.79.197.203
                Apr 28, 2025 03:38:36.136138916 CEST49678443192.168.2.720.189.173.15
                Apr 28, 2025 03:38:36.323616982 CEST4969680192.168.2.787.236.16.69
                Apr 28, 2025 03:38:36.640685081 CEST804969687.236.16.69192.168.2.7
                Apr 28, 2025 03:38:43.840409994 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:43.840456963 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:43.840523958 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:43.840686083 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:43.840698957 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:44.147378922 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:44.147880077 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:44.147893906 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:54.147195101 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:54.147264004 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:54.147562027 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:54.606585979 CEST49717443192.168.2.7142.250.217.132
                Apr 28, 2025 03:38:54.606610060 CEST44349717142.250.217.132192.168.2.7
                Apr 28, 2025 03:38:57.511040926 CEST4970580192.168.2.7142.250.189.3
                Apr 28, 2025 03:38:57.661788940 CEST8049705142.250.189.3192.168.2.7
                Apr 28, 2025 03:38:57.661859989 CEST4970580192.168.2.7142.250.189.3
                TimestampSource PortDest PortSource IPDest IP
                Apr 28, 2025 03:37:39.307888031 CEST53643241.1.1.1192.168.2.7
                Apr 28, 2025 03:37:39.411320925 CEST53621771.1.1.1192.168.2.7
                Apr 28, 2025 03:37:40.590429068 CEST53568451.1.1.1192.168.2.7
                Apr 28, 2025 03:37:41.909110069 CEST53622721.1.1.1192.168.2.7
                Apr 28, 2025 03:37:43.778306007 CEST5890253192.168.2.71.1.1.1
                Apr 28, 2025 03:37:43.778497934 CEST6068053192.168.2.71.1.1.1
                Apr 28, 2025 03:37:43.919086933 CEST53606801.1.1.1192.168.2.7
                Apr 28, 2025 03:37:43.919370890 CEST53589021.1.1.1192.168.2.7
                Apr 28, 2025 03:37:44.959348917 CEST6324353192.168.2.71.1.1.1
                Apr 28, 2025 03:37:44.959491014 CEST5925953192.168.2.71.1.1.1
                Apr 28, 2025 03:37:45.610446930 CEST53592591.1.1.1192.168.2.7
                Apr 28, 2025 03:37:45.651837111 CEST53632431.1.1.1192.168.2.7
                Apr 28, 2025 03:37:47.900513887 CEST5644353192.168.2.71.1.1.1
                Apr 28, 2025 03:37:47.900681019 CEST5807753192.168.2.71.1.1.1
                Apr 28, 2025 03:37:48.074981928 CEST53580771.1.1.1192.168.2.7
                Apr 28, 2025 03:37:48.084515095 CEST53564431.1.1.1192.168.2.7
                Apr 28, 2025 03:37:50.017678976 CEST5990253192.168.2.71.1.1.1
                Apr 28, 2025 03:37:50.017888069 CEST5311353192.168.2.71.1.1.1
                Apr 28, 2025 03:37:50.663357019 CEST53599021.1.1.1192.168.2.7
                Apr 28, 2025 03:37:50.680522919 CEST53531131.1.1.1192.168.2.7
                Apr 28, 2025 03:37:54.896138906 CEST5650953192.168.2.71.1.1.1
                Apr 28, 2025 03:37:54.896472931 CEST5028253192.168.2.71.1.1.1
                Apr 28, 2025 03:37:55.048372030 CEST53565091.1.1.1192.168.2.7
                Apr 28, 2025 03:37:55.054364920 CEST53502821.1.1.1192.168.2.7
                Apr 28, 2025 03:37:55.055088043 CEST6476253192.168.2.71.1.1.1
                Apr 28, 2025 03:37:55.215028048 CEST53647621.1.1.1192.168.2.7
                Apr 28, 2025 03:37:55.253066063 CEST5754953192.168.2.78.8.8.8
                Apr 28, 2025 03:37:55.254232883 CEST5460153192.168.2.71.1.1.1
                Apr 28, 2025 03:37:55.404664040 CEST53546011.1.1.1192.168.2.7
                Apr 28, 2025 03:37:55.409440041 CEST53575498.8.8.8192.168.2.7
                Apr 28, 2025 03:37:56.272346020 CEST5807653192.168.2.71.1.1.1
                Apr 28, 2025 03:37:56.272689104 CEST6383653192.168.2.71.1.1.1
                Apr 28, 2025 03:37:56.418724060 CEST53638361.1.1.1192.168.2.7
                Apr 28, 2025 03:37:56.427141905 CEST53580761.1.1.1192.168.2.7
                Apr 28, 2025 03:37:58.881382942 CEST53559551.1.1.1192.168.2.7
                Apr 28, 2025 03:38:01.444628000 CEST5910153192.168.2.71.1.1.1
                Apr 28, 2025 03:38:01.445430040 CEST5796853192.168.2.71.1.1.1
                Apr 28, 2025 03:38:01.599447012 CEST53579681.1.1.1192.168.2.7
                Apr 28, 2025 03:38:01.645560026 CEST53591011.1.1.1192.168.2.7
                Apr 28, 2025 03:38:01.646409988 CEST5911253192.168.2.71.1.1.1
                Apr 28, 2025 03:38:01.787321091 CEST53591121.1.1.1192.168.2.7
                Apr 28, 2025 03:38:07.837532043 CEST5183853192.168.2.71.1.1.1
                Apr 28, 2025 03:38:07.837697983 CEST5392853192.168.2.71.1.1.1
                Apr 28, 2025 03:38:07.984782934 CEST53539281.1.1.1192.168.2.7
                Apr 28, 2025 03:38:07.995893002 CEST53518381.1.1.1192.168.2.7
                Apr 28, 2025 03:38:07.997051954 CEST6230153192.168.2.71.1.1.1
                Apr 28, 2025 03:38:08.138753891 CEST53623011.1.1.1192.168.2.7
                Apr 28, 2025 03:38:08.171839952 CEST5208553192.168.2.71.1.1.1
                Apr 28, 2025 03:38:08.172141075 CEST5892453192.168.2.78.8.8.8
                Apr 28, 2025 03:38:08.322237968 CEST53520851.1.1.1192.168.2.7
                Apr 28, 2025 03:38:08.329726934 CEST53589248.8.8.8192.168.2.7
                Apr 28, 2025 03:38:17.654289961 CEST53535531.1.1.1192.168.2.7
                Apr 28, 2025 03:38:19.717782974 CEST5831153192.168.2.71.1.1.1
                Apr 28, 2025 03:38:19.717969894 CEST6344753192.168.2.71.1.1.1
                Apr 28, 2025 03:38:19.865575075 CEST53583111.1.1.1192.168.2.7
                Apr 28, 2025 03:38:19.881042957 CEST53634471.1.1.1192.168.2.7
                Apr 28, 2025 03:38:19.885473013 CEST6009053192.168.2.71.1.1.1
                Apr 28, 2025 03:38:20.043869019 CEST53600901.1.1.1192.168.2.7
                Apr 28, 2025 03:38:20.062978029 CEST5374453192.168.2.71.1.1.1
                Apr 28, 2025 03:38:20.063266039 CEST5312553192.168.2.78.8.8.8
                Apr 28, 2025 03:38:20.220295906 CEST53531258.8.8.8192.168.2.7
                Apr 28, 2025 03:38:20.244796038 CEST53537441.1.1.1192.168.2.7
                Apr 28, 2025 03:38:32.636961937 CEST6130653192.168.2.71.1.1.1
                Apr 28, 2025 03:38:32.790997982 CEST53613061.1.1.1192.168.2.7
                Apr 28, 2025 03:38:39.230293989 CEST53633041.1.1.1192.168.2.7
                Apr 28, 2025 03:38:40.496179104 CEST53621501.1.1.1192.168.2.7
                Apr 28, 2025 03:38:42.475965977 CEST53566371.1.1.1192.168.2.7
                Apr 28, 2025 03:38:50.110769987 CEST5098453192.168.2.71.1.1.1
                Apr 28, 2025 03:38:50.110985994 CEST6213153192.168.2.71.1.1.1
                Apr 28, 2025 03:38:50.263417959 CEST53621311.1.1.1192.168.2.7
                Apr 28, 2025 03:38:50.267131090 CEST53509841.1.1.1192.168.2.7
                Apr 28, 2025 03:38:50.268017054 CEST5827453192.168.2.71.1.1.1
                Apr 28, 2025 03:38:50.417656898 CEST53582741.1.1.1192.168.2.7
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 28, 2025 03:37:43.778306007 CEST192.168.2.71.1.1.10x84f0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:43.778497934 CEST192.168.2.71.1.1.10x5f32Standard query (0)www.google.com65IN (0x0001)false
                Apr 28, 2025 03:37:44.959348917 CEST192.168.2.71.1.1.10x57e0Standard query (0)vetero-air-spb.ruA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:44.959491014 CEST192.168.2.71.1.1.10x99f4Standard query (0)vetero-air-spb.ru65IN (0x0001)false
                Apr 28, 2025 03:37:47.900513887 CEST192.168.2.71.1.1.10x1b14Standard query (0)pave-eg.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:47.900681019 CEST192.168.2.71.1.1.10xf8baStandard query (0)pave-eg.com65IN (0x0001)false
                Apr 28, 2025 03:37:50.017678976 CEST192.168.2.71.1.1.10x9207Standard query (0)vetero-air-spb.ruA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:50.017888069 CEST192.168.2.71.1.1.10xd966Standard query (0)vetero-air-spb.ru65IN (0x0001)false
                Apr 28, 2025 03:37:54.896138906 CEST192.168.2.71.1.1.10x9717Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:54.896472931 CEST192.168.2.71.1.1.10x6ebcStandard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:37:55.055088043 CEST192.168.2.71.1.1.10xde04Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.253066063 CEST192.168.2.78.8.8.80x278eStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.254232883 CEST192.168.2.71.1.1.10xc9edStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:56.272346020 CEST192.168.2.71.1.1.10x7d41Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:56.272689104 CEST192.168.2.71.1.1.10xa64dStandard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:38:01.444628000 CEST192.168.2.71.1.1.10x82d1Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:01.445430040 CEST192.168.2.71.1.1.10xe1f9Standard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:38:01.646409988 CEST192.168.2.71.1.1.10xa50dStandard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:07.837532043 CEST192.168.2.71.1.1.10x36dbStandard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:07.837697983 CEST192.168.2.71.1.1.10xd24dStandard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:38:07.997051954 CEST192.168.2.71.1.1.10xafceStandard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:08.171839952 CEST192.168.2.71.1.1.10x4abaStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:08.172141075 CEST192.168.2.78.8.8.80xf6cbStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:19.717782974 CEST192.168.2.71.1.1.10xad43Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:19.717969894 CEST192.168.2.71.1.1.10xe58Standard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:38:19.885473013 CEST192.168.2.71.1.1.10xe157Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:20.062978029 CEST192.168.2.71.1.1.10xe352Standard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:20.063266039 CEST192.168.2.78.8.8.80xcc9fStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:32.636961937 CEST192.168.2.71.1.1.10x340cStandard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:50.110769987 CEST192.168.2.71.1.1.10x7961Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:50.110985994 CEST192.168.2.71.1.1.10x28f8Standard query (0)additionalfeatures.digital65IN (0x0001)false
                Apr 28, 2025 03:38:50.268017054 CEST192.168.2.71.1.1.10xbdc7Standard query (0)additionalfeatures.digitalA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 28, 2025 03:37:43.919086933 CEST1.1.1.1192.168.2.70x5f32No error (0)www.google.com65IN (0x0001)false
                Apr 28, 2025 03:37:43.919370890 CEST1.1.1.1192.168.2.70x84f0No error (0)www.google.com142.250.217.132A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:45.651837111 CEST1.1.1.1192.168.2.70x57e0No error (0)vetero-air-spb.ru87.236.16.69A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.074981928 CEST1.1.1.1192.168.2.70xf8baNo error (0)pave-eg.com65IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.80.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.112.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.48.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.64.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.16.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.32.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:48.084515095 CEST1.1.1.1192.168.2.70x1b14No error (0)pave-eg.com104.21.96.1A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:50.663357019 CEST1.1.1.1192.168.2.70x9207No error (0)vetero-air-spb.ru87.236.16.69A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.048372030 CEST1.1.1.1192.168.2.70x9717Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.054364920 CEST1.1.1.1192.168.2.70x6ebcName error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:37:55.215028048 CEST1.1.1.1192.168.2.70xde04Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.404664040 CEST1.1.1.1192.168.2.70xc9edNo error (0)google.com142.250.189.14A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:55.409440041 CEST8.8.8.8192.168.2.70x278eNo error (0)google.com142.250.69.14A (IP address)IN (0x0001)false
                Apr 28, 2025 03:37:56.418724060 CEST1.1.1.1192.168.2.70xa64dName error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:37:56.427141905 CEST1.1.1.1192.168.2.70x7d41Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:01.599447012 CEST1.1.1.1192.168.2.70xe1f9Name error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:38:01.645560026 CEST1.1.1.1192.168.2.70x82d1Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:01.787321091 CEST1.1.1.1192.168.2.70xa50dName error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:07.984782934 CEST1.1.1.1192.168.2.70xd24dName error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:38:07.995893002 CEST1.1.1.1192.168.2.70x36dbName error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:08.138753891 CEST1.1.1.1192.168.2.70xafceName error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:08.322237968 CEST1.1.1.1192.168.2.70x4abaNo error (0)google.com142.251.40.46A (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:08.329726934 CEST8.8.8.8192.168.2.70xf6cbNo error (0)google.com142.250.69.14A (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:19.865575075 CEST1.1.1.1192.168.2.70xad43Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:19.881042957 CEST1.1.1.1192.168.2.70xe58Name error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:38:20.043869019 CEST1.1.1.1192.168.2.70xe157Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:20.220295906 CEST8.8.8.8192.168.2.70xcc9fNo error (0)google.com142.250.69.14A (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:20.244796038 CEST1.1.1.1192.168.2.70xe352No error (0)google.com142.251.40.46A (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:32.790997982 CEST1.1.1.1192.168.2.70x340cName error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:50.263417959 CEST1.1.1.1192.168.2.70x28f8Name error (3)additionalfeatures.digitalnonenone65IN (0x0001)false
                Apr 28, 2025 03:38:50.267131090 CEST1.1.1.1192.168.2.70x7961Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                Apr 28, 2025 03:38:50.417656898 CEST1.1.1.1192.168.2.70xbdc7Name error (3)additionalfeatures.digitalnonenoneA (IP address)IN (0x0001)false
                • vetero-air-spb.ru
                • pave-eg.com
                • c.pki.goog
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.74969687.236.16.69805156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Apr 28, 2025 03:37:50.998857021 CEST449OUTGET /wp-includes/page/ HTTP/1.1
                Host: vetero-air-spb.ru
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Apr 28, 2025 03:37:51.315960884 CEST431INHTTP/1.1 301 Moved Permanently
                Server: nginx-reuseport/1.21.1
                Date: Mon, 28 Apr 2025 01:37:51 GMT
                Content-Type: text/html
                Content-Length: 179
                Connection: keep-alive
                Keep-Alive: timeout=30
                Location: https://vetero-air-spb.ru/wp-includes/page/
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2d 72 65 75 73 65 70 6f 72 74 2f 31 2e 32 31 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx-reuseport/1.21.1</center></body></html>
                Apr 28, 2025 03:38:36.323616982 CEST6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination Port
                1192.168.2.749705142.250.189.380
                TimestampBytes transferredDirectionData
                Apr 28, 2025 03:37:57.040858030 CEST200OUTGET /r/r4.crl HTTP/1.1
                Cache-Control: max-age = 3000
                Connection: Keep-Alive
                Accept: */*
                If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                User-Agent: Microsoft-CryptoAPI/10.0
                Host: c.pki.goog
                Apr 28, 2025 03:37:57.188756943 CEST1243INHTTP/1.1 200 OK
                Accept-Ranges: bytes
                Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                Cross-Origin-Resource-Policy: cross-origin
                Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                Content-Length: 530
                X-Content-Type-Options: nosniff
                Server: sffe
                X-XSS-Protection: 0
                Date: Mon, 28 Apr 2025 01:17:13 GMT
                Expires: Mon, 28 Apr 2025 02:07:13 GMT
                Cache-Control: public, max-age=3000
                Age: 1244
                Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                Content-Type: application/pkix-crl
                Vary: Accept-Encoding
                Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.74969287.236.16.694435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:46 UTC683OUTGET /wp-includes/page HTTP/1.1
                Host: vetero-air-spb.ru
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:46 UTC242INHTTP/1.1 301 Moved Permanently
                Server: nginx-reuseport/1.21.1
                Date: Mon, 28 Apr 2025 01:37:46 GMT
                Content-Type: text/html; charset=iso-8859-1
                Content-Length: 331
                Connection: close
                Location: http://vetero-air-spb.ru/wp-includes/page/
                2025-04-28 01:37:46 UTC331INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 76 65 74 65 72 6f 2d 61 69 72 2d 73 70 62 2e 72 75 2f 77 70 2d 69 6e 63 6c 75 64 65 73 2f 70 61 67 65 2f 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65
                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="http://vetero-air-spb.ru/wp-includes/page/">here</a>.</p><hr><address>Apache


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.74969387.236.16.694435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:47 UTC684OUTGET /wp-includes/page/ HTTP/1.1
                Host: vetero-air-spb.ru
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:47 UTC258INHTTP/1.1 302 Found
                Server: nginx-reuseport/1.21.1
                Date: Mon, 28 Apr 2025 01:37:47 GMT
                Content-Type: text/html; charset=UTF-8
                Content-Length: 234
                Connection: close
                X-Powered-By: PHP/7.4.33
                Location: https://pave-eg.com/pave/public/wp?ref=b701995f37
                2025-04-28 01:37:47 UTC234INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 27 72 65 66 72 65 73 68 27 20 63 6f 6e 74 65 6e 74 3d 27 30 3b 75 72 6c 3d 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 3f 72 65 66 3d 62 37 30 31 39 39 35 66 33 37 27 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 49 66 20 79 6f 75 20 61 72 65 20 6e 6f 74 20 72 65 64 69 72 65 63 74 65 64 2c 20 3c 61 20 68 72 65 66 3d 27 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 3f 72 65 66 3d 62 37 30 31 39 39 35 66 33 37 27 3e 63 6c 69 63 6b 20 68 65 72 65 3c 2f 61 3e 2e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                Data Ascii: <html><head><meta http-equiv='refresh' content='0;url=https://pave-eg.com/pave/public/wp?ref=b701995f37'></head><body>If you are not redirected, <a href='https://pave-eg.com/pave/public/wp?ref=b701995f37'>click here</a>.</body></html>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.749694104.21.80.14435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:48 UTC690OUTGET /pave/public/wp?ref=b701995f37 HTTP/1.1
                Host: pave-eg.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:49 UTC331INHTTP/1.1 301 Moved Permanently
                Date: Mon, 28 Apr 2025 01:37:49 GMT
                Content-Type: text/html; charset=iso-8859-1
                Transfer-Encoding: chunked
                Connection: close
                Server: cloudflare
                Location: https://pave-eg.com/pave/public/wp/?ref=b701995f37
                Cf-Cache-Status: DYNAMIC
                CF-RAY: 9372d627191e522b-LAX
                alt-svc: h3=":443"; ma=86400
                2025-04-28 01:37:49 UTC265INData Raw: 31 30 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 2f 3f 72 65 66 3d 62 37 30 31 39 39 35 66 33 37 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e
                Data Ascii: 102<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://pave-eg.com/pave/public/wp/?ref=b701995f37">here</a>.</p></body>
                2025-04-28 01:37:49 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.749695104.21.80.14435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:49 UTC691OUTGET /pave/public/wp/?ref=b701995f37 HTTP/1.1
                Host: pave-eg.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.74969887.236.16.694435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:51 UTC684OUTGET /wp-includes/page/ HTTP/1.1
                Host: vetero-air-spb.ru
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:52 UTC258INHTTP/1.1 302 Found
                Server: nginx-reuseport/1.21.1
                Date: Mon, 28 Apr 2025 01:37:52 GMT
                Content-Type: text/html; charset=UTF-8
                Content-Length: 234
                Connection: close
                X-Powered-By: PHP/7.4.33
                Location: https://pave-eg.com/pave/public/wp?ref=2b6c42880c
                2025-04-28 01:37:52 UTC234INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 27 72 65 66 72 65 73 68 27 20 63 6f 6e 74 65 6e 74 3d 27 30 3b 75 72 6c 3d 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 3f 72 65 66 3d 32 62 36 63 34 32 38 38 30 63 27 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 49 66 20 79 6f 75 20 61 72 65 20 6e 6f 74 20 72 65 64 69 72 65 63 74 65 64 2c 20 3c 61 20 68 72 65 66 3d 27 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 3f 72 65 66 3d 32 62 36 63 34 32 38 38 30 63 27 3e 63 6c 69 63 6b 20 68 65 72 65 3c 2f 61 3e 2e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                Data Ascii: <html><head><meta http-equiv='refresh' content='0;url=https://pave-eg.com/pave/public/wp?ref=2b6c42880c'></head><body>If you are not redirected, <a href='https://pave-eg.com/pave/public/wp?ref=2b6c42880c'>click here</a>.</body></html>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.749699104.21.80.14435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:52 UTC690OUTGET /pave/public/wp?ref=2b6c42880c HTTP/1.1
                Host: pave-eg.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:53 UTC331INHTTP/1.1 301 Moved Permanently
                Date: Mon, 28 Apr 2025 01:37:53 GMT
                Content-Type: text/html; charset=iso-8859-1
                Transfer-Encoding: chunked
                Connection: close
                Server: cloudflare
                Location: https://pave-eg.com/pave/public/wp/?ref=2b6c42880c
                Cf-Cache-Status: DYNAMIC
                CF-RAY: 9372d643cd11f08d-DFW
                alt-svc: h3=":443"; ma=86400
                2025-04-28 01:37:53 UTC265INData Raw: 31 30 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 70 61 76 65 2d 65 67 2e 63 6f 6d 2f 70 61 76 65 2f 70 75 62 6c 69 63 2f 77 70 2f 3f 72 65 66 3d 32 62 36 63 34 32 38 38 30 63 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e
                Data Ascii: 102<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://pave-eg.com/pave/public/wp/?ref=2b6c42880c">here</a>.</p></body>
                2025-04-28 01:37:53 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.749700104.21.80.14435156C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-28 01:37:54 UTC691OUTGET /pave/public/wp/?ref=2b6c42880c HTTP/1.1
                Host: pave-eg.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-28 01:37:54 UTC303INHTTP/1.1 302 Found
                Date: Mon, 28 Apr 2025 01:37:54 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                Server: cloudflare
                Location: https://AdditionalFeatures.digital/cap/
                Cf-Cache-Status: DYNAMIC
                CF-RAY: 9372d64a7aa752bf-LAX
                alt-svc: h3=":443"; ma=86400
                2025-04-28 01:37:54 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:0
                Start time:21:37:36
                Start date:27/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff778810000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:21:37:37
                Start date:27/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2068,i,7477291261038422964,12150219640225577417,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2116 /prefetch:3
                Imagebase:0x7ff778810000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:5
                Start time:21:37:43
                Start date:27/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vetero-air-spb.ru/wp-includes/page"
                Imagebase:0x7ff778810000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly