Create Interactive Tour

Windows Analysis Report
https://kutt.it/t6killx

Overview

General Information

Sample URL:https://kutt.it/t6killx
Analysis ID:686621
Infos:

Detection

HTMLPhisher
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Misleading page title found
Yara detected HtmlPhish10
Multi AV Scanner detection for submitted file
HTML body contains low number of good links
Suspicious form URL found
No HTML title found

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is start
  • chrome.exe (PID: 928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kutt.it/t6killx MD5: 74859601FB4BEEA84B40D874CCB56CAB)
    • chrome.exe (PID: 796 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,11702765727564047898,12252251064509017740,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 /prefetch:8 MD5: 74859601FB4BEEA84B40D874CCB56CAB)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
25855.0.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    58601.1.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: https://kutt.it/t6killxAvira URL Cloud: detection malicious, Label: phishing
      Source: https://kutt.it/t6killxSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
      Source: https://kutt.it/t6killxVirustotal: Detection: 6%Perma Link

      Phishing

      barindex
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Page Title: American Express : Online Services : Log in
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Page Title: American Express : Online Services : Log in
      Source: Yara matchFile source: 25855.0.pages.csv, type: HTML
      Source: Yara matchFile source: 58601.1.pages.csv, type: HTML
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: Number of links: 0
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: Number of links: 0
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: Number of links: 0
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: Number of links: 0
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: Form action: index2.php
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: Form action: index2.php
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: Form action: login.php
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: Form action: login.php
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: HTML title missing
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: HTML title missing
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: HTML title missing
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: HTML title missing
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: No <meta name="author".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: No <meta name="author".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: No <meta name="author".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: No <meta name="author".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: No <meta name="copyright".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/HTTP Parser: No <meta name="copyright".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: No <meta name="copyright".. found
      Source: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpHTTP Parser: No <meta name="copyright".. found
      Source: unknownHTTPS traffic detected: 5.101.152.35:443 -> 192.168.2.3:61957 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 5.101.152.35:443 -> 192.168.2.3:61956 version: TLS 1.2
      Source: unknownDNS traffic detected: queries for: kutt.it
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49523
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63292
      Source: unknownNetwork traffic detected: HTTP traffic on port 52628 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53867
      Source: unknownNetwork traffic detected: HTTP traffic on port 59863 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61356 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61958 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58597 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57606
      Source: unknownNetwork traffic detected: HTTP traffic on port 49523 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61956 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61402
      Source: unknownNetwork traffic detected: HTTP traffic on port 61401 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61403
      Source: unknownNetwork traffic detected: HTTP traffic on port 60670 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60670
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53294
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61641
      Source: unknownNetwork traffic detected: HTTP traffic on port 61403 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61401
      Source: unknownNetwork traffic detected: HTTP traffic on port 57606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55715
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50703
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52628
      Source: unknownNetwork traffic detected: HTTP traffic on port 53867 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57218 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57218
      Source: unknownNetwork traffic detected: HTTP traffic on port 61957 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61959 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53294 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63292 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58597
      Source: unknownNetwork traffic detected: HTTP traffic on port 57022 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61402 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 61641 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59863
      Source: unknownNetwork traffic detected: HTTP traffic on port 50703 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61956
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61957
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61958
      Source: unknownNetwork traffic detected: HTTP traffic on port 55715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61959
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57022
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61356
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=92.0.4515.107&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-92.0.4515.107Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /t6killx HTTP/1.1Host: kutt.itConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/ HTTP/1.1Host: internet-cheboksary.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/head.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/main.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/sign.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/footer.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/favicon.ico HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/head.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/favicon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/main.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/footer.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/headsd.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/maind.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/logins.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/down.PNG HTTP/1.1Host: internet-cheboksary.ruConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mycounter=Checked
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/maind.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/headsd.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: global trafficHTTP traffic detected: GET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/down.PNG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: internet-cheboksary.ru
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: ;https://www.facebook.com/sharer/sharer.php?u=%(escaped_url) equals www.facebook.com (Facebook)
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: Nhttp://www.linkedin.com/shareArticle?url=%(escaped_url)&title=%(escaped_title) equals www.linkedin.com (Linkedin)
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: http://pinterest.com/pin/create/button/?url=%(escaped_url)&description=%(escaped_title)
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: http://reddit.com/submit?url=%(escaped_url)&title=%(escaped_title)
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: http://www.linkedin.com/shareArticle?url=%(escaped_url)&title=%(escaped_title)
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://accounts.google.com
      Source: craw_window.js.1.drString found in binary or memory: https://accounts.google.com/MergeSession
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://apis.google.com
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://clients2.google.com
      Source: manifest.json.1.drString found in binary or memory: https://clients2.google.com/service/update2/crx
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://clients2.googleusercontent.com
      Source: 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://content-autofill.googleapis.com
      Source: craw_background.js.1.dr, craw_window.js.1.drString found in binary or memory: https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
      Source: 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://kutt.it
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://ogs.google.com
      Source: manifest.json.1.dr, craw_window.js.1.drString found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
      Source: manifest.json.1.dr, craw_window.js.1.drString found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://ssl.gstatic.com
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: https://twitter.com/intent/tweet?url=%(escaped_url)&text=%(escaped_title)
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://update.googleapis.com
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: https://vk.com/share.php?url=%(escaped_url)&title=%(escaped_title)
      Source: desktop_sharing_hub.pb.1.drString found in binary or memory: https://web.whatsapp.com/send?text=%(escaped_url)
      Source: craw_background.js.1.dr, craw_window.js.1.drString found in binary or memory: https://www-googleapis-staging.sandbox.google.com
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://www.google.com
      Source: manifest.json.1.drString found in binary or memory: https://www.google.com/
      Source: craw_window.js.1.drString found in binary or memory: https://www.google.com/accounts/OAuthLogin?issueuberauth=1
      Source: craw_window.js.1.drString found in binary or memory: https://www.google.com/images/cleardot.gif
      Source: craw_window.js.1.drString found in binary or memory: https://www.google.com/images/dot2.gif
      Source: craw_window.js.1.drString found in binary or memory: https://www.google.com/images/x2.gif
      Source: craw_background.js.1.drString found in binary or memory: https://www.google.com/intl/en-US/chrome/blank.html
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.dr, craw_background.js.1.dr, craw_window.js.1.drString found in binary or memory: https://www.googleapis.com
      Source: manifest.json.1.drString found in binary or memory: https://www.googleapis.com/
      Source: manifest.json.1.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore
      Source: manifest.json.1.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
      Source: manifest.json.1.drString found in binary or memory: https://www.googleapis.com/auth/sierra
      Source: manifest.json.1.drString found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
      Source: dd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drString found in binary or memory: https://www.gstatic.com
      Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620
      Source: unknownHTTPS traffic detected: 5.101.152.35:443 -> 192.168.2.3:61957 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 5.101.152.35:443 -> 192.168.2.3:61956 version: TLS 1.2
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Temp\56292729-c70f-43d4-843f-8804977e66f6.tmpJump to behavior
      Source: classification engineClassification label: mal72.phis.win@29/119@5/7
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kutt.it/t6killx
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,11702765727564047898,12252251064509017740,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,11702765727564047898,12252251064509017740,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62FF3968-3A0.pmaJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      1
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
      Encrypted Channel
      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
      Non-Application Layer Protocol
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
      Obfuscated Files or Information
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
      Application Layer Protocol
      Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
      Ingress Tool Transfer
      SIM Card SwapCarrier Billing Fraud
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 686621 URL: https://kutt.it/t6killx Startdate: 19/08/2022 Architecture: WINDOWS Score: 72 13 internet-cheboksary.ru 2->13 25 Antivirus / Scanner detection for submitted sample 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Misleading page title found 2->29 31 Yara detected HtmlPhish10 2->31 7 chrome.exe 19 268 2->7         started        signatures3 process4 dnsIp5 15 192.168.2.1 unknown unknown 7->15 17 239.255.255.250 unknown Reserved 7->17 10 chrome.exe 18 7->10         started        process6 dnsIp7 19 clients.l.google.com 142.250.185.238, 443, 50703 GOOGLEUS United States 10->19 21 accounts.google.com 142.250.186.77, 443, 52628 GOOGLEUS United States 10->21 23 4 other IPs or domains 10->23

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      https://kutt.it/t6killx7%VirustotalBrowse
      https://kutt.it/t6killx100%Avira URL Cloudphishing
      https://kutt.it/t6killx100%SlashNextCredential Stealing type: Phishing & Social Engineering
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      internet-cheboksary.ru
      5.101.152.35
      truefalse
        unknown
        accounts.google.com
        142.250.186.77
        truefalse
          high
          kutt.it
          172.67.188.125
          truefalse
            high
            clients.l.google.com
            142.250.185.238
            truefalse
              high
              clients2.google.com
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=92.0.4515.107&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    https://kutt.it/t6killxfalse
                      high
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://web.whatsapp.com/send?text=%(escaped_url)desktop_sharing_hub.pb.1.drfalse
                        high
                        https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.pcraw_background.js.1.dr, craw_window.js.1.drfalse
                          high
                          https://www.google.com/intl/en-US/chrome/blank.htmlcraw_background.js.1.drfalse
                            high
                            https://ogs.google.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                              high
                              https://www.google.com/images/cleardot.gifcraw_window.js.1.drfalse
                                high
                                https://payments.google.com/payments/v4/js/integrator.jsmanifest.json.1.dr, craw_window.js.1.drfalse
                                  high
                                  http://pinterest.com/pin/create/button/?url=%(escaped_url)&description=%(escaped_title)desktop_sharing_hub.pb.1.drfalse
                                    high
                                    https://sandbox.google.com/payments/v4/js/integrator.jsmanifest.json.1.dr, craw_window.js.1.drfalse
                                      high
                                      https://www.google.com/images/x2.gifcraw_window.js.1.drfalse
                                        high
                                        http://www.linkedin.com/shareArticle?url=%(escaped_url)&title=%(escaped_title)desktop_sharing_hub.pb.1.drfalse
                                          high
                                          https://accounts.google.com/MergeSessioncraw_window.js.1.drfalse
                                            high
                                            https://vk.com/share.php?url=%(escaped_url)&title=%(escaped_title)desktop_sharing_hub.pb.1.drfalse
                                              high
                                              https://www.google.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                high
                                                https://www.google.com/images/dot2.gifcraw_window.js.1.drfalse
                                                  high
                                                  https://accounts.google.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                    high
                                                    https://clients2.googleusercontent.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                      high
                                                      https://apis.google.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                        high
                                                        https://www.google.com/accounts/OAuthLogin?issueuberauth=1craw_window.js.1.drfalse
                                                          high
                                                          http://reddit.com/submit?url=%(escaped_url)&title=%(escaped_title)desktop_sharing_hub.pb.1.drfalse
                                                            high
                                                            https://www.google.com/manifest.json.1.drfalse
                                                              high
                                                              https://kutt.it471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                                high
                                                                https://www-googleapis-staging.sandbox.google.comcraw_background.js.1.dr, craw_window.js.1.drfalse
                                                                  high
                                                                  https://clients2.google.comdd382a8d-2341-49fc-9745-213cc1bd40f0.tmp.3.dr, 471ac95f-3b17-4364-89bb-934cd330bb44.tmp.3.drfalse
                                                                    high
                                                                    https://clients2.google.com/service/update2/crxmanifest.json.1.drfalse
                                                                      high
                                                                      https://twitter.com/intent/tweet?url=%(escaped_url)&text=%(escaped_title)desktop_sharing_hub.pb.1.drfalse
                                                                        high
                                                                        • No. of IPs < 25%
                                                                        • 25% < No. of IPs < 50%
                                                                        • 50% < No. of IPs < 75%
                                                                        • 75% < No. of IPs
                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                        142.250.185.238
                                                                        clients.l.google.comUnited States
                                                                        15169GOOGLEUSfalse
                                                                        5.101.152.35
                                                                        internet-cheboksary.ruRussian Federation
                                                                        198610BEGET-ASRUfalse
                                                                        239.255.255.250
                                                                        unknownReserved
                                                                        unknownunknownfalse
                                                                        172.67.188.125
                                                                        kutt.itUnited States
                                                                        13335CLOUDFLARENETUSfalse
                                                                        142.250.186.77
                                                                        accounts.google.comUnited States
                                                                        15169GOOGLEUSfalse
                                                                        IP
                                                                        192.168.2.1
                                                                        127.0.0.1
                                                                        Joe Sandbox Version:35.0.0 Citrine
                                                                        Analysis ID:686621
                                                                        Start date and time:2022-08-19 00:18:32 +02:00
                                                                        Joe Sandbox Product:CloudBasic
                                                                        Overall analysis duration:0h 4m 20s
                                                                        Hypervisor based Inspection enabled:false
                                                                        Report type:light
                                                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                        Sample URL:https://kutt.it/t6killx
                                                                        Number of analysed new started processes analysed:14
                                                                        Number of new started drivers analysed:0
                                                                        Number of existing processes analysed:0
                                                                        Number of existing drivers analysed:0
                                                                        Number of injected processes analysed:0
                                                                        Technologies:
                                                                        • HCA enabled
                                                                        • EGA enabled
                                                                        • HDC enabled
                                                                        • AMSI enabled
                                                                        Analysis Mode:default
                                                                        Analysis stop reason:Timeout
                                                                        Detection:MAL
                                                                        Classification:mal72.phis.win@29/119@5/7
                                                                        EGA Information:Failed
                                                                        HDC Information:Failed
                                                                        HCA Information:
                                                                        • Successful, ratio: 100%
                                                                        • Number of executed functions: 0
                                                                        • Number of non-executed functions: 0
                                                                        Cookbook Comments:
                                                                        • Adjust boot time
                                                                        • Enable AMSI
                                                                        • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, CompPkgSrv.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                                                                        • TCP Packets have been reduced to 100
                                                                        • Created / dropped Files have been reduced to 100
                                                                        • Excluded IPs from analysis (whitelisted): 142.250.186.35, 34.104.35.123, 142.250.74.202, 142.250.184.227, 142.250.185.195
                                                                        • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, content-autofill.googleapis.com, slscr.update.microsoft.com, eudb.ris.api.iris.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, arc.msn.com, ris.api.iris.microsoft.com, edgedl.me.gvt1.com, login.live.com, update.googleapis.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, www.gstatic.com, nexusrules.officeapps.live.com
                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                        • Report size getting too big, too many NtCreateFile calls found.
                                                                        • Report size getting too big, too many NtOpenFile calls found.
                                                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                                                        • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                        No simulations
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):123036
                                                                        Entropy (8bit):6.061609955264153
                                                                        Encrypted:false
                                                                        SSDEEP:1536:SNZl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:SN7rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:4A7E02164493E6FF890B975EBFFA8242
                                                                        SHA1:799C454DA3541A123BC4A769B232573D7289A559
                                                                        SHA-256:8234307683EAA312EB8020CED4C0401FE4F5EF9AD30C8C5A4A2A29A95B68D774
                                                                        SHA-512:61EC4045A27318C79FA7301D9F6CBE62605928E09EA298722C44F3E4E53E9359FF3EC3BF61AC1C1DDA0E6EB858D46B451A574FA488B0DB4C9E0EFDB34FAC9334
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13288110187924434"},"plugins":{"metadata":{"adobe-flash-player":{"displ
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):123123
                                                                        Entropy (8bit):6.061859560619297
                                                                        Encrypted:false
                                                                        SSDEEP:1536:SaZl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:Sa7rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:EF8D708D876E1E19D6C117B6C42BBCB9
                                                                        SHA1:816E450116284B36A3033695D440ECF93FA667EC
                                                                        SHA-256:B9ECFE8F85F3E24212CFEF3F9E51156043A5C93A1D65B8D2F17D635648B65DD9
                                                                        SHA-512:7CC9CD2C537932A06A1ABFE76827CD5934CD39FE41241D1744833BF938EAD1704C76D85403BE9C283D0BB944658B18311334142C4AE57513B9A82058E667D28E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13288110187924434"},"plugins":{"metadata":{"adobe-flash-player":{"displ
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):97528
                                                                        Entropy (8bit):3.7557922195870757
                                                                        Encrypted:false
                                                                        SSDEEP:384:LNntMIGEKxaFoSYYsPH9uJ/GaVluzuDxkgy6dWnknBdwjl2i6qMVSRLv/U1/y5zm:lWY6Twqb/oJPyh+RVKi2hbS
                                                                        MD5:9C815D8539705DAE195BCE641343BBDD
                                                                        SHA1:D360267E8D1E1FEF0D1C5A48C93EA6E31D881D70
                                                                        SHA-256:35AE6543F8070BE9748945D92DBF163CAF80F22797B221C0BB5ADEBD94AF245A
                                                                        SHA-512:1B44537A818E9EA1220E8EBA0096B1CDF1D2A4DAA3CA3BEA3FA2D7F1AA2606EE77237443AE55C6233C32BC5DD73197E854245E3FC0119A50227E0DA936BFD3B3
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.|..............T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.......puA...c.:.\.p.r.o.g.r.a.m. .f.i.l.e.s. .(.x.8.6.).\.m.i.c.r.o.s.o.f.t. .o.n.e.d.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.......f.i.l.e.s.y.n.c.s.h.e.l.l.6.4...d.l.l.......M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e."...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.....2.1...0.8.3...0.4.2.5...0.0.0.3.....T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n...?e8. ...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.7.-.Z.i.p.\.7.-.z.i.p...d.l.l.......n\....%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.7.-.z.i.p.\.......7.-.z.i.p...d.l.l.......7.-.Z.i.p.......7.-.Z.i.p. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.......1.9...0.0...............?e8.....
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):118521
                                                                        Entropy (8bit):6.032427818429482
                                                                        Encrypted:false
                                                                        SSDEEP:1536:c1pl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:c1LrkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:5AE03080970731F72B678FD5360160F0
                                                                        SHA1:F7014227A47C45C41766EEA565938FD7CE522468
                                                                        SHA-256:231A49B286202C9388FA9ED69158E59583BB608A8D84D80A5331DDC792A0D785
                                                                        SHA-512:056BC055FD680A7D70953F95A88420B7106475BC72DCF300B8A1B9448093614695CDC2D5D7B299D5CC2BDE9C9B812375C7AB559F4067F67074C57A583591DF6B
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"policy":{"last_statistics_update":"13305367145572832"},"profile":{"info_cache":{"Default":{"active_time":1660893546.710097,"avatar_icon":"chrom
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:modified
                                                                        Size (bytes):123213
                                                                        Entropy (8bit):6.062010213454118
                                                                        Encrypted:false
                                                                        SSDEEP:1536:SPZl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:SP7rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:67928B747BC32C652882D7B5F8030372
                                                                        SHA1:55E719EBE019FBE4F014D837D00608B8ACC9066D
                                                                        SHA-256:23FD1B76769D708891A5EDD17CC07DB3CF7683FE41E514B23F1D95FD52D5C732
                                                                        SHA-512:0A6D6A5BD90339C62B41FF4B9E64840F66C902423F7735DCFCD5BE6AF86CE86A025AD61307EECAA13002DD580ED6B524FF77674F5344E9CBFC9398425CC58064
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13288110187924434"},"plugins":{"metadata":{"adobe-flash-player":{"displ
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):40
                                                                        Entropy (8bit):3.254162526001658
                                                                        Encrypted:false
                                                                        SSDEEP:3:FkXSoWA0:+g
                                                                        MD5:FA7200D6F80CD1757911C45559E59C0E
                                                                        SHA1:89C6E99BAEC4EBB3E9A97B928FB473D1498EBA88
                                                                        SHA-256:D9779EA4D6DD544A23C2A1C53146B6A4E596927F47DFA0680B0A7EE751D43BB2
                                                                        SHA-512:71D9B2DA8EAF404063D918812BA61C3EFB6A23A283B0332180A38C8137FBB21D7977C008D5A57A74469776945CD4ED42C0BCC09F923EDEC52D8F7FE90FA2D104
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:sdPC.....................A.>'..M..,.,.-.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6567
                                                                        Entropy (8bit):4.988462729475217
                                                                        Encrypted:false
                                                                        SSDEEP:96:nF72H1KViauTRWMoiVmdeldNOIbTVk7MV1ZXJJExMziZwB:nF7I1K4WM1ddbT2QLE+
                                                                        MD5:9CC0F856E43906B995E4652385665D84
                                                                        SHA1:E203FFF29870CECA303FBE0628A5CCBFDB811566
                                                                        SHA-256:979B2A9BCADD2DE63B8E599951A22B7DC8B2F0AF8AEF582B3F911453960DDEFE
                                                                        SHA-512:B798089B8D75EE97FFDEF2964D133EFCC389AD975FFC01FC51C9909994D444107BA16CCC06A8291210C73A6DB8BE7E6CF6697CA7CBEDA84A6B8AC578BC985382
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":91},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"default_browser_infobar_last_declined":"13267638900457663","has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_recei
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:modified
                                                                        Size (bytes):1850
                                                                        Entropy (8bit):4.951615266809715
                                                                        Encrypted:false
                                                                        SSDEEP:48:Y2TtwDHXPqnyv3zss2eDszMRLse/swdxbD:JTODHXin+RvxnxH
                                                                        MD5:36CABD3C424CF974D92E0374694DB8F5
                                                                        SHA1:3BA241B04378255508CF237FCD5AABE25C449567
                                                                        SHA-256:F774AAF5CAFFD1620F706F8E93CE2CA01AC3575001F67C6822E08D95C80535D3
                                                                        SHA-512:2EAF7BCE6C0E62C082D40941B826E1A78BF8202C46F1E0A0F3AB65019645205FCB36C2D1F89FE85787E23836281ACF650A291B33CFDB3741F4DDEA246075E493
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://update.googleapis.com","supports_spdy":true},{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"isolation":[],"server":"https://www.googleapis.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"],"expiration":"13307959148254412","port":443,"protocol_str":"quic"},{"advertised_alpns":["h3-Q050"],"expiration":"13307959148254417","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://clients2.google.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):15765
                                                                        Entropy (8bit):5.573415986933224
                                                                        Encrypted:false
                                                                        SSDEEP:384:aYPtsLlaX51kXqKf/pUZNCgVLH2HfETrU2rv4I:cLlI51kXqKf/pUZNCgVLH2HfOrUqvP
                                                                        MD5:98BF484F8AEF0AE9E71A136F3852FE10
                                                                        SHA1:11624E67DEFBF6983CE54BC5C20DEAB47FD236AA
                                                                        SHA-256:97D72D7F8954CAA4076DAA07FC7B9F6B4AB201EDCF589A54EDFD11A892F7A0CF
                                                                        SHA-512:A0F8485A5C6839EE3E0758DCE31C1136490254B2681875C08FB12E6BED6B4678FDE708782B94672E1C72632ADD2F1B4D164C59C0DC9E1D37B5A63ECAE323D12D
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6903
                                                                        Entropy (8bit):5.009898631393683
                                                                        Encrypted:false
                                                                        SSDEEP:96:nk1H1KKIiauTRWMoiVmdeLkd150NOIbTVk7MV1ZXJJExbAiZw4:nkF1K4WMbkdj0dbT2QLEX
                                                                        MD5:C99FAEE894D0DE3D7287173A9621E965
                                                                        SHA1:7804A3D0FC33EA5F2170BFDC121D8246117E463C
                                                                        SHA-256:90D277518BBB01EE57F5E0E4C10976FC1305C3A619A1CB1B3B3FBFDA7B34B161
                                                                        SHA-512:96B7AFCC54085801DEED3684FBFF93C9F8E4B837E8318B3C49CE187FD10BA8E9C21C514D99982FC9EA5628A9AAC5554CE56BB9E68CA497574B37F12DCF9FD7AA
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":92},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7164
                                                                        Entropy (8bit):5.011104636791012
                                                                        Encrypted:false
                                                                        SSDEEP:96:nkIH1eKIiauTRWMoiVmdewkQMH8WNOIbTVk7MV1ZXJJExbAiZw4:nkS1e4WMAkQ1WdbT2QLEX
                                                                        MD5:ACA86154C8DC04768DD9ECF0041D1A58
                                                                        SHA1:A61F69EC639E32BDBA5CA97C7356C11A4F8BAED8
                                                                        SHA-256:45BE9CE2AF6C86D33E0BDDBA0283600EE4DE467BB6EFB8E3B92C1BFB9DEFA8E4
                                                                        SHA-512:3BD235C24A8B4B11F942F667C23C0958592D4CED1F3323A93F0A7D4147DC48308D0770BD0E6C36BDC558EF4E4A1A8BC8B25C0EDC7963A135B94C1D80EC7A60D4
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":92},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6567
                                                                        Entropy (8bit):4.988304997452246
                                                                        Encrypted:false
                                                                        SSDEEP:96:nF72H1KViauTRWMoiVmdeldNOIbTVk7MV1ZXJJExMAiZwB:nF7I1K4WM1ddbT2QLEJ
                                                                        MD5:E3A19C23011941A915E357E1C71600B3
                                                                        SHA1:0A38D30F369F04CE55C55CDCF71532B9884C280D
                                                                        SHA-256:AB15776AD504D9EC5C59E3D92F559E67D730E20451F3A0EBE7D33141278E6099
                                                                        SHA-512:3FFFB3474E23B04FFB651B746A6FE6CFEFF5965E3F6E23B0D1F6321436578E681D1FC19BF26FB0AD89A26F815A993EBDF83766D6890D08B75CAE5117B01EF089
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":91},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"default_browser_infobar_last_declined":"13267638900457663","has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_recei
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):16478
                                                                        Entropy (8bit):5.5712109419589515
                                                                        Encrypted:false
                                                                        SSDEEP:384:aCptRLlaXQ1kXqKf/pUZNCgVLH2HfEjrUJ1v4s:5LlIQ1kXqKf/pUZNCgVLH2HfkrU3vP
                                                                        MD5:A4CB0F8F5A6D19241A9A9EA06DD633B0
                                                                        SHA1:64DB2F514FCDA6600428B0F3BF261B846CC5B331
                                                                        SHA-256:3C58358433A4100F7DC7CE1B3440EC718E8E3E26B9E42C55E2313D7B63BFE0B1
                                                                        SHA-512:36571244EE21B05A2523041B0078F2B23C940BB75A8B88D4F646AF08A6885D4A3B0386FB0333789986D1AA19CB169190300736E4C5AB1F4DA54C1BC09CD79FF2
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6993
                                                                        Entropy (8bit):5.015028471186382
                                                                        Encrypted:false
                                                                        SSDEEP:96:nkyH1KKIiauTRWMoiVmdewkQMH8WNOIbTVk7MV1ZXJJExbAiZw4:nk81K4WMAkQ1WdbT2QLEX
                                                                        MD5:69A6104E9D475A287A6F49566408FEAC
                                                                        SHA1:57131CAF3AB2C419C60D6D89B4B545A2EC1689B7
                                                                        SHA-256:01538FC4812E0531B130619EA608C070494E5970DA68F50304ED5DCDD93F3E86
                                                                        SHA-512:A50086EC793892DC15A5C210CBE2112E4F9206483496E2D6741D70C20EF390102E7ABDDF1432343EDFCD44E6DE6A516EE80FB7CD894F76BF153800B5D631BC25
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":92},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):11336
                                                                        Entropy (8bit):6.0707244876366575
                                                                        Encrypted:false
                                                                        SSDEEP:192:AbylJnlTwGB7V9Hne4qasKxXItmLG48gcLg/PkI:Ab+nldByaFx4toj8VEPT
                                                                        MD5:2E2110A99AD3AE9721A458C95C64C868
                                                                        SHA1:72AE17599EDC0B2DC61C41D946E3E296864F2CBA
                                                                        SHA-256:BB46BA705D5F6F43F66B07EA5DA4CC7CC0BF8FE635CCC4EBBA30A5D4A54158DE
                                                                        SHA-512:29D95D043F3E529DD33F73B3207A9167D479D9FC404209497B53229CF68AA634CB8A1FE3FD08512FD7F48AFB567144DB873FBBDAD8171D42968B97357F06BC1E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"file_hashes":[{"block_hashes":["8D+nOE33nrpuAnTVcJlgMPWVo79reBkp3Z22WTJi5B8="],"block_size":4096,"path":"_locales/nb/messages.json"},{"block_hashes":["A+1PYW3V6CJbBuQ7aqrgYhyH3bT8PKyBXp3hN2slpI0=","WSOpQRkYTHjPSlG9Zif2a7TNhy43NDcG1Zg5Nv0UbH0=","jDctR8ImG5KZrQKm4kDjUB7FokSJfjo/pmvFowRVlaY=","LPxhhJiuU0lprt0T6flpS7TkaDg7MocrbmzO65xH6RI=","nZ9zLb2By96AkKXALRM+C0Eu11XUjPiMXEKjiCPdtHE=","wifibc1QfMBN2jrtUtLgsCefvuceTpAatmLvul11RJA=","dHjWlSIIdjj7MWqg3T8MG58RuuqRXk32vqi/13JqEgA=","zd3DV7dbvfNvx1hdhU01fW5ily52DLN0CFL/ADaEeTI=","DpjXcO85FFFY9KJFPkGNfFUtdQIOsGwO5jUckiUwY14=","gqid6l1+mk/6yWgUECRofI9lMipXgXh2jEN2+CxmPE0=","prDB91X2Mmfg/M/txVMITWBmEGbOGjqBTP7CMjYqdHs=","yLPAqV4gqoyS/zFkEt3Cn2j0q2v9QOSthVFfWn8EzCM=","EPQ3jzdrLkAHyvf3920B5Y3aAkO1IJdn/UtbnAmq6T0=","+oOc6ca+ChKUpTu+oa2ZRxRE+wG3QJmuYWEvYCs40NI=","3mBGNAiRlTANEQkqzU3TEi+5wJ0ubR5uwtS4/9OOM7w=","1A9NNawxuhu95H5eThvf1rewJ4QQWhhPNxJXO1C/n68=","E3vWLQxzmj+e5QxYbUscllJ5n0ITpw5JBHV1Kph3/KM=","i3I8ghdTF9c1ZXNBZmvsID+DV4gxBVN27rj9wsMtRpg=","R
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):1850
                                                                        Entropy (8bit):4.951615266809715
                                                                        Encrypted:false
                                                                        SSDEEP:48:Y2TtwDHXPqnyv3zss2eDszMRLse/swdxbD:JTODHXin+RvxnxH
                                                                        MD5:36CABD3C424CF974D92E0374694DB8F5
                                                                        SHA1:3BA241B04378255508CF237FCD5AABE25C449567
                                                                        SHA-256:F774AAF5CAFFD1620F706F8E93CE2CA01AC3575001F67C6822E08D95C80535D3
                                                                        SHA-512:2EAF7BCE6C0E62C082D40941B826E1A78BF8202C46F1E0A0F3AB65019645205FCB36C2D1F89FE85787E23836281ACF650A291B33CFDB3741F4DDEA246075E493
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://update.googleapis.com","supports_spdy":true},{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"isolation":[],"server":"https://www.googleapis.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"],"expiration":"13307959148254412","port":443,"protocol_str":"quic"},{"advertised_alpns":["h3-Q050"],"expiration":"13307959148254417","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://clients2.google.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7164
                                                                        Entropy (8bit):5.011104636791012
                                                                        Encrypted:false
                                                                        SSDEEP:96:nkIH1eKIiauTRWMoiVmdewkQMH8WNOIbTVk7MV1ZXJJExbAiZw4:nkS1e4WMAkQ1WdbT2QLEX
                                                                        MD5:ACA86154C8DC04768DD9ECF0041D1A58
                                                                        SHA1:A61F69EC639E32BDBA5CA97C7356C11A4F8BAED8
                                                                        SHA-256:45BE9CE2AF6C86D33E0BDDBA0283600EE4DE467BB6EFB8E3B92C1BFB9DEFA8E4
                                                                        SHA-512:3BD235C24A8B4B11F942F667C23C0958592D4CED1F3323A93F0A7D4147DC48308D0770BD0E6C36BDC558EF4E4A1A8BC8B25C0EDC7963A135B94C1D80EC7A60D4
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13305367146766414","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13267638885244271","autocomplete":{"retention_policy_last_version":92},"autofill":{"orphan_rows_removed":true},"bookmark_bar":{"show_on_all_tabs":false},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","1490045"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0"
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18569
                                                                        Entropy (8bit):5.558665287094436
                                                                        Encrypted:false
                                                                        SSDEEP:384:aCptaLlaXQ1kXqKf/pUZNCgVLH2HfEjrUIHGWrv4A:CLlIQ1kXqKf/pUZNCgVLH2HfkrU8GKvn
                                                                        MD5:E5B3AC1A17BF1904E4623980630A15B4
                                                                        SHA1:94FB0C33A0AFCD209354ED4CBAAC6EA97DD08FA3
                                                                        SHA-256:5897BC4EF2F330F0AA2C35AADB0B11F833A7C46F319AC07594C33BCAAF31411C
                                                                        SHA-512:AC18A0B7D8B59004BF049B897807CD594A966961B50EE9DBB63985F2546A235268DEE74DF8A9A7FF21C675C78B801C0131949A7F3070C4A91F043D7192AE36D5
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):270336
                                                                        Entropy (8bit):0.0012471779557650352
                                                                        Encrypted:false
                                                                        SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                        MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                        SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                        SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                        SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):139
                                                                        Entropy (8bit):4.762700853527964
                                                                        Encrypted:false
                                                                        SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJqjn1KKtiKnMb1KKtiVY:YHpoeS7PMVKJw1K3KnMRK3VY
                                                                        MD5:038931FF72A0C6AA0695A404960B1B22
                                                                        SHA1:90802F36B75C3CA70FC8CD1CF8BDFBAE0E8723A4
                                                                        SHA-256:BEF93811AE263E2E9145A44205340015843B1D4485D084BB642EAEB500FE564C
                                                                        SHA-512:97903821D21BB748255C29BE83BCA5BE61E0E36719050D4BB780EBC35424202A23F3ED4EE0056833E7748F1D55D82A5F38476298C5012202776BEA411DA7001E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                        MD5:46295CAC801E5D4857D09837238A6394
                                                                        SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                        SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                        SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000001.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                        MD5:46295CAC801E5D4857D09837238A6394
                                                                        SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                        SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                        SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000001.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:PGP\011Secret Key -
                                                                        Category:dropped
                                                                        Size (bytes):41
                                                                        Entropy (8bit):4.704993772857998
                                                                        Encrypted:false
                                                                        SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                        MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                        SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                        SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                        SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.|.."....leveldb.BytewiseComparator......
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):139
                                                                        Entropy (8bit):4.762700853527964
                                                                        Encrypted:false
                                                                        SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJqjn1KKtiKnMb1KKtiVY:YHpoeS7PMVKJw1K3KnMRK3VY
                                                                        MD5:038931FF72A0C6AA0695A404960B1B22
                                                                        SHA1:90802F36B75C3CA70FC8CD1CF8BDFBAE0E8723A4
                                                                        SHA-256:BEF93811AE263E2E9145A44205340015843B1D4485D084BB642EAEB500FE564C
                                                                        SHA-512:97903821D21BB748255C29BE83BCA5BE61E0E36719050D4BB780EBC35424202A23F3ED4EE0056833E7748F1D55D82A5F38476298C5012202776BEA411DA7001E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):139
                                                                        Entropy (8bit):4.762700853527964
                                                                        Encrypted:false
                                                                        SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJqjn1KKtiKnMb1KKtiVY:YHpoeS7PMVKJw1K3KnMRK3VY
                                                                        MD5:038931FF72A0C6AA0695A404960B1B22
                                                                        SHA1:90802F36B75C3CA70FC8CD1CF8BDFBAE0E8723A4
                                                                        SHA-256:BEF93811AE263E2E9145A44205340015843B1D4485D084BB642EAEB500FE564C
                                                                        SHA-512:97903821D21BB748255C29BE83BCA5BE61E0E36719050D4BB780EBC35424202A23F3ED4EE0056833E7748F1D55D82A5F38476298C5012202776BEA411DA7001E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):270336
                                                                        Entropy (8bit):0.0012471779557650352
                                                                        Encrypted:false
                                                                        SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                        MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                        SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                        SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                        SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):139
                                                                        Entropy (8bit):4.762700853527964
                                                                        Encrypted:false
                                                                        SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJqjn1KKtiKnMb1KKtiVY:YHpoeS7PMVKJw1K3KnMRK3VY
                                                                        MD5:038931FF72A0C6AA0695A404960B1B22
                                                                        SHA1:90802F36B75C3CA70FC8CD1CF8BDFBAE0E8723A4
                                                                        SHA-256:BEF93811AE263E2E9145A44205340015843B1D4485D084BB642EAEB500FE564C
                                                                        SHA-512:97903821D21BB748255C29BE83BCA5BE61E0E36719050D4BB780EBC35424202A23F3ED4EE0056833E7748F1D55D82A5F38476298C5012202776BEA411DA7001E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                        MD5:46295CAC801E5D4857D09837238A6394
                                                                        SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                        SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                        SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000001.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                        MD5:46295CAC801E5D4857D09837238A6394
                                                                        SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                        SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                        SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000001.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:PGP\011Secret Key -
                                                                        Category:dropped
                                                                        Size (bytes):41
                                                                        Entropy (8bit):4.704993772857998
                                                                        Encrypted:false
                                                                        SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                        MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                        SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                        SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                        SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.|.."....leveldb.BytewiseComparator......
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:very short file (no magic)
                                                                        Category:dropped
                                                                        Size (bytes):1
                                                                        Entropy (8bit):0.0
                                                                        Encrypted:false
                                                                        SSDEEP:3:L:L
                                                                        MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                        SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                        SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                        SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18569
                                                                        Entropy (8bit):5.558665287094436
                                                                        Encrypted:false
                                                                        SSDEEP:384:aCptaLlaXQ1kXqKf/pUZNCgVLH2HfEjrUIHGWrv4A:CLlIQ1kXqKf/pUZNCgVLH2HfkrU8GKvn
                                                                        MD5:E5B3AC1A17BF1904E4623980630A15B4
                                                                        SHA1:94FB0C33A0AFCD209354ED4CBAAC6EA97DD08FA3
                                                                        SHA-256:5897BC4EF2F330F0AA2C35AADB0B11F833A7C46F319AC07594C33BCAAF31411C
                                                                        SHA-512:AC18A0B7D8B59004BF049B897807CD594A966961B50EE9DBB63985F2546A235268DEE74DF8A9A7FF21C675C78B801C0131949A7F3070C4A91F043D7192AE36D5
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Tv:1qIFj
                                                                        MD5:AEFD77F47FB84FAE5EA194496B44C67A
                                                                        SHA1:DCFBB6A5B8D05662C4858664F81693BB7F803B82
                                                                        SHA-256:4166BF17B2DA789B0D0CC5C74203041D98005F5D4EF88C27E8281E00148CD611
                                                                        SHA-512:B733D502138821948267A8B27401D7C0751E590E1298FDA1428E663CCD02F55D0D2446FF4BC265BDCDC61F952D13C01524A5341BC86AFC3C2CDE1D8589B2E1C3
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000006.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.2743974703476995
                                                                        Encrypted:false
                                                                        SSDEEP:3:1sjgWIV//Tv:1qIFj
                                                                        MD5:AEFD77F47FB84FAE5EA194496B44C67A
                                                                        SHA1:DCFBB6A5B8D05662C4858664F81693BB7F803B82
                                                                        SHA-256:4166BF17B2DA789B0D0CC5C74203041D98005F5D4EF88C27E8281E00148CD611
                                                                        SHA-512:B733D502138821948267A8B27401D7C0751E590E1298FDA1428E663CCD02F55D0D2446FF4BC265BDCDC61F952D13C01524A5341BC86AFC3C2CDE1D8589B2E1C3
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:MANIFEST-000006.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):3343
                                                                        Entropy (8bit):4.945222848960228
                                                                        Encrypted:false
                                                                        SSDEEP:48:YXsVVMHzzsmdAMHtKsyfDszmcQ/RLsOcXSsM1PzshVMH8sp1AAMHDysKGMHTFsB5:PGqGctrmKwGPTGD7GSGMphH
                                                                        MD5:CAB8BEABE7E66A4015C98A3C77B3698B
                                                                        SHA1:C960AAAEA7014E105290C7D0F09BFCA837C8E8CC
                                                                        SHA-256:75431010BFE77818B8BEF4B0C4B328C00668DC6B13C09AAB769EBF58BDA4EDF7
                                                                        SHA-512:0D1E94E84294AEA4BF400FF9D0654748BFFEB92D3A1643A6A13B541ADB1BC13EA2F649560A27C8CC3D8AEF9DA5D6B668C7E3BE696091CE882A475B91A9A4CAC8
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3-29"],"expiration":"13270230891381309","port":443,"protocol_str":"quic"},{"advertised_alpns":["h3-Q050"],"expiration":"13270230891381310","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":39697},"server":"https://www.googleapis.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"],"expiration":"13270230887958662","port":443,"protocol_str":"quic"},{"advertised_alpns":["h3-Q050"],"expiration":"13270230887958664","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":52163},"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3-29"],"expiration":"13270230886326794","port":443,"protocol_str":"quic"},{"advertised_alpns":["h3-Q050"],"expiration":"13270230886326795","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://clients2.google.com","supports_spdy
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18568
                                                                        Entropy (8bit):5.558617735006885
                                                                        Encrypted:false
                                                                        SSDEEP:384:aCptaLlaXQ1kXqKf/pUZNCgVLH2HfEjrUIHGp7v4m:CLlIQ1kXqKf/pUZNCgVLH2HfkrU8GNvN
                                                                        MD5:5DB9F7B420015CDB5B010C49A81FF562
                                                                        SHA1:CD7A54E1083DA2F01BD190BE0A734B2C5FBFC73E
                                                                        SHA-256:02FD2EF419E558F5933971456AEA4575CE9DC511A2FF2EA55B2FDF017B491A7A
                                                                        SHA-512:5B60026C480FFD3CE910E9F9EE505397106F5875C16399CBDD8A03B2DAC811590A6C3C18E5D2425ED37062E002911A14E137A15141731C9576C43A74BDEAA511
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):16479
                                                                        Entropy (8bit):5.571107750726341
                                                                        Encrypted:false
                                                                        SSDEEP:384:aCptaLlaXQ1kXqKf/pUZNCgVLH2HfEjrU01v4z:CLlIQ1kXqKf/pUZNCgVLH2HfkrUivU
                                                                        MD5:B307AE9E7C97D90EA21A62C540459235
                                                                        SHA1:3DB41210473376961C778E5279B7FC90FED9A61D
                                                                        SHA-256:7B82B9047F7C66A11F2C524498E2A5748FB51EA86002D6BC7072CBBF89BDE1CD
                                                                        SHA-512:1012813B24F5EF834ABE934145D161BD867784ED9DD80BA212C11ADAE469ABA4C6F3C10DE3FCE7BD29478452515BB12BE8AC7165AC78AF6703A79AF9F1216B41
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13305367145939508","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):106
                                                                        Entropy (8bit):3.138546519832722
                                                                        Encrypted:false
                                                                        SSDEEP:3:tbloIlrJ5ldQxl7aXVdJiG6R0RlAl:tbdlrnQxZaHIGi0R6l
                                                                        MD5:DE9EF0C5BCC012A3A1131988DEE272D8
                                                                        SHA1:FA9CCBDC969AC9E1474FCE773234B28D50951CD8
                                                                        SHA-256:3615498FBEF408A96BF30E01C318DAC2D5451B054998119080E7FAAC5995F590
                                                                        SHA-512:CEA946EBEADFE6BE65E33EDFF6C68953A84EC2E2410884E12F406CAC1E6C8A0793180433A7EF7CE097B24EA78A1FDBB4E3B3D9CDF1A827AB6FF5605DA3691724
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e...e.x.e.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):13
                                                                        Entropy (8bit):2.873140679513133
                                                                        Encrypted:false
                                                                        SSDEEP:3:mB4:mu
                                                                        MD5:3A0E5D4F452CF99191634D0FFAB744A0
                                                                        SHA1:F115BBB898EEFF640D8D19AD44A86C3FCDFFC0AD
                                                                        SHA-256:B9D528D3AE283039F4700C7E4E790744C58A26353A91B536DD91CBA4F648A35F
                                                                        SHA-512:87BF9DB30598EC454A02A4A32E5458E83870524D4AA497CB167C8A92B7521204B7B75E2BE18D61F9FBE51CA7DE8E35782AA65E6F6F11E4A4926A9B6C85D6528A
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:92.0.4515.107
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):123213
                                                                        Entropy (8bit):6.062010213454118
                                                                        Encrypted:false
                                                                        SSDEEP:1536:SPZl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:SP7rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:67928B747BC32C652882D7B5F8030372
                                                                        SHA1:55E719EBE019FBE4F014D837D00608B8ACC9066D
                                                                        SHA-256:23FD1B76769D708891A5EDD17CC07DB3CF7683FE41E514B23F1D95FD52D5C732
                                                                        SHA-512:0A6D6A5BD90339C62B41FF4B9E64840F66C902423F7735DCFCD5BE6AF86CE86A025AD61307EECAA13002DD580ED6B524FF77674F5344E9CBFC9398425CC58064
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13288110187924434"},"plugins":{"metadata":{"adobe-flash-player":{"displ
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):98268
                                                                        Entropy (8bit):3.7559138952193845
                                                                        Encrypted:false
                                                                        SSDEEP:384:fNntMIGEKxaFoSYYsPH9uJ/GaVluzuDxkgy6dWnknBdwjl2iOGqMVSRLv/U1/y5e:hWY6T1qb/oJPyh+RVKi2hbW
                                                                        MD5:C562F139A81E0750893B13B4569C7048
                                                                        SHA1:E44422A82D91D859F38A15484980FE4C7274F194
                                                                        SHA-256:3EF4E72D95FF5C5D31F0B5AA2B6330D92EB1B0D047376CF836D32B64B5D6C205
                                                                        SHA-512:5CC93F34AFB072B83E922AE9BCCE31C012C3C407A3AB7F5AC8CE01FBF806AC9EF49FE9F108952C4D72AD3DAF88CB105C052E045692A0052F585BCD4B9011ECB1
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:................T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.......puA...c.:.\.p.r.o.g.r.a.m. .f.i.l.e.s. .(.x.8.6.).\.m.i.c.r.o.s.o.f.t. .o.n.e.d.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.......f.i.l.e.s.y.n.c.s.h.e.l.l.6.4...d.l.l.......M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e."...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.....2.1...0.8.3...0.4.2.5...0.0.0.3.....T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n...?e8. ...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.7.-.Z.i.p.\.7.-.z.i.p...d.l.l.......n\....%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.7.-.z.i.p.\.......7.-.z.i.p...d.l.l.......7.-.Z.i.p.......7.-.Z.i.p. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.......1.9...0.0...............?e8.....
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):118540
                                                                        Entropy (8bit):6.032711524051656
                                                                        Encrypted:false
                                                                        SSDEEP:1536:c1Yl1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:c16rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:B50A82F0315D0FFBC959CA4CFD43A137
                                                                        SHA1:CDBC1E39B2FE99952954365CCEEA00BBF78B8136
                                                                        SHA-256:FC67BF5B6012FBCAE2550BEC502F690BF1D3F0D1410ED9D3E35AE8F4A1C1AB13
                                                                        SHA-512:7770FAE5C6E91F4783A0216CA08282D8CBEC5E9C48B03DAC43D973359EDAAC78621C59FDB234D1111D2F5F585938EF5ECD2899889109D77352AC7C48EED21A47
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"policy":{"last_statistics_update":"13305367145572832"},"profile":{"info_cache":{"Default":{"active_time":1660893546.710097,"avatar_icon":"chrom
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):118633
                                                                        Entropy (8bit):6.033276309158698
                                                                        Encrypted:false
                                                                        SSDEEP:1536:01il1EKk6JUVSf0lEDWZiAnxPkusweEAhXNRpaah1GOVchCsjUtjOjXMWj:014rkzI0lW1AnijCaNp19URgyjX3
                                                                        MD5:9E81CBE6AD1CCD36731EA43975A64052
                                                                        SHA1:6913379FD4A28643B3D31F620E1797B03A45C74F
                                                                        SHA-256:16E66E7BC287D3C3ECB852CAE49C98FDE252B4D1E6BA1C932D3F7CAE22E13EB6
                                                                        SHA-512:D8DEE7B1252C41D8CF8AD2EDB4DB6A6BF8853337CD1529D5635053C734CB9C61B59DC2E0C7C04357642A7D31D51565BB001FB4064C754F6AF1BCCE133158C603
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"91.0.4472.77"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.660893547530686e+12,"network":1.660861147e+12,"ticks":169438733.0,"uncertainty":2615491.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABBQ7WxpM2gT7fMNkY5iRxkAAAAAAIAAAAAABBmAAAAAQAAIAAAALDWDwoLRYqp0NkiPsTxUN2QcOPsitaJrdacpo+ULE2PAAAAAA6AAAAAAgAAIAAAAOIeKQBWbQSCqXv1OSNS2lIZGHfAdJRwvbkapN4/FWvwMAAAAPz8I/w07KQb4Ut8ObsBGVgFwbuU88R362cCGZpNEtOEILJDMaKWOA4Y9ejBRTt5kEAAAADq8RkIezfgqGPgEaEMkhoGd9qhyBeyucXcRUPEI7mgYIxaDt8C5FJrjkEhV5EOUcUmR2SCzqYelImLnfOlbhRQ"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13288110187924434"},"policy":{"last_statistics_update":"133053671455728
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):95480
                                                                        Entropy (8bit):3.7548454368914053
                                                                        Encrypted:false
                                                                        SSDEEP:384:QNntMIGEKxJoHPH9uJ/GaVluzuDxkgy6dWnknBdwjl2i6qMVSRLv/U1/y5zjF7/E:KY6Twqb/oJPyh+RVKi2hbS
                                                                        MD5:36A95AFE69EEB295B0DC91B1DB60EB12
                                                                        SHA1:30E291AAD331CD772C53200D2117792AEB9C2A67
                                                                        SHA-256:D6730FD3CC864EBE622B309DB9FC9ABF927C06BC75831D601DF9C3D0BC7BD6EA
                                                                        SHA-512:FE2B0DF10DFD40BF1A04FE06ABD8C23C9FD5EDF225F2F1D7301487CFFDF7FC1FA2B8557A8632545556657D61D5D0F6BDE0A3FB2985E90E21910FAF38EDDD9080
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.t..............T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.......puA...c.:.\.p.r.o.g.r.a.m. .f.i.l.e.s. .(.x.8.6.).\.m.i.c.r.o.s.o.f.t. .o.n.e.d.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.......f.i.l.e.s.y.n.c.s.h.e.l.l.6.4...d.l.l.......M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e."...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.....2.1...0.8.3...0.4.2.5...0.0.0.3.....T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n...?e8. ...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.7.-.Z.i.p.\.7.-.z.i.p...d.l.l.......n\....%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.7.-.z.i.p.\.......7.-.z.i.p...d.l.l.......7.-.Z.i.p.......7.-.Z.i.p. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.......1.9...0.0...............?e8.....
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):98268
                                                                        Entropy (8bit):3.7559138952193845
                                                                        Encrypted:false
                                                                        SSDEEP:384:fNntMIGEKxaFoSYYsPH9uJ/GaVluzuDxkgy6dWnknBdwjl2iOGqMVSRLv/U1/y5e:hWY6T1qb/oJPyh+RVKi2hbW
                                                                        MD5:C562F139A81E0750893B13B4569C7048
                                                                        SHA1:E44422A82D91D859F38A15484980FE4C7274F194
                                                                        SHA-256:3EF4E72D95FF5C5D31F0B5AA2B6330D92EB1B0D047376CF836D32B64B5D6C205
                                                                        SHA-512:5CC93F34AFB072B83E922AE9BCCE31C012C3C407A3AB7F5AC8CE01FBF806AC9EF49FE9F108952C4D72AD3DAF88CB105C052E045692A0052F585BCD4B9011ECB1
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:................T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.......puA...c.:.\.p.r.o.g.r.a.m. .f.i.l.e.s. .(.x.8.6.).\.m.i.c.r.o.s.o.f.t. .o.n.e.d.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.......f.i.l.e.s.y.n.c.s.h.e.l.l.6.4...d.l.l.......M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e."...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.....2.1...0.8.3...0.4.2.5...0.0.0.3.....T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e.\.2.1...0.8.3...0.4.2.5...0.0.0.3.\.a.m.d.6.4.\.F.i.l.e.S.y.n.c.S.h.e.l.l.6.4...d.l.l.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n...?e8. ...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.7.-.Z.i.p.\.7.-.z.i.p...d.l.l.......n\....%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.7.-.z.i.p.\.......7.-.z.i.p...d.l.l.......7.-.Z.i.p.......7.-.Z.i.p. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n.......1.9...0.0...............?e8.....
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):5168
                                                                        Entropy (8bit):7.956694278195136
                                                                        Encrypted:false
                                                                        SSDEEP:96:HLCk5oNLp/f4PvzusAnSWuaGqLiWuGVaNhZMHd0NJHp9873PDqQ7:H2vUv7AnSKnaNPM+4uA
                                                                        MD5:3E5CCD9B583763AF68E28C5101373167
                                                                        SHA1:2005CDC0A8070B65E321A197D576698ECC267496
                                                                        SHA-256:41412C0863920BA95E9FDBD3AF000CBE926A73C078997A233DF55379A5C4D274
                                                                        SHA-512:04BF4F7320326B085C40527797577D8770A30A1ED24A8587A000A5AE1D8F39E0B7F187DB14603295AC7A2901A4698683CC3BED2C2611539293A1927AB31BEAE1
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:...........[ks.8..._.........#..,.G..8.;.55;.%..&5$e...... )..d.._...%.....s.....+..Uv}...]rq......luK.).zJh..3.&..Uu...W...s.H. .MV..\U3Ef.\.|...TU.9.z )I...u.+.g3U`Zs.6d...JiJ.rU.IV.".'L|8.d..j.J..q.....O."..<,...n...~|E.dV.u.O..'"...e.uyJ?..?]~.?.......M.,.7...j.,.fz].. >+o.gz....<^(5.Jg_.Ap.U.i............?.8....,..*.*./.iQ..8......A.DO/....?.~..N.~a.-..g.N~.......o.^...L.mW.]:{....../........[VkTu[wki.gK...;-.<...\.".3]..}V...)9i.V.P="m?......V.i...7..S.U.d..(..\....g....bU.....}........P9$.A...N..ckV..Qz..A....7..{pd.f.7....}6on.....7J;...Y..l>W...H.Z.........j.......Wk9vj+V.W.zAm.....P.oYo..|........}.g.^.p...Z....l%cT|LN3..H......{...~.J.%.!k.(.)..."....q.%.V.. d..MZ.`......o..m3....1.../..jeH........Q....X...j..o..|.o.r..nVw._...9 .......o...l....!...{....xU5..}.x.I..3.vT%z.k..o..........^.S*.t(....+r\.u<...G.`.........g...r..?...}7.=.....c~.F.e..w.v$sC/.B.p.D~..J...:....7Vl3w...s.-"......]+..KO.~....%.I..?.&.o...\?.9..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):101891
                                                                        Entropy (8bit):7.9971613680976565
                                                                        Encrypted:true
                                                                        SSDEEP:3072:Xs4McBbhITdJs7qJdKpJcKdNd+HyEzEcl6dr:X7Bb4dJsOPKpJrv4tTl6dr
                                                                        MD5:173CA02E5B06065771DEB2F28E4E5A9E
                                                                        SHA1:20F1774FB280C94C13082A255C27D7A786EFD5C7
                                                                        SHA-256:634557AE2916F2FAA0CBF2557F8F96E26845ABE94D2784FD73B169EC5618B186
                                                                        SHA-512:D947E3ED56BE1F3C668943E8F066F39650D2E0D76BF64BAD167E100B8B1066B88D8E851346AFBD9777E90445F41C5108A0A2F1514A3F28F02D4EC39978121E71
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:............{..0......&xqH.....zyIBv9....=...+......I6....3#.l.@..9.s].W7...h4..H...7.^.........Bg.....`.;.S...P.............z.3.........9~.P..{..-.z........b.:......>..'....I8.......'v.M'E.?bA...N8.'.8I.._...<v&.pT{.L'Ne...#.S!].T.-+...r)5.j.U.8q....X..VPo.....F.o..A.~~.?.w......eNJ..a)....i....:?._^..v.<=ei...i.......Q...8k......~j.c.W......~...Q.yq..^9..z.......S..b.E..L3|.9S.pa...a....5...J.\.2l..s..4.....S.u..o.|.Q.K.0.=........0....xj.4....Mie..C..3..... ..........WN........4Vs.B..N.bD...VK%...mb...{{....pd..7..G.....}.J;"..4,.......A.R|0d..)..M......;;.8.h.C.u..pkM..Z@.......r..U....H...],..l:~p..8`....3....5.*.t../S{.{`.^kB=f......ZR..L.$t..D%I..xB../.{rb..h8.!.........Z.0........{PuK%Vv...RR.*.......j.vw.[B..$..|&..eZEW.Z[&..d>.o......@..t.z.O.12C......Kk..oS.[.0.M...<.zq#*g.r......"0+.[.....Tb.E....F...U..U0...G.........t!.+...&K.@.N.#R.]...+.;.M[..x,...J.l........&y.n.....j>..0.|W.+.S.0X.S.E..L....R.....W.u.g.S.&^.g..N/..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):28748
                                                                        Entropy (8bit):7.9918576871001425
                                                                        Encrypted:true
                                                                        SSDEEP:384:SU7ZPeF1W3JgUrqaO/8dOcbwy59NjS5BMYGYycIfPhrVx2NtsEeSeFzVXe/rxd:H7peFkZL9RZSz3gnhhGcpXetd
                                                                        MD5:2A37AD0EC191D53104BB46953AC6C43C
                                                                        SHA1:FD23FFC5B7E4A6B45FBD88A486D15FAA51DC07AE
                                                                        SHA-256:51F075EB69486CB23B32A0776782B4A1B2AF204429AB94510469E02B115E56CC
                                                                        SHA-512:AEB91CB7902A800D7B0C43627EC2B52121BC41BA29A1B6ABEDBFCFA4802254A0594ED239EA7A3F8D40241E43D436428D1E4AC117BD97269D78460F82F9BDCF68
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:...........Zms.6..._..p..[.(.b[...M....N{..t ...S.......v...H.q.g:....]...p..6I8_d...C.\p.X$.2.p.g.8I}8.".D)$<..O...}.J9.3..a.i.'...x.....5O...x......I.M.!.'\.l.2.0.cN.fq....\......7..,......>.p...w&.KS.......(O.V>......O.r..V~J.`....U(..Y..MIy..w..g0e......D.,L..y..N.+..._....O.h.]...V....r................O.|.:....Li..>COy......N.h.......R....Q%.,Xr.y...G8=.A....!8(..L....c....sA....t.Vl:...v...G;...^.l...#.t.>...k..d..kr...B......Pb.0*..!..;9.....:~....j;....j.*O..!B......?....^.]....;...[.g.B...%..'.7;.9.>..gP. p8...:.5l.Y.....Jp..R,.?..b..8O......h.X(..G.).Cz.C..%....x.ET.....AEi.../..0.. ....k.*t...wl..e...H.i.F.....?.....z...?..........(../.O..R.?.4..7...j ..Q.....l..ob!..A..j...@..!).....K...MW.U.N.......W..Bh'8.'.y....Y.[o...PI..W.*...i...r.e..=.k^.WC..Uy.j..687^.z.#u5.4O...........-j.j3..L.1..F...8.......@l.9.c.aGC.R.&..j.Q-av?...[4.E..T8....u..+9.<.n.Qw.D..N..S..3.D...... .%C.j.7.Y.s(.0wq.ZI.#''#..[K.GJ ....4.....?
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:very short file (no magic)
                                                                        Category:dropped
                                                                        Size (bytes):1
                                                                        Entropy (8bit):0.0
                                                                        Encrypted:false
                                                                        SSDEEP:3:L:L
                                                                        MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                        SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                        SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                        SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):3110
                                                                        Entropy (8bit):7.933903341619943
                                                                        Encrypted:false
                                                                        SSDEEP:96:0MWjN1CDThRYxENcEvyGF/8WAr6Fv9MFghzqSl:0MWjN1gRYavR8WjMFQzqSl
                                                                        MD5:A83A2746B84F1CF573B02965B72ED592
                                                                        SHA1:85CC572D6F90029EB99AAFA56297D1BCA494313A
                                                                        SHA-256:DF4B53C1C7C48E80753D4945E6EC7847084F51BF57F0ED9D341326C74651D6EC
                                                                        SHA-512:C287F479EF572A06FF191C4E9A8A718507C97A2A45CB265D7DC65DD7922B80D36CE7660EC5D7EA9F3D1F1EF71C51C3E4F3D7973754F97A89B4F14D1B1FDE70DE
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:............ko.7......J...../..v....... ....zE.\+.T..f..%wW.$........p8/.....z..|a...}.#y.`.l..7Kr..T:'.UE,.&.i..Y............h...B.....gJ....%.\.?.f]1R..@3.jHA..eHi&.Q..`....g.__?'3^...@~X..a8............UN..%...&.F..K19".Y:.).L.L..WL..xxD>.P@ ...&'..j..)%.Q\..<!.3n.<#....;.gd2.LZ....x.m&.e.`&;.KX..."...<G....8.R.jsd....g.)..?.$=UVT...#.+g.!.......R..1..#D.k...3.Bj3iT.....*.M..L....}..S.K.....zi..n.A{......n..o.0j..q...w...3.7.N..].>...zK..sr1#.d..Tk..ckB...<....j.a.M1oe.9.jIQ.y+...6.....]....v.X.......q.....a>...2`.WV.v.'..~.3*.4.'8...hkT.H..9SOIF.%...;n.6.U....i!...2v.9/.;.....R..8.(..L.b....aY2ps% ."...x.V..Y[.h.....^.........U.....p.'.&m.....6..%pWE....:..o.k...<.....5....j.I...*9...f..3.....-..0..D;......*S.td/...........^_.v.)y ..Uf..q>.v2...0....o....Y%5;.5fn..{.......p_......B..V.......D.Y.l....q 3...sm.b..!..E....a. &.w.-.s..>..M_...`.0..k.!<SH...9$.....V.\A$..}..8....#`...,...3.W..k...\..xH.1).~.Y.L1.O...\.....k.....s..i+.....).0
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):33872
                                                                        Entropy (8bit):2.0569169245781995
                                                                        Encrypted:false
                                                                        SSDEEP:96:SuvCanrfpcIQPDdn6ZElJghag9exwM7FHjwvZJiSHqLg9wR7e9AncnT5S7QEdZ4h:g1Qhh9eKKLg9wR7aAWZ3h
                                                                        MD5:0F63C5027C2425412AFDE4B88D9BDDE8
                                                                        SHA1:98457E193D6DD71525AEB3F48CD13B6455C35B9F
                                                                        SHA-256:C8232B6128DC4759DB73245BD110589BA2D910DB20FB6367AFB6E6D9E4C1F54B
                                                                        SHA-512:9C98F0F257456B542EF0177F513F07440165468DB4B01342A009210554079186FC03E61E0BF92ABED35A51B6578A263197A9061F699EF960CDEE85553D0BCDEE
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:#"b####""##########c####""#$#######""""#""#""#############""#""#################$$$$$$$$$$$$########$$$$$$$$$$$$########$##$########""#$##$$######""#$##########""#""#$$####$##$$$$$$$$$$$$$$##$$$$$$$$$$$$$$$cc#ccc"b"b$######ccbbccc"aa"b######""#####""#""###########""#""#"!!""$####""#$##$##$$$$#c##$##$$$$$$####$$$$$$$##$$$$######""#$##$##cc"b#""#"a!#$##$""#####""#""#$##$####""#""#"!!#$####""#$##$$$$$$$$$##$$$$$$$$$$$$$$$##$$$$#c###############c######$##$##""""""""""#""""############""#""#$##########$$$$$d$$$$$$$$########$$$$$$$##$$$$c"b##bb###########c###c#""#$##$##""""""#""#""#########""###"b#""#####$######$$$$$$$##$$$$$$####$$##$$$$##$$$$$$cccc##""bb$######ccbbcccbb"b$##########""#""""##########""#""#"!!""$####""#$######$$$$d##$##$$$$$##$##$$$$$##$$$$$$####c#""#######""#cc"b#"b#"!!""$####""#####""#"!!#######""###""#""#!!!!#$####""#$##$##$$$$$$$$$$$$$$$$$$$$$$$$$$$$#c######$$$###c######$$$########""###$##$######""#$$$##$$$$$$$$$$$##$$$$$$$$$$$$$$$$$$$$##$$##$$$$####$$$$$$##$####$$$$$$$$
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):1765
                                                                        Entropy (8bit):6.014705394789547
                                                                        Encrypted:false
                                                                        SSDEEP:48:p/henDcwAakDUSy+T5V3uVTuCojVkS4FkZXco:RcDPAa8y+TbpjVyFiMo
                                                                        MD5:8B845471B314D55AE06FBF882AB8F776
                                                                        SHA1:190ECAEAF30450A3130E775C0B4B92B90F11B24B
                                                                        SHA-256:992660E19AE360708B225EEAAE07D9A8BCE2A5AC2CE2822AAEC9A8D9945F0F2D
                                                                        SHA-512:2ED7B15600BBC2F5BDF5A55CA589A49C2C33DAD373DFCD17286A6BADF1F2A8457DE516D5770DD68DBA2102875C2D4B839C0E5EEE1B6F673B695E012775C116D5
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiJTb3J0aW5nTHNoQ2x1c3RlcnMiLCJyb290X2hhc2giOiJWUzhSZkJXN1Y5b1hSMmkySndJUUtPRXNUNUtISUl5dzdDVGNzbkhlX3RzIn0seyJwYXRoIjoibWFuaWZlc3QuanNvbiIsInJvb3RfaGFzaCI6Ik5rQVVqMDZ0dDlZQmhXY1htY0o2akZNQ2xRZHEtUmVYQmVxbTFNVkUxaWMifV0sImZvcm1hdCI6InRyZWVoYXNoIiwiaGFzaF9ibG9ja19zaXplIjo0MDk2fV0sIml0ZW1faWQiOiJjbWFoaG5waG9sZGlqaGpva29ubWZkamJmbWtscHBpaiIsIml0ZW1fdmVyc2lvbiI6IjEuMC42IiwicHJvdG9jb2xfdmVyc2lvbiI6MX0","signatures":[{"header":{"kid":"publisher"},"protected":"eyJhbGciOiJSUzI1NiJ9","signature":"XcqF0Bmr71CCZ9EStq6NKbjAraTtAZbHDIbaD5yWBJEQkMYVMxuJwjEMuAxifiAqEPIJ7PTVSja92fVNZxwEAmFjHXMKVs9WL1y0cqggHKaQ3A0cMF75ibR02WUkqgYa2Br8jxaapS7i1cNFY7qRNY__eT_tsKgfQRX7eNHB4RJ_ZuKpAD4wR5i03UhUo9FRvdAnFbv_p-GwEh-yq5iUaqoF5gc9vE1YJcf8somTz1eMJeoU3tXZjYZpxCsMl68hUXlH4sAHWLgKbT0I3zknkwKUWDFdtsBRUyTSoMabDC7_EvCpnQw8Wq1R17YYtUoG7Y1bK1jhQ0-nb7kuElF15qAmmI
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):66
                                                                        Entropy (8bit):3.922738348156206
                                                                        Encrypted:false
                                                                        SSDEEP:3:Shj4WEB8HYXAAhGfyn:Shj2XAAhGK
                                                                        MD5:AA9B8B29E3D553EB48973A7FF3D5FEA5
                                                                        SHA1:D8F0A1D39C59B4C45406E1481910992F7C23192B
                                                                        SHA-256:60D8DD0ECEF5BC2E653E1CE906D4BAF07D56491B39B29F051F414288A84720C3
                                                                        SHA-512:A73F7A352CE648BF40EEEB27E3AB3E6FCBF54E7DCE7F5BCD656205B7DBCF00E5A1A1E48B375EA82D4CE7CD7416142E04C22D346566CBF9C661C29377784C6E0E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:1.b4ddbdce4f8d5c080328aa34c19cb533f2eedec580b5d97dc14f74935e4756b7
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):122
                                                                        Entropy (8bit):4.549343645753808
                                                                        Encrypted:false
                                                                        SSDEEP:3:rR6TAulhFphifFwAjTho2Hgz4LAnhtWhFgS18LAn:F6VlMmAjFm8LMggS18LAn
                                                                        MD5:441350F2F2F1F5726A84E989F3F9BF91
                                                                        SHA1:C9530224671F181AE8ED47DBA82741B8AD920EA9
                                                                        SHA-256:3640148F4EADB7D60185671799C27A8C530295076AF9179705EAA6D4C544D627
                                                                        SHA-512:5AC785E7F3A35035B4958B2EF33534AB6E0448CDC5A5A881911123545930DAAFF6759AB2AB663327525A496E306CC1C98FD5F0EE079E2C6D92C47FD0CFAB51DE
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{. "manifest_version": 2,. "name": "Federated Learning of Cohorts",. "floc_component_format": 3,. "version": "1.0.6".}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):1774
                                                                        Entropy (8bit):5.992271755620209
                                                                        Encrypted:false
                                                                        SSDEEP:48:p/h5rIiI1q9pFWNSSkak/5rFcO6Vtv1QkgFtx8d1:RjrI3SvDJakUROjdW1
                                                                        MD5:F11FD62EF87DD1DC7FCB6A8000E9AF3C
                                                                        SHA1:B711DD36575CFF4CE1B217C88E36924B5376904E
                                                                        SHA-256:9151B1742552CD3B8F2BDDB76B44C18657E93DBA7EA4DECDDCABF6673ABC3CC7
                                                                        SHA-512:900D48157723A7F122E05CFCC0C23DEC8677C147FC005547449D5EB626A57BA360D1A45EA62CFB6BE5B3CB3DE8516D68322CEC948E0A81DFEB60452D29834B8F
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiJkZXNrdG9wX3NoYXJpbmdfaHViLnBiIiwicm9vdF9oYXNoIjoiWDc4QXNERUh3YjRkZ2NVNU44dUFPeHRobms5eW56amJnLTNiS3JzblBHbyJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJnVEhnNmxJdm52MXlHeWp2YUl3ZG5XcGhrYVQ3czdYeHM1c1hVSHE0QU1ZIn1dLCJmb3JtYXQiOiJ0cmVlaGFzaCIsImhhc2hfYmxvY2tfc2l6ZSI6NDA5Nn1dLCJpdGVtX2lkIjoiZGhscG9iZGdjamFmZWJnYmJoamRuYXBlam1wa2dpaWUiLCJpdGVtX3ZlcnNpb24iOiIyMDIyMDUwNSIsInByb3RvY29sX3ZlcnNpb24iOjF9","signatures":[{"header":{"kid":"publisher"},"protected":"eyJhbGciOiJSUzI1NiJ9","signature":"cHz94SeQdRzRwDsJg6GK2_jT7RRBnjSffvoD9N7MiV9Qbu3c6rDymWjzr8AWZtA5UUdoUCXtJx9frIL8iYuE7FTUJrxIVpbiIYngoCnk0aXARtsAAMysGtTli-_vyRQeW9jjbRei-ckS3uLk9keDws03R7XMRJ15xmX-4UUnjdYlnDJzqx7YG5Ufzxo4G26hYy9TmLuG7Pwf600iG-cDhgo0YYqTG2WfibL3Zg0Fcs0jtXpAZwuIZNix-vay7ueZ3aFbljtMv0NmLh5Ikj3ouR3EPxNVgVUuALZnSaDFneuPcv3oWY6AZHKaskEsxIerrhpU1cqvzDdw44iMV
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):308654
                                                                        Entropy (8bit):5.98805437515377
                                                                        Encrypted:false
                                                                        SSDEEP:3072:S94COx94COU6iJi5pJ4uJNRpJGpJCQCOkSJr:3WsJgJRJpJAJJfJr
                                                                        MD5:3782080E35A441E7483E284E8410694E
                                                                        SHA1:41F6B0EC91A2897B62D3D11136F4A995AB703A5B
                                                                        SHA-256:228CBBD9FE34AA70BAA415AFA875AD475866DAC2E3F36F62A2B3CC9FBDA6EA47
                                                                        SHA-512:FC6CC7438AEF10DCDEA762596ACF14DE02D7BA354FAE410F71A6FEEEBE8C6C7440EB7C97F9D6D54F474F3328D87C160D176D3A5ACDA970C3959614E65F509C76
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:......US.........Facebook.;https://www.facebook.com/sharer/sharer.php?u=%(escaped_url)...iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAAAFKADAAQAAAABAAAAFAAAAACy3fD9AAABc0lEQVQ4EWNgoDJgBJnnFTU94T8DQzYDw38wn3Q7GP8zMDFO3r4kYxELSDPIsP8M/01INwimA2jCP5CDGCAGkuoyLk42Bh5udoafP38zfPz8A2wq0GtMIAbYhWARIghleRGGgjQHBhUFUbjq4JS5DN++/4LziTaQnY2Foa7Ig0FMhBeuGRuDaAM1VMThht25/5ph/Y5LDL9//2X4+esPirlEGyghxgfXuGXPVYZ9R27B+cgMcEAiC+BiMzEhUhRymKGrJ+jCMF9DBlUlUQZkFwZ76zPYWSgzfP/+m6Fv1n4UMwkaqKkmwWBhpICiSV1ZnAGE7z16iyIO4hA08O/ffwx//vxlYGJiAmKIt//++8fw/99/hmcvPpBuYMuEnWBNnk5aDHnJ9mB255Q9DIdP3sUwDCRAdKRg1Y1FcOQaCCzPKATgAgxoBiTZAAtHUHkGK4KwmQ3MtwIPn7yTBMn9/fv/CSMD42eYOpBhwMiYAuNTlQYAlC5lOycVuoMAAAAASUVORK5CYII="..iVBORw0KGgoAAAANSUhEUgAAACgAAAAoCAYAAACM/rhtAAAAAXNSR0IArs4c6QAAAERlWElmTU0AKgAAAAgAAYdpAAQAAAABAAAAGgAAAAAAA6ABAAMAAAABAAEAAKACAAQAAAABAAAAKKADAAQAAAABAAAAKAAAAAB65masAAACXUlEQVRYCWNgGAWUhQAjsnavmBmR///9t2Vg+M+M
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):66
                                                                        Entropy (8bit):3.768504335670099
                                                                        Encrypted:false
                                                                        SSDEEP:3:SVPK0daQRBG2QVKR7xvljD:SgSRB4VKjjD
                                                                        MD5:B41C34E3935751085A8FDAFD9793BFDF
                                                                        SHA1:CBC1B2B01C067A9174FA6C5FF9A45EAB3EC9E403
                                                                        SHA-256:B7FD9F5F41DF520D6DDCC7D1E36721A06BD7A63AEC6B185CE33161C4FBFAF84F
                                                                        SHA-512:4F1ED7EFE4E88894D7DA8E6CA0669EB211B7491431A37716EC8EC155F1C520EA74EBCBBC77D53DAD5E26F8C6ACC6F3AB4D9DCDA5DCEB8461E1A1422A6A014DAC
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:1.0c24e9bd976adffa987e08fc54dc0950c84cf18f9cdb4c5caabc6acf24887c4f
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):182
                                                                        Entropy (8bit):4.54915508626463
                                                                        Encrypted:false
                                                                        SSDEEP:3:rR6TAulhFphifFfMTDkJHKS1IQpvFFpEeSWU4pv/8F/FxLj2RF2fcTZTotL:F6VlMGTw0S1IQpuWfB0NpK4aotL
                                                                        MD5:38A19C9D0CDC86DD0C126B26E3B83601
                                                                        SHA1:19B922CA393768BC71B9F5BC45443B89561A0C34
                                                                        SHA-256:8131E0EA522F9EFD721B28EF688C1D9D6A6191A4FBB3B5F1B39B17507AB800C6
                                                                        SHA-512:AD94F75EDEE71C9B65436050A80ACC9BD16533FB9446758B84B0F95244F0680CE510928014406B8135D1BE9DB8CCBEADE509A7317FF875A81B1670DD0B13A591
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{. "manifest_version": 2,. "name": "sharinghub.binarypb",. "version": "20220505",. "imageName": "image.squash",. "squash": true,. "fsType": "squashfs",. "isRemovable": false.}
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:Google Chrome extension, version 3
                                                                        Category:dropped
                                                                        Size (bytes):248531
                                                                        Entropy (8bit):7.963657412635355
                                                                        Encrypted:false
                                                                        SSDEEP:3072:r+nmRykNgoldZ8GjJCiUXZSk+QSVh85PxEalRVHmcld9R6yYfEp4ABUGDcaKklrv:k3oF4Z4h45P99Fld9RBQYBVcaxlnfL
                                                                        MD5:541F52E24FE1EF9F8E12377A6CCAE0C0
                                                                        SHA1:189898BB2DCAE7D5A6057BC2D98B8B450AFAEBB6
                                                                        SHA-256:81E3A4D43A73699E1B7781723F56B8717175C536685C5450122B30789464AD82
                                                                        SHA-512:D779D78A15C5EFCA51EBD6B96A7CCB6D718741BDF7D9A37F53B2EB4B98AA1A78BC4CFA57D6E763AAB97276C8F9088940AC0476690D4D46023FF4BF52F3326C88
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:Cr24..............0.."0...*.H.............0...........\7c.<........Fto.8.2'5..qk...%....2...C.F.9.#..e.xQ.......[...L|....3>/....u.:T.7...(.yM...?V.<?........1.a...O?d.....A.H..'.MpB..T.m..Vn Ip..>k.|1..n.<Fb..f..*Q1.....s..2..{*.6....Pp....obM..1.......b1.......(.u^.'z......v.F.W.X4."-*eu...b.........\..F!...b...l5....zJ.q.......L].....w[T0.6....E.....r..%Z.vFm.9..5!,.~g5...;.t...']....+A.....u....k...e..&..l.6r[yU...%..f.......N..V.....<+.....l..}.{...z...)y.n..'..).....,.b....5.08K%..O.g..D.S.F5o..<(....>....\f..X..I..2."l...w....7f|.~.c.4.E.......0..0...*.H............0.......).'..b.*$w\$.q&.]zF_2..;...?.U,...W..L1.2...R..#....W.....c1k.$W..$.J....+M!.Hz.n`U.I)N.|b.l....{.K@]6.LlP/....](.A..................I...).H....IQ.y.;MG.d..ix..#f.Z$|..|.?...0K...t"i..s...Y..%.Ky....0...{.!+.~v.;....J.....Z....).(6..@?v.;~..2..c....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. .0...|!..A..L.+.=...kP.!.1..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):30948
                                                                        Entropy (8bit):7.99105089802474
                                                                        Encrypted:true
                                                                        SSDEEP:768:jElAfPryn5QzShaPuChbhFbHRu/llKGr7J9FwyIlWg+S3:jElAfzyneSMPuKbvzUllKGzFDOWgv
                                                                        MD5:7F0FCE2F184F63FED8E9929FB106C282
                                                                        SHA1:0582EB5BFC7FCCCC1C77A860F00E351E61F5DC67
                                                                        SHA-256:7C33F333216849E50AFC9550DA7DA4450D221B837340716ACCEE3766FFD4A62B
                                                                        SHA-512:AD1CD5B804C08C4C25BD6F97153D3371156848A83682DF1829B0B113B60ED0B01D67B5CD737CB414C8B825E12C7E0D6B5F9B338F4AF7FC82BE8AAF4CA8E279BA
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:............y..../...*D4e.sH.v.{......mv9MR...&..b.`.P."........r.....X...9s.s..w..;...>.}8...O.ep....O.]...$KO.tu...2?Yfi.'ove..T.....(.N7.R..<yr....t..})......>[......*."......'7.j......#.n..e1..Fr...........j5xH.~.*...yvw....y.....vI......IWT..)...|...\..<=.V.C..}.fF..T.....~.~..:).....i...2./D.}...]..<+3T..Z.Q9*0.......3..7.e..p.:..-.P..n.}j....U...."...|Gm...AdQ:*...gz%n..:...K.o[...".n...(V..A...U.D.~x.Q..X.tw.F..,.Q...k.9.w.......2....t......XF....E./...Hu.%..].....7.T...X.\$4.~.....`..e\....}.X...`A...J.....k...$IO..OS:...=...R...q......FE.H.)M..WX/........6.._..ry..J..`.q.'....x^..[r..Z.Y:..0...g.y....#.1.'...F7M.6...S....7.To.G.... `#.......-."...^....;..8..{.6VhL?%uU...K....O9.`Y....b.5.,zP.+\..!.1wK.j.P].....jW.!.j...i3.v.<..n.P..g....~.x..z.8...2^..U.f.bt#.+.U..N......!.[.!#.C.A.xy.....p...n.mU,.....=.......h .ME..T/....lT\h,.U..........(.U ...Tf.?Zd8.2.V......*..../....Oyh.j.._.I.k..u...).3.r.3...j......O....+],...
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
                                                                        Category:dropped
                                                                        Size (bytes):30948
                                                                        Entropy (8bit):7.99105089802474
                                                                        Encrypted:true
                                                                        SSDEEP:768:jElAfPryn5QzShaPuChbhFbHRu/llKGr7J9FwyIlWg+S3:jElAfzyneSMPuKbvzUllKGzFDOWgv
                                                                        MD5:7F0FCE2F184F63FED8E9929FB106C282
                                                                        SHA1:0582EB5BFC7FCCCC1C77A860F00E351E61F5DC67
                                                                        SHA-256:7C33F333216849E50AFC9550DA7DA4450D221B837340716ACCEE3766FFD4A62B
                                                                        SHA-512:AD1CD5B804C08C4C25BD6F97153D3371156848A83682DF1829B0B113B60ED0B01D67B5CD737CB414C8B825E12C7E0D6B5F9B338F4AF7FC82BE8AAF4CA8E279BA
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:............y..../...*D4e.sH.v.{......mv9MR...&..b.`.P."........r.....X...9s.s..w..;...>.}8...O.ep....O.]...$KO.tu...2?Yfi.'ove..T.....(.N7.R..<yr....t..})......>[......*."......'7.j......#.n..e1..Fr...........j5xH.~.*...yvw....y.....vI......IWT..)...|...\..<=.V.C..}.fF..T.....~.~..:).....i...2./D.}...]..<+3T..Z.Q9*0.......3..7.e..p.:..-.P..n.}j....U...."...|Gm...AdQ:*...gz%n..:...K.o[...".n...(V..A...U.D.~x.Q..X.tw.F..,.Q...k.9.w.......2....t......XF....E./...Hu.%..].....7.T...X.\$4.~.....`..e\....}.X...`A...J.....k...$IO..OS:...=...R...q......FE.H.)M..WX/........6.._..ry..J..`.q.'....x^..[r..Z.Y:..0...g.y....#.1.'...F7M.6...S....7.To.G.... `#.......-."...^....;..8..{.6VhL?%uU...K....O9.`Y....b.5.,zP.+\..!.1wK.j.P].....jW.!.j...i3.v.<..n.P..g....~.x..z.8...2^..U.f.bt#.+.U..N......!.[.!#.C.A.xy.....p...n.mU,.....=.......h .ME..T/....lT\h,.U..........(.U ...Tf.?Zd8.2.V......*..../....Oyh.j.._.I.k..u...).3.r.3...j......O....+],...
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):796
                                                                        Entropy (8bit):4.864931792423268
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJMLkSlwZGGMLkSlwZ+WYpU34f145Gb+dgoxTyO8ZpU34f1L0frhmJ03OyZnLt:1HE7n4gn8WYpYrbhz8ZpotHOGAOf6aD
                                                                        MD5:6F8E288A9AD5B1ED8633B430E2B4D4CA
                                                                        SHA1:F671D3D4BEFA431D1946D706F4192D44E29B6F08
                                                                        SHA-256:A114E2783D0E9B12155017323BA70838F0F82A71C7EE8DC1F115AE36991241F8
                                                                        SHA-512:0F87F3F0D115B872288949E59ACD3CD41B1FBC64A622D8FDA6D71FAFC5A900D92ADFBB0E7EB926F2A8759BBAA0896D48728FB719BBF5EF54AC21027328F7700C
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "........ . ... ........ .. Chrome".. },.. "app_name": {.. "message": "........ . ... ........ .. Chrome".. },.. "craw_app_unavailable": {.. "message": "........... .... ...... .. .............".. },.. "craw_connect_to_network": {.. "message": "...., ........ .. . ......".. },.. "iap_unavailable": {.. "message": "........... .... ...... .. .......... ....... .. .........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "...., ...... . Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):675
                                                                        Entropy (8bit):4.536753193530313
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ0gbbGG0gbb+WYpU34g3YbiLO+dgyGFoO8ZpU34+puiPmb03OyZnLAOfTYABk:1HE5baib6WYpm31Lt0Z8Zp8pxOGAOfKD
                                                                        MD5:1FDAFC926391BD580B655FBAF46ED260
                                                                        SHA1:C95743C3F43B2B099FEBEBC5BD850F0C20E820AC
                                                                        SHA-256:C67898B67F9C9209EAFDA6532B62D5789863CFB855998DD6A70E7775316CEC20
                                                                        SHA-512:39D95D45C5746DA3BAA7AE6A3344EA17D7A7C3569C2A56959FF119261DA08C747A320FCF701AC72B8DBDBF8BF06FD8B239017A282CDDA444F3826D4EC672CBB4
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Ara mateix aquesta aplicaci. no est. disponible.".. },.. "craw_connect_to_network": {.. "message": "Connecteu-vos a una xarxa.".. },.. "iap_unavailable": {.. "message": "La funci. Pagaments a l'aplicaci. no est. disponible actualment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicieu la sessi. a Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):641
                                                                        Entropy (8bit):4.698608127109193
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJfZGGfZ+WYpU34OBh+dgN/O8ZpU34j05U03OyZnLAOfTYWc:1HEl4G8WYpdt8Zpq5TOGAOfW
                                                                        MD5:76DEC64ED1556180B452A13C83171883
                                                                        SHA1:CFB1E56FD587BCDC459C1D9A683B71F9849058F9
                                                                        SHA-256:32290D69A90E6BAAC428B10382C99221B12773BB9A184F3B93DFB48A4F6D7A40
                                                                        SHA-512:5230A217968D5DC463E2E92D704544311A721E5CEF65C3125CBD8DEB9C0293D3BFB5C820A6011ABF77095FDEE7DAF67D541DC202B0C9CDB0908CBB85D84885CB
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "app_name": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikace v sou.asn. dob. nen. dostupn..".. },.. "craw_connect_to_network": {.. "message": "P.ipojte se pros.m k s.ti.".. },.. "iap_unavailable": {.. "message": "Platby v aplikaci aktu.ln. nejsou k dispozici.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "P.ihlaste se do Chromu.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):624
                                                                        Entropy (8bit):4.5289746475384565
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJJMKKFZGGJMKKFZ+WYpU34OHu+dgxlCZO8ZpU34J4Wu03OyZnLAOfTYzD:1HErMKfqMKVWYpM6lL8ZpDNOGAOfiD
                                                                        MD5:238B97A36E411E42FF37CEFAF2927ED1
                                                                        SHA1:4E47AC90BA24C8F4724D9293FA40CFD4ADA66FE0
                                                                        SHA-256:4977D4A053542FF66967FAED6B06585DD70E68E20BFEB533B66FE3287F9655D9
                                                                        SHA-512:FD0742D47B5F5AB9AAD9B4C3D57F63CB693E060EECE123A72036C6E92156D099495C7E9E9CC6DC83EEBCDDCC4B4C81FB47E4C9559DA3EBA024780FFF10C53E0A
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Betalinger i Chrome Webshop".. },.. "app_name": {.. "message": "Betalinger i Chrome Webshop".. },.. "craw_app_unavailable": {.. "message": "Appen er ikke tilg.ngelig i .jeblikket.".. },.. "craw_connect_to_network": {.. "message": "Opret forbindelse til et netv.rk.".. },.. "iap_unavailable": {.. "message": "Betaling i appen er ikke tilg.ngelig i .jeblikket.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Log ind p. Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):651
                                                                        Entropy (8bit):4.583694000020627
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJQ1ZGGQ1Z+WYpU34pCEMT+dgJMlCTO8ZpU34p6FK603OyZnLAOfTYJ6K:1HEzWWYp3Bewv8Zp7k4OGAOfQj
                                                                        MD5:6B3E916E8C1991AA0453CBA00FEDCAAA
                                                                        SHA1:D6366D15912E40CA107FD42BFE9579C3336A51F9
                                                                        SHA-256:A62FFAB910E31531758EEE48B2CC71A8857BEC3021DEAD50B668CBA3C8667053
                                                                        SHA-512:87EA4311B61F29543B13F3E17DFA919D0C320B4FE370CC152E0B1514BCA79B0ABB526DDCF08621D6EBFA48923EE8FB4C667EFB120A72BD9583EEBEE7BFB80552
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Web Store-Zahlungen".. },.. "app_name": {.. "message": "Chrome Web Store-Zahlungen".. },.. "craw_app_unavailable": {.. "message": "Die App ist momentan nicht verf.gbar.".. },.. "craw_connect_to_network": {.. "message": "Bitte stellen Sie eine Verbindung zu einem Netzwerk her.".. },.. "iap_unavailable": {.. "message": "In-App-Zahlungen sind momentan nicht m.glich.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Bitte melden Sie sich in Chrome an.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):787
                                                                        Entropy (8bit):4.973349962793468
                                                                        Encrypted:false
                                                                        SSDEEP:24:1HEw+aZ+6WYpbWZe80A08ZpCGyDVWlOGAOf+XD:WguYpCZnpEZbGoD
                                                                        MD5:05C437A322C1148B5F78B2F341339147
                                                                        SHA1:AB53003A678E44A170E73711FBD9949833BBF3AA
                                                                        SHA-256:A052C32B4FCAC61152EB0ADB2C260FB6A8256AD104AA0013DB93E9798D41A070
                                                                        SHA-512:C36CB9202A34356DD06D377E2A088F428D0B8EBE7D2E54F8380485E9D94A0598D7F651C1E7A2FD55BE481D49C02B0812F2BA335E08611EC85EE0BD60784A6B40
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "........ ... Chrome Web Store".. },.. "app_name": {.. "message": "........ ... Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": ". ........ .... .. ..... ... ..... ..........".. },.. "craw_connect_to_network": {.. "message": ".......... .. ... .......".. },.. "iap_unavailable": {.. "message": ".. ........ ..... ......... ... ..... ..... .. ...... ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": ".......... ... Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):593
                                                                        Entropy (8bit):4.483686991119526
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                                                        MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                                                        SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                                                        SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                                                        SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):593
                                                                        Entropy (8bit):4.483686991119526
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                                                        MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                                                        SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                                                        SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                                                        SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):661
                                                                        Entropy (8bit):4.450938335136508
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34lPbdlVo03OyZnLAOfTY6xjD:1HEvaC6WYpcDeEFxq8ZpNl5OGAOffD
                                                                        MD5:82719BD3999AD66193A9B0BB525F97CD
                                                                        SHA1:41194D511F1ACC16C1CA828AC81C18C8C6B47287
                                                                        SHA-256:4DB9B2721E625C18B9E05C04B31AF5D9694712F1CAAF6219ABE34BB08E5DB1C7
                                                                        SHA-512:D4C49B43427799B6292CEED11CACB1D76F7CE43EBF402B43B638A6EB2B414ED0981E386CB8CDF0B51D1BD9552934FE25B2F6392266BB73D8C9A691F65BCE0128
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "Los pagos en la aplicaci.n no est.n disponibles en este momento.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicia sesi.n en Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):637
                                                                        Entropy (8bit):4.47253983486615
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34GLO03OyZnLAOfTYiJD:1HEvaC6WYpcDeEFxq8Zp4LlOGAOfvD
                                                                        MD5:6B2583D8D1C147E36A69A88009CBEBC7
                                                                        SHA1:4D4DEEB4BE6AA0181825F3371A761ABC5B4D5937
                                                                        SHA-256:6659BC3705311D7641A73995DCFEA80C7734F2F4EBBC3787B3892A240348324F
                                                                        SHA-512:37F0DBFCC1B5A2B8E4C92C49D2D9DEEF25616421350324F57E0149A45A6CCB437F5E3CBE97412C4B5DBBF2593783C7DF71E9C25A851AEAE6E4764C545723FA53
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "En este momento, Pagos En-Apps no est. disponible.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Accede a Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):595
                                                                        Entropy (8bit):4.467205425399467
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJfPGGGfPG+WYpU34Ze7z+dgrW9O8ZpU34ZwZz03OyZnLAOfTYgoLIR:1HEdvqlWYpTeObk8ZpT/OGAOfuLIR
                                                                        MD5:CFF6CB76EC724B17C1BC920726CB35A7
                                                                        SHA1:14ED068251D65A840F00C05409D705259D329FFC
                                                                        SHA-256:C85800BF45942FCC7FD6B1DF929C25F9CC2A977A6678966BD03D4B6B69889AFD
                                                                        SHA-512:53D7D01BB30C0306DE65A79FD9551D2E8C1F71F4F45F71906B009071CB3E0F231E6A50FDD78773E9B4DE94085BC7B97F829842FA21A89A2080D33458B745C46F
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome'i veebipoe maksed".. },.. "app_name": {.. "message": "Chrome'i veebipoe maksed".. },.. "craw_app_unavailable": {.. "message": "Rakendus pole praegu saadaval.".. },.. "craw_connect_to_network": {.. "message": "Looge .hendus v.rguga.".. },.. "iap_unavailable": {.. "message": "Rakendusesisesed maksed ei ole praegu saadaval.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Logige Chrome'i sisse.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):647
                                                                        Entropy (8bit):4.595421267152647
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJRuzGGRuz+WYpU34ujSBu+dgYO8ZpU34J+Bu03OyZnLAOfTY5HN:1HEFcWYpPNa8ZpD+FOGAOfEHN
                                                                        MD5:3A01FEE829445C482D1721FF63153D16
                                                                        SHA1:F3EAAADDC03F943FC88B30B67F534AA13E3336DD
                                                                        SHA-256:0BDE54B20845124113383B6EB81E43A0F05E4EB0C44BEE3C1DFAC4CC5FEC2836
                                                                        SHA-512:3B92B6C86D30FD36AA3CEFF8773BA60C3FC5CC19C693540137044C5838A5503895C770C0336A4D0A3DB5E42F3FB36274D8D3F85B9DCA2F3EC0E974FDDB0BEAD8
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Web Storen maksut".. },.. "app_name": {.. "message": "Chrome Web Storen maksut".. },.. "craw_app_unavailable": {.. "message": "Sovellus ei ole t.ll. hetkell. k.ytett.viss..".. },.. "craw_connect_to_network": {.. "message": "Muodosta verkkoyhteys.".. },.. "iap_unavailable": {.. "message": "Sovelluksen sis.iset maksut eiv.t ole t.ll. hetkell. k.ytett.viss..".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Kirjaudu sis..n Chromeen.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):658
                                                                        Entropy (8bit):4.5231229502550745
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJADlbGGADlb+WYpU34hTUT+dgHfZAFFZO8ZpU34hTjzeT03OyZnLAOfTYHfvF:1HEYah6WYp7TUSoxOS8Zp7TOsOGAOfqV
                                                                        MD5:57AF5B654270A945BDA8053A83353A06
                                                                        SHA1:EEEF7A4F869F97CF471A05D345E74F982D15E167
                                                                        SHA-256:EC002ED92359F67818B49455DFC579E140368E6A004080AF022FD4F57F6B03F2
                                                                        SHA-512:5F0AE839FCF3F4EA48FF41A76655AE0F3821564AFD5D42FBB9FBB9A38E8D8F7BB5E9B6F71064588CD441261F644095A44A755C134CE546D506D9A21E488BAF52
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "app_name": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Kasalukuyang hindi available ang app.".. },.. "craw_connect_to_network": {.. "message": "Mangyaring kumonekta sa isang network.".. },.. "iap_unavailable": {.. "message": "Kasalukuyang hindi available ang Mga Pagbabayad na In-App.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Mangyaring mag-sign in sa Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):677
                                                                        Entropy (8bit):4.552569602149629
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJALf/nbGGALf/nb+WYpU34Owdgbyb+dgdQjO8ZpU34ITQpGnbyb03OyZnLAO8:1HE4Hna1Hn6WYpNdgpY8ZpSTQwnBOGAh
                                                                        MD5:8D11C90F44A6585B57B933AB38D1FFF8
                                                                        SHA1:3F9D44EA8807069A32AACA2AAAD02FD892E6CC90
                                                                        SHA-256:599491F8C52B945C16C441ADF45BFD45AFAE046DA07757D97C56AF4DE75ED3B5
                                                                        SHA-512:D7EF7F5AD7EF1A1595825D79B69E2B1E988AD3CF1F3881496FCCD30F241E4E9C6E457F9F5D0F855DE3536DB7A40C3E1C55946B50D3F556F4A35285066A0CD6F7
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "app_name": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "craw_app_unavailable": {.. "message": "Application indisponible pour le moment.".. },.. "craw_connect_to_network": {.. "message": "Veuillez vous connecter . un r.seau.".. },.. "iap_unavailable": {.. "message": "Les paiements via l'application ne sont pas disponibles pour le moment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Veuillez vous connecter . Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):835
                                                                        Entropy (8bit):4.791154467711985
                                                                        Encrypted:false
                                                                        SSDEEP:24:1HEs07J0JWYp9vnCSVLP8Zp6CsOGAOf8SLm:Wh7qgYp1CMLUph1GiSLm
                                                                        MD5:E376D757C8FD66AC70A7D2D49760B94E
                                                                        SHA1:1525C5B1312D409604F097768503298EC440CC4D
                                                                        SHA-256:8106D98C4F8DA16DB698444409558E29CC96735E188BFA303C333A5D99231C1D
                                                                        SHA-512:673F3F259AF2946E4F49BBED14A2A70D44BF9FDA9D7A71DC9172BA9B7B3C7F7062B16D29682B638D485B0520ED6F99E7A735F28C7C719B539559005B69FA7555
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome ... ..... ......".. },.. "app_name": {.. "message": "Chrome ... ..... ......".. },.. "craw_app_unavailable": {.. "message": "......... .. ... ...... .... ...".. },.. "craw_connect_to_network": {.. "message": "..... ....... .. ...... .....".. },.. "iap_unavailable": {.. "message": "..-.. ...... ... ...... .... ...".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "..... Chrome ... .... .. .....".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):618
                                                                        Entropy (8bit):4.56999230891419
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJGiimxmbZGGGiimxmbZ+WYpU34OBOEuhopIO+dgcapZO8ZpU34GiiZrMrQphK:1HE4H4TH8WYpNjTta28ZpQVLP0SOGAOK
                                                                        MD5:8185D0490C86363602A137F9A261CC50
                                                                        SHA1:5BD933B874441CEACB9201CCC941FF67BAED6DC0
                                                                        SHA-256:A2B2EC359A9DD9DCCCE02859CE1E738BD30FAA4A05F1DC522893FFDF722BBC15
                                                                        SHA-512:D7629978FC031EA5F716F9C1065FB2FEAB48C15F10CD68830DC966FA1002C03DDC7ACDE314C7D075F9F3A0A68552A6ACBCCDEE24CF20B6C3DD1BCE6562D0396E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "app_name": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikacija trenuta.no nije dostupna.".. },.. "craw_connect_to_network": {.. "message": "Pove.ite se s mre.om.".. },.. "iap_unavailable": {.. "message": "Pla.anje u aplikaciji trenuta.no nije dostupno.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prijavite se na Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):683
                                                                        Entropy (8bit):4.675370843321512
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJVJiGGVJi+WYpU34Hpo9O+dgMmfgijO8ZpU34Huo9O03OyZnLAOfTYBIAYm:1HEVrk5WYpQzTUg/8ZpwoXOGAOfYIAd
                                                                        MD5:85609CF8623582A8376C206556ED2131
                                                                        SHA1:1E16EB70DB5E59BB684866FF3E3925C2DEF25A12
                                                                        SHA-256:32A249749F12ADB6A220BF9ADC272C7E5D9AD5497A38B0086D961E3ABA17FBC6
                                                                        SHA-512:27883430865D3CFA6EDFE8C6CE1442BD96150B5CE520CCF7D556A330CAA6392C712B47BD86F7350E174876BC681F6DEC94D1312402655B0AF90883A2899EC78B
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "app_name": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "craw_app_unavailable": {.. "message": "Az alkalmaz.s jelenleg nem .rhet. el.".. },.. "craw_connect_to_network": {.. "message": "K.rj.k, csatlakozzon egy h.l.zathoz.".. },.. "iap_unavailable": {.. "message": "Az alkalmaz.son bel.li fizet.s jelenleg nem .rhet. el.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Jelentkezzen be a Chrome-ba.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):604
                                                                        Entropy (8bit):4.465685261172395
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJs25bGGs25b+WYpU34ORBHAeSJ+dgkmO8ZpU34s22C/SzFAs03OyZnLAOfTYR:1HEBaA6WYpaHFH8ZptOYOGAOf2D
                                                                        MD5:EAB2B946D1232AB98137E760954003AA
                                                                        SHA1:60BDC2937905B311D2C9844DF2D639D7AC9F7F67
                                                                        SHA-256:C6E8800450602DE0F39FE9F6854472383813FB454B08ABAE7E25A9167CE004C3
                                                                        SHA-512:970FEC9A9EF0BAF7F693C4C5977F3B47914579C5B5414FCE9DBB5E4574659A5BB9AD2DE0CC886B368F49C019785AF7D2D7FE82F71341F039EADC399ED776CA12
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pembayaran Chrome Webstore".. },.. "app_name": {.. "message": "Pembayaran Chrome Webstore".. },.. "craw_app_unavailable": {.. "message": "Aplikasi tidak tersedia saat ini.".. },.. "craw_connect_to_network": {.. "message": "Sambungkan ke jaringan.".. },.. "iap_unavailable": {.. "message": "Pembayaran Dalam Aplikasi saat ini tidak tersedia.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Harap masuk ke Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):603
                                                                        Entropy (8bit):4.479418964635223
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJsqd/bGGsqd/b+WYpU34OcX4+dgUvIO8ZpU34vq703OyZnLAOfTYsD:1HEXd/aKd/6WYpZrv58ZpskOGAOfzD
                                                                        MD5:A328EEF5E841E0C72D3CD7366899C5C8
                                                                        SHA1:2851ED658385804E87911643F5A4200B1FB26E13
                                                                        SHA-256:CD891C45F7586FB4A2514205A11F260E4A6D4482FA03D901909DD9F57BE0536D
                                                                        SHA-512:E47297896E981774EC3B59D41B89D6BA9333F6B4435EB9727D8645A46B10C7D408ADE06844871FA757382FBE7E645276449DB7B1B23BC59C9A71A5CB5A5ECC57
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pagamenti Chrome Web Store".. },.. "app_name": {.. "message": "Pagamenti Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "App al momento non disponibile.".. },.. "craw_connect_to_network": {.. "message": "Collegati a una rete.".. },.. "iap_unavailable": {.. "message": "La funzione Pagamenti In-App non . al momento disponibile.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Accedi a Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):697
                                                                        Entropy (8bit):5.20469020877498
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ07uGG07u+WYpU34DB+dgnsVztO8ZpU34MwiB03OyZnLAOfTYmSH:1HEcnDNWYp1kxU8Zp2wiqOGAOfpSH
                                                                        MD5:9B3A5D473C3F2BBFAEECE94A07A940B8
                                                                        SHA1:61BACA342CF766BBA15C7B4D892A0E7DAC9405AA
                                                                        SHA-256:706312A4A2AEF3317223F141EB2B82685345B7EED444F16BB4DF3A272716DA1F
                                                                        SHA-512:94F6FEE9A11BD890AB8211C98D1CC142348961EBCF756F66477A3E3A76519804B70BE0AE4E551739F8AFE32D7ADE6EDE04EF6B9B9EED03E3A857E6058EEDD4C6
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome ........".. },.. "app_name": {.. "message": "Chrome ........".. },.. "craw_app_unavailable": {.. "message": ".................".. },.. "craw_connect_to_network": {.. "message": "................".. },.. "iap_unavailable": {.. "message": ".......................".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Chrome ............".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):631
                                                                        Entropy (8bit):5.160315577642469
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ1GG1+WYpU34K3aT+dgh8d0HTO8ZpU34KaNkaT03OyZnLAOfTY/YeHx:1HEajWYpc3aSl0Hq8Zpc6kasOGAOfyYA
                                                                        MD5:9F6B4D82A70C74CA751E2EAE70FAB5CF
                                                                        SHA1:0534F125FFCE8222277CF2BE3401C59DAF9217F8
                                                                        SHA-256:D1467B8D037114403E8F4EFC52E88C4A7FEB96126BE4CFF883FEFF1084EF7E68
                                                                        SHA-512:ED9319830314385D09C06F62EE34186E8CA576C857981205E4468A28B3ACD2AB03384E77B866032C324ABDD97A56EFD08E2D6E0C79D563578B3EC52517819BD8
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome . ... ..".. },.. "app_name": {.. "message": "Chrome . ... ..".. },.. "craw_app_unavailable": {.. "message": ".. .. ... . .....".. },.. "craw_connect_to_network": {.. "message": "..... ......".. },.. "iap_unavailable": {.. "message": ".. .. ... ... . .....".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Chrome. .......".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):665
                                                                        Entropy (8bit):4.66839186029557
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJpqHnkGGpqHnk+WYpU346M+dgV6O8ZpU34WzSWz03OyZnLAOfTYx:1HELqHtKqHPWYpM3A8ZpwGzOGAOfg
                                                                        MD5:4CA644F875606986A9898D04BDAE3EA5
                                                                        SHA1:722A10569E93975129D67FBDB75B537D9D622AD1
                                                                        SHA-256:7C311AB751D840D750C11553C083785813E079C1D464FE568A98C9E3EF3DB96C
                                                                        SHA-512:E575E3D0622F5BD4B6C0EE79128A1B1F1882195670139D1983F4377D847141B8FB8EBB8BCED82AF3A220ED07D3577AFBE085BADC0E9C7678292B80E3EC5D3444
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": ".Chrome. internetin.s parduotuv.s mok.jimo sistema".. },.. "app_name": {.. "message": ".Chrome. internetin.s parduotuv.s mok.jimo sistema".. },.. "craw_app_unavailable": {.. "message": "Programa .iuo metu negalima.".. },.. "craw_connect_to_network": {.. "message": "Prisijunkite prie tinklo.".. },.. "iap_unavailable": {.. "message": "Mok.jimai programoje .iuo metu negalimi.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prisijunkite prie .Chrome..".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):671
                                                                        Entropy (8bit):4.631774066483956
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJFhVbGGFhVb+WYpU34wDoz+dgGedBO8ZpU34wF03OyZnLAOfTYGYID:1HENQKkWYp2Doy/em8Zp2WOGAOfRYID
                                                                        MD5:C5CE2C51391EAFD3DA9E4C71549A3C28
                                                                        SHA1:1F67FF6EF6E90C0CE3AAF56ED543A3EFD381574D
                                                                        SHA-256:1FA1DF2CA8516DEF490FB8484E9AA498ACFF80EEF5C9258FFE42D3678E6C7DED
                                                                        SHA-512:C85F6281E682F52BC2147DEA7E2F3BB4DC48D98BADA8687B05C6C7271C78EA7F5431CD51671A4184C9AE004FC53C016E3C594697F483195CCBA08A93821EEF70
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome interneta veikala maks.jumu sist.ma".. },.. "app_name": {.. "message": "Chrome interneta veikala maks.jumu sist.ma".. },.. "craw_app_unavailable": {.. "message": "Lietotne pagaid.m nav pieejama.".. },.. "craw_connect_to_network": {.. "message": "L.dzu, izveidojiet savienojumu ar t.klu.".. },.. "iap_unavailable": {.. "message": "Maks.jumi lietotn.s pa.laik nav pieejami.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "L.dzu, pierakstieties p.rl.k. Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):501
                                                                        Entropy (8bit):4.804937629013952
                                                                        Encrypted:false
                                                                        SSDEEP:12:YGGYpB928UZjdyE9iDCiop8682fURHWO/NrnLAOK:YHYpXK/iOiop8NFHWOFvAOK
                                                                        MD5:8F0168B9A546D5A99FD8A262C975C80E
                                                                        SHA1:B0718071BD0B7251D4459E9C87DF50C14622FBD6
                                                                        SHA-256:F03FA7384DF79EBA6E0274D570996030F595A3BF6B781929DD9DB6593262E41F
                                                                        SHA-512:A1191CDC496DDD7470BDCFAF186BB9488767159E0CA6A6242D195FA3351704DC8F8BBD03DBEE57D37BBD897C9E8D14B7325FB37D58AC80DEC0F972FF893758B8
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"craw_app_unavailable":{"message":"Appen er utilgjengelig for \u00f8yeblikket."},"craw_connect_to_network":{"message":"Du m\u00e5 koble til et nettverk."},"app_name":{"message":"Chrome Nettmarked-betalinger"},"app_description":{"message":"Chrome Nettmarked-betalinger"},"iap_unavailable":{"message":"Betaling i app er ikke tilgjengelig for \u00f8yeblikket."},"please_sign_in":{"message":"Du m\u00e5 logge p\u00e5 Chrome."},"jwt_retrieve_failed":{"message":"The transaction could not be completed."}}.
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:ASCII text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):615
                                                                        Entropy (8bit):4.4715318546237315
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJJQGkbGGJQGkb+WYpU34OQKJT+dgiXUmvFZO8ZpU34g7JT03OyZnLAOfTYMD:1HErxkaqxk6WYptndXI8ZpTOGAOfbD
                                                                        MD5:7A8F9D0249C680F64DEC7650A432BD57
                                                                        SHA1:53477198AEE389F6580921B4876719B400A23CA1
                                                                        SHA-256:92BE7C2DC9CFBE5A65E9CE6488D364C8D7EC19E7B67A31E4D43C1CB2B169671C
                                                                        SHA-512:969AB979546A741C0F3EDBEEB21BABA375FA8870D4FB9248CDD4C305736E332E10CAB7B64C5C078E60EC0CD73848101B390BE8F44B89C310058AF4C1CA3C8AA7
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Betalingen via Chrome Web Store".. },.. "app_name": {.. "message": "Betalingen via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "App momenteel niet beschikbaar.".. },.. "craw_connect_to_network": {.. "message": "Maak verbinding met een netwerk.".. },.. "iap_unavailable": {.. "message": "In-app-betalingen is momenteel niet beschikbaar.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Log in bij Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):636
                                                                        Entropy (8bit):4.646901997539488
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJbiVbGGbiVb+WYpU34OBHlBi9+dgQUg6O8ZpU34bdbfiIu03OyZnLAOfTYR5k:1HE5iVauiV6WYpIAYr8ZpxFiaOGAOfIC
                                                                        MD5:0E6194126AFCCD1E3098D276A7400175
                                                                        SHA1:E8127B905A640B1C46362FA6E1127BE172F4A40F
                                                                        SHA-256:E2699F98C511B18A2AFB82EAE9A4804B646C4FF1077D80E77C17A3943A6373C2
                                                                        SHA-512:A71F7C7BFBBF1E37E699601AF2E095C56CBA91F90CB7556477DF31D01B83ADFB1271E1775C9BA299FF6875BBFC2B6AB47488CC88E33DEF2F6F2E0E5AC687B777
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "P.atno.ci w sklepie Chrome Web Store".. },.. "app_name": {.. "message": "P.atno.ci w sklepie Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplikacja jest obecnie niedost.pna.".. },.. "craw_connect_to_network": {.. "message": "Po..cz si. z sieci..".. },.. "iap_unavailable": {.. "message": "P.atno.ci w ramach aplikacji s. teraz niedost.pne.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Zaloguj si. w Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):636
                                                                        Entropy (8bit):4.515158874306633
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJsc/bGGsc/b+WYpU34OLw+dgn/KzO8ZpU34FjIBMwGRO03OyZnLAOfTYN+KcY:1HEb/a8/6WYp4mZ8Zp7cKlOGAOf2tD
                                                                        MD5:86A2B91FA18B867209024C522ED665D5
                                                                        SHA1:63DEC245637818C76655E01FCB6D59784BC7184E
                                                                        SHA-256:6374880FDD1F8AF1EE8AEA6A06B73BE0AB265AFCEB4FE6F08BDE3B3989264B21
                                                                        SHA-512:DA6DBDE5028756421C2904F605632EE98831A25A1247E6238A931629B94CE8A00FD76F4235F118D2167304BD60F2C06B2AD78E54FF6CE53F8C38DF8C7B5AFCE4
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pagamentos da Chrome Web Store".. },.. "app_name": {.. "message": "Pagamentos da Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplicativo indispon.vel no momento.".. },.. "craw_connect_to_network": {.. "message": "Conecte-se a uma rede.".. },.. "iap_unavailable": {.. "message": "No momento, os Pagamentos no aplicativo n.o est.o dispon.veis.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Fa.a login no Google Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):622
                                                                        Entropy (8bit):4.526171498622949
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJsZUkbGGsZUkb+WYpU34OAE+dgqxKzO8ZpU34rEpBfvPO03OyZnLAOfTYLD:1HEmUka5Uk6WYpFvdxZ8ZpSTnPlOGAOS
                                                                        MD5:750A4800EDB93FBE56495963F9FB3B94
                                                                        SHA1:8BFB915488A4EB3CB33D68E2E59F1F8447DB7D61
                                                                        SHA-256:C1C94F65FABAF17DEF98A8587711A56D61B1E5607500E9B01F2824DB109F9E83
                                                                        SHA-512:2AEDEF5793406221BE76AF22031CE8C30AB5FAEAED09BB394C153E2EBE990C89C1A2A73B40D8A92842641AFCA8C77FFD808A2058602D3646FD8DAE2844406F24
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pagamentos via Chrome Web Store".. },.. "app_name": {.. "message": "Pagamentos via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplica..o atualmente indispon.vel.".. },.. "craw_connect_to_network": {.. "message": "Ligue-se a uma rede.".. },.. "iap_unavailable": {.. "message": "Os Pagamentos na app est.o atualmente indispon.veis.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicie sess.o no Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):641
                                                                        Entropy (8bit):4.61125938671415
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJqJrJZGGqJrJZ+WYpU344HIx2Z+dgrVPlZO8ZpU34qT7hI3O03OyZnLAOfTYU:1HEC4D8WYpKow8WV68ZpKhoOGAOfoVGD
                                                                        MD5:98D43E4B1054A65DF3FA3CC40AB6FB6D
                                                                        SHA1:46E0A21C4DA2BB5D4D8F837AE211C1B6FA26E7E2
                                                                        SHA-256:113A13900CBA62FE8AED06751971C23A80A99B47F9BE219CF884D57DB19611D9
                                                                        SHA-512:A76DC53912A4F46714926B9EA2B22E909540E447F61F6DD72607AB7B3BB5D4A9B39E525B04C33AEC53BA813D14AC1FB5827275B2524E52B693E83171E1CD1466
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pl..i prin Magazinul web Chrome".. },.. "app_name": {.. "message": "Pl..i prin Magazinul web Chrome".. },.. "craw_app_unavailable": {.. "message": ".n prezent, aplica.ia nu este disponibil..".. },.. "craw_connect_to_network": {.. "message": "Conecteaz.-te la o re.ea.".. },.. "iap_unavailable": {.. "message": "Pl..ile .n aplica.ie nu sunt disponibile momentan.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Conecteaz.-te la Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):744
                                                                        Entropy (8bit):4.918620852166656
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ7OJHZMSl3ZGG7OJHZMSl3Z+WYpU34zWJ2F+dgVtLSv/TO8ZpU347NWjT03On:1HElOJHZMq4uOJHZMq8WYpdWJ/YGHq8m
                                                                        MD5:DB2EDF1465946C06BD95C71A1E13AE64
                                                                        SHA1:FB4F3ECE9ECECEBBC6CA2A592A15FB9C1FDFB811
                                                                        SHA-256:FBAF22CE6E16DE174CED8CB5EA3098CCA1C3426A2111FF33BD3E64DA64ED67AB
                                                                        SHA-512:4E0CF00BAEF1757548DEB17BBE1AF55770A0A0F7351779EF55C7DEFA6D112D0227B8865C2C22E0EC62E6E2F1C8E1632A2D0CE6828D25C5ABBF143C990116F632
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "......... ....... ........-........ Chrome".. },.. "app_name": {.. "message": "......... ....... ........-........ Chrome".. },.. "craw_app_unavailable": {.. "message": ".......... ...........".. },.. "craw_connect_to_network": {.. "message": "............ . .....".. },.. "iap_unavailable": {.. "message": "....... ..... .......... ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "....... . Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):647
                                                                        Entropy (8bit):4.640777810668463
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJfZGGfZ+WYpU34ORO+dgmmCO8ZpU34yH7u2Z03OyZnLAOfTYCUAi0D:1HEl4G8WYpetPmD8ZpcH7aOGAOfzUeD
                                                                        MD5:8DF215D1EFBDABB175CCDD68ED8DCB0A
                                                                        SHA1:2B374462137A38589A73FDD00A84CBDC7E50F9F4
                                                                        SHA-256:7FA16AF97E6CFC52EC6008EB679D3F30E7E0C24F9EF2D18A9228EAF4DED9D63B
                                                                        SHA-512:C0E623343BDAEB4731800D183B59F2FCFE285F0C7153EC99641FD84F2F2DCFE47D21E73F3D28B1240340453C5668EB0AFFBE087AAB62F1C88CD2A40CC44E599D
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "app_name": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplik.cia moment.lne nie je dostupn..".. },.. "craw_connect_to_network": {.. "message": "Pripojte sa k sieti.".. },.. "iap_unavailable": {.. "message": "Platby v aplik.cii moment.lne nie s. k dispoz.cii.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prihl.ste sa do prehliada.a Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):617
                                                                        Entropy (8bit):4.5101656584816885
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJGcyvmbZGGGcyvmbZ+WYpU34OBOEtf+dgca1ZO8ZpU34GcQArERff03OyZnLh:1HE4cyY4TcyY8WYpNoWa1w8ZpQcQ6AfK
                                                                        MD5:3943FA2A647AECEDFD685408B27139EE
                                                                        SHA1:0129DD19D28373359530B3B477FE8A9279DABB7D
                                                                        SHA-256:18AFF072EE0DF7C3495045435C752A805606E6D5D462EF2321C443F1773F4B3A
                                                                        SHA-512:42E62B3855611FF2E1D39C11404CB1A09825EE4CA6A8ACB3FF538B4574388F549E3BD79137DD4DC128A8DC44DD270D7D878E4AAD20DA8250A5C25297B0DEC09D
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Pla.ila v spletni trgovini Chrome".. },.. "app_name": {.. "message": "Pla.ila v spletni trgovini Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikacija trenutno ni na voljo.".. },.. "craw_connect_to_network": {.. "message": "Pove.ite se z omre.jem.".. },.. "iap_unavailable": {.. "message": "Pla.ila v aplikacijah trenutno niso na voljo.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prijavite se v Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):743
                                                                        Entropy (8bit):4.913927107235852
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJssbdOGGssbdO+WYpU347xBP+dgcucO8ZpU34s1muP03OyZnLAOfTYzDYD:1HEKsb59sbTWYplx4Xud8Zpy1mNOGAOv
                                                                        MD5:D485DF17F085B6A37125694F85646FD0
                                                                        SHA1:24D51D8642CDC6EFD5D8D7A4430232D8CDE25108
                                                                        SHA-256:7FFDE34C58E7C376C042DE64DEF6481DAE32BE8B70F0B18EDF536290CBE0C818
                                                                        SHA-512:0DDECFD860E99290B6C3AAA04F510272AE081CF2D93ED5832D9D6378EC9D36177FFBE213471247FB94721EA34A83E7665669200047091D0FDE134E3D763217E7
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "....... . Chrome ...-..........".. },.. "app_name": {.. "message": "....... . Chrome ...-..........".. },.. "craw_app_unavailable": {.. "message": ".......... .. ........ ...........".. },.. "craw_connect_to_network": {.. "message": "........ .. .......".. },.. "iap_unavailable": {.. "message": "....... . .......... .. ........ ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "......... .. . Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):630
                                                                        Entropy (8bit):4.52964089437422
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJJMkbGGJMkb+WYpU34OACwz+dgNPGFZO8ZpU34JgpXLSb03OyZnLAOfTYLdID:1HErMkaqMk6WYpTOcb8ZpDgdZOGAOf8Y
                                                                        MD5:D372B8204EB743E16F45C7CBD3CAAF37
                                                                        SHA1:C96C57219D292B01016B37DCF82E7C79AD0DD1E8
                                                                        SHA-256:B8BA77E0089B0676545EC16D32468B727812B444F90B33A7A5B748E6C36C4388
                                                                        SHA-512:33640529E0D5DCC5CA4BDB0615A2818E8D26C6FCB7B3474C08AC3EB67B9DB40E1F0A79954ED20728CD47A686D2533DCBC76ABCBDB917F8530C8DE8BBA687352E
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Betalning via Chrome Web Store".. },.. "app_name": {.. "message": "Betalning via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Appen .r inte tillg.nglig f.r tillf.llet.".. },.. "craw_connect_to_network": {.. "message": "Anslut till ett n.tverk.".. },.. "iap_unavailable": {.. "message": "Betalning i appen .r inte tillg.ngligt f.r n.rvarande.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Logga in i Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):945
                                                                        Entropy (8bit):4.801079428724355
                                                                        Encrypted:false
                                                                        SSDEEP:24:1HEKa1dDa1/WYp6UFi72SmlG8ZpyactrW2SAOGAOfvSLD:WK2DNYp6U4y3bpyLxwGFW
                                                                        MD5:83E2D1E97791A4B2C5C69926EFB629C9
                                                                        SHA1:429600425CB0F196DDD717F940E94DBD8BFF2837
                                                                        SHA-256:2FECA577F43D97BAEEA464741D585892103585208FD0A935B810A03BDCE83C88
                                                                        SHA-512:60A5928DAA8CB4341487F477C56B5A98B83EDE50E5F4F55A802E01FDDAB86F3E795D391953D3D9214552D14D3F58C5A183693C613720FC12FC387D7B8F9B9AB6
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "............... Chrome .........".. },.. "app_name": {.. "message": "............... Chrome .........".. },.. "craw_app_unavailable": {.. "message": ".............................".. },.. "craw_connect_to_network": {.. "message": ".........................".. },.. "iap_unavailable": {.. "message": "...............................................".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "................. Chrome".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):631
                                                                        Entropy (8bit):4.710869622361971
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ9Y8GG9Y8+WYpU34wWT+dgGb0GO8ZpU34wryd7T03OyZnLAOfTYGbPKG:1HE0jWYpyRnG8Zpyr/OGAOfFPn
                                                                        MD5:2CEAE0567B6BB1D240BBAD690A98CA3B
                                                                        SHA1:5944346FBD4A0797B13223895995CAB58E9ECD23
                                                                        SHA-256:A7CB86F30C9C31FE5540282C308BA96ADB4EC16EF98C87129EB88105E5BEF5FC
                                                                        SHA-512:108A07C6D03D7178E8D0FFEF5349E0249A898D864964FED8757BD8A08BC1C6D9613F2A6C01AA34A6606127D1C6CE14C229FA02586677DBB060B85E3E845950E1
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome Web Ma.azas. .demeleri".. },.. "app_name": {.. "message": "Chrome Web Ma.azas. .demeleri".. },.. "craw_app_unavailable": {.. "message": "Uygulama .u anda kullan.lam.yor.".. },.. "craw_connect_to_network": {.. "message": "L.tfen bir a.a ba.lan.n.".. },.. "iap_unavailable": {.. "message": "Uygulama ..i .demeler .u anda kullan.lamaz.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "L.tfen Chrome'da oturum a..n.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):720
                                                                        Entropy (8bit):4.977397623063544
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ7wILkSlXZGG7wILkSlXZ+WYpU34zb1Oy2P+dgSV1EjiTO8ZpU347qtfP2CTW:1HElwEkK4uwEkK8WYpd/dTV1e8Zptq5S
                                                                        MD5:AB0B56120E6B38C42CC3612BE948EF50
                                                                        SHA1:8B3F520E5713D9F116D68E71DAEED1F6E8D74629
                                                                        SHA-256:68ABA284751EB9C856032062EF9B1651E2A1E5CE5FDA0977FFC97D63BA7BED9E
                                                                        SHA-512:CD852A58217F739C1CD58567FF432D31A7AD3F68C884ABBA1DA95799BCD1545C6A5D3B06F319681C12B78AD0A709828DE4B22736316F148D21F5DB76A5BCCBEF
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "....... ...-........ Chrome".. },.. "app_name": {.. "message": "....... ...-........ Chrome".. },.. "craw_app_unavailable": {.. "message": "........ ......... ...........".. },.. "craw_connect_to_network": {.. "message": "............. .. .......".. },.. "iap_unavailable": {.. "message": "....... ..... ........ ..... .. .........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "........ . Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):695
                                                                        Entropy (8bit):4.855375139026009
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJMAZrSFZGGMAZrSFZ+WYpU34WFHoz+dgdklzoO8ZpU34NFHoz03OyZnLAOfTU:1HEI4B8WYpAKytFZ8ZpXKMOGAOfd6D
                                                                        MD5:7EBB677FEAD8557D3676505225A7249A
                                                                        SHA1:F161B4B6001AEAEAB246FF8987F4D992B48D47BE
                                                                        SHA-256:051F96ED874C11C4A13589B5F68964E4F5B03B52DDA223D56524F2CA23760C04
                                                                        SHA-512:74FD267CF7E299FB8E7054605C3F651F057F676FF865082FA24F4916755456768DB0DA62DBC515D829B48AB1F9CFC8AD3E841DCBF1F194D5CB14C5335A192A0D
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Thanh to.n tr.n c.a h.ng Chrome tr.c tuy.n".. },.. "app_name": {.. "message": "Thanh to.n tr.n c.a h.ng Chrome tr.c tuy.n".. },.. "craw_app_unavailable": {.. "message": ".ng d.ng hi.n kh.ng kh. d.ng.".. },.. "craw_connect_to_network": {.. "message": "Vui l.ng k.t n.i v.i m.ng.".. },.. "iap_unavailable": {.. "message": "Thanh to.n trong .ng d.ng hi.n kh.ng kh. d.ng.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Vui l.ng ..ng nh.p v.o Chrome.".. }..}..
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):595
                                                                        Entropy (8bit):5.210259193489374
                                                                        Encrypted:false
                                                                        SSDEEP:12:1HEJ01GG01+WYpU34zeHz+dgfO8ZpU34YKiO03OyZnLAOfTYB6U:1HEpIWYpISv8Zp+JOGAOfa6U
                                                                        MD5:BB73BF561BB79F89D9BF7C67C5AE5C65
                                                                        SHA1:2FADD3A1959B29C44830033A35C637D0311A8C9C
                                                                        SHA-256:D804F2A040D21D7511EFD5213D8E1721D64964A1A0DBB48E21622CEEDC9D967E
                                                                        SHA-512:627D44CEF1FE5C5ABD598BD47FF5E22B9EFC1CF98DDE3868FA9E5896C134A0C9C055AC34EDDADAE56B6690E51AEA89965D38F770552A85C732CC796795DC68D2
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{.. "app_description": {.. "message": "Chrome .........".. },.. "app_name": {.. "message": "Chrome .........".. },.. "craw_app_unavailable": {.. "message": ".........".. },.. "craw_connect_to_network": {.. "message": ".......".. },.. "iap_unavailable": {.. "message": "............".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "... Chrome.".. }..}..
                                                                        No static file info
                                                                        • Total Packets: 55
                                                                        • 443 (HTTPS)
                                                                        • 53 (DNS)
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Aug 19, 2022 00:19:07.496454000 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.496514082 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.496603012 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.497486115 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.497523069 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.498107910 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.498167992 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.498301029 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.499372005 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.499420881 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.499507904 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.499825001 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.499855995 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.500075102 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.500102043 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.504746914 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.504781961 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.504873991 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.505093098 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.505110025 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.560954094 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.562632084 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.567148924 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.567188978 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.567368031 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.567414999 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.567781925 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.567883968 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.568707943 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.568732023 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.568856955 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.568857908 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.584569931 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.587667942 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.595036030 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.595061064 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.595593929 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.595639944 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.596479893 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.596564054 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.597978115 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.598098993 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.762181997 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.762579918 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.762670040 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.763503075 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.763740063 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.763827085 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.763843060 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.764028072 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.764224052 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.764394999 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.764424086 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.764539957 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.764811039 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.794013023 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.794128895 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.794156075 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.794178963 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.794236898 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.798137903 CEST50703443192.168.2.3142.250.185.238
                                                                        Aug 19, 2022 00:19:07.798171043 CEST44350703142.250.185.238192.168.2.3
                                                                        Aug 19, 2022 00:19:07.804730892 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.804733038 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.804747105 CEST44363292172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:07.804820061 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:07.814809084 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.815009117 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.815103054 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.817189932 CEST52628443192.168.2.3142.250.186.77
                                                                        Aug 19, 2022 00:19:07.817219019 CEST44352628142.250.186.77192.168.2.3
                                                                        Aug 19, 2022 00:19:07.849371910 CEST63292443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:08.719856977 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:08.720161915 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:08.720266104 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:08.725105047 CEST61356443192.168.2.3172.67.188.125
                                                                        Aug 19, 2022 00:19:08.725159883 CEST44361356172.67.188.125192.168.2.3
                                                                        Aug 19, 2022 00:19:09.164355040 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.164408922 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.164525986 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.164763927 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.164783001 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.308679104 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.312486887 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.312532902 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.313761950 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.313853025 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.317310095 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.317429066 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.317836046 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.317848921 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.449947119 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.973036051 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.973078012 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.973154068 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:09.973196983 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.973225117 CEST443532945.101.152.35192.168.2.3
                                                                        Aug 19, 2022 00:19:09.973303080 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:10.008393049 CEST53294443192.168.2.35.101.152.35
                                                                        Aug 19, 2022 00:19:10.008457899 CEST443532945.101.152.35192.168.2.3
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Aug 19, 2022 00:19:07.436379910 CEST5808453192.168.2.31.1.1.1
                                                                        Aug 19, 2022 00:19:07.475795984 CEST5865253192.168.2.31.1.1.1
                                                                        Aug 19, 2022 00:19:07.476946115 CEST5535553192.168.2.31.1.1.1
                                                                        Aug 19, 2022 00:19:07.483067989 CEST53580841.1.1.1192.168.2.3
                                                                        Aug 19, 2022 00:19:07.493196964 CEST53586521.1.1.1192.168.2.3
                                                                        Aug 19, 2022 00:19:07.494203091 CEST53553551.1.1.1192.168.2.3
                                                                        Aug 19, 2022 00:19:08.734603882 CEST5541653192.168.2.31.1.1.1
                                                                        Aug 19, 2022 00:19:09.127779961 CEST53554161.1.1.1192.168.2.3
                                                                        Aug 19, 2022 00:19:11.946537018 CEST5124953192.168.2.31.1.1.1
                                                                        Aug 19, 2022 00:19:12.103116989 CEST53512491.1.1.1192.168.2.3
                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                        Aug 19, 2022 00:19:07.436379910 CEST192.168.2.31.1.1.10x624dStandard query (0)kutt.itA (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.475795984 CEST192.168.2.31.1.1.10xdaf8Standard query (0)clients2.google.comA (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.476946115 CEST192.168.2.31.1.1.10x27ddStandard query (0)accounts.google.comA (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:08.734603882 CEST192.168.2.31.1.1.10x3fb3Standard query (0)internet-cheboksary.ruA (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:11.946537018 CEST192.168.2.31.1.1.10x7a0eStandard query (0)internet-cheboksary.ruA (IP address)IN (0x0001)
                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                        Aug 19, 2022 00:19:07.483067989 CEST1.1.1.1192.168.2.30x624dNo error (0)kutt.it172.67.188.125A (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.483067989 CEST1.1.1.1192.168.2.30x624dNo error (0)kutt.it104.21.43.235A (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.493196964 CEST1.1.1.1192.168.2.30xdaf8No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.493196964 CEST1.1.1.1192.168.2.30xdaf8No error (0)clients.l.google.com142.250.185.238A (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:07.494203091 CEST1.1.1.1192.168.2.30x27ddNo error (0)accounts.google.com142.250.186.77A (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:09.127779961 CEST1.1.1.1192.168.2.30x3fb3No error (0)internet-cheboksary.ru5.101.152.35A (IP address)IN (0x0001)
                                                                        Aug 19, 2022 00:19:12.103116989 CEST1.1.1.1192.168.2.30x7a0eNo error (0)internet-cheboksary.ru5.101.152.35A (IP address)IN (0x0001)
                                                                        • clients2.google.com
                                                                        • accounts.google.com
                                                                        • kutt.it
                                                                        • internet-cheboksary.ru
                                                                        • https:
                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        0192.168.2.350703142.250.185.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:07 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=92.0.4515.107&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                                                        Host: clients2.google.com
                                                                        Connection: keep-alive
                                                                        X-Goog-Update-Interactivity: fg
                                                                        X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfm
                                                                        X-Goog-Update-Updater: chromecrx-92.0.4515.107
                                                                        Sec-Fetch-Site: none
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: empty
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        2022-08-18 22:19:07 UTC1INHTTP/1.1 200 OK
                                                                        Content-Security-Policy: script-src 'report-sample' 'nonce-k_y9kWi5OB9V9j2897pcEw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                                                        Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                        Pragma: no-cache
                                                                        Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                        Date: Thu, 18 Aug 2022 22:19:07 GMT
                                                                        Content-Type: text/xml; charset=UTF-8
                                                                        X-Daynum: 5708
                                                                        X-Daystart: 55147
                                                                        X-Content-Type-Options: nosniff
                                                                        X-Frame-Options: SAMEORIGIN
                                                                        X-XSS-Protection: 1; mode=block
                                                                        Server: GSE
                                                                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                        Accept-Ranges: none
                                                                        Vary: Accept-Encoding
                                                                        Connection: close
                                                                        Transfer-Encoding: chunked
                                                                        2022-08-18 22:19:07 UTC2INData Raw: 33 31 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 37 30 38 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 35 31 34 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                                                        Data Ascii: 31a<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5708" elapsed_seconds="55147"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                                                        2022-08-18 22:19:07 UTC3INData Raw: 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 61 70
                                                                        Data Ascii: mhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app><ap
                                                                        2022-08-18 22:19:07 UTC3INData Raw: 30 0d 0a 0d 0a
                                                                        Data Ascii: 0


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        1192.168.2.352628142.250.186.77443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:07 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                                                        Host: accounts.google.com
                                                                        Connection: keep-alive
                                                                        Content-Length: 1
                                                                        Origin: https://www.google.com
                                                                        Content-Type: application/x-www-form-urlencoded
                                                                        Sec-Fetch-Site: none
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: empty
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: CONSENT=PENDING+620
                                                                        2022-08-18 22:19:07 UTC1OUTData Raw: 20
                                                                        Data Ascii:
                                                                        2022-08-18 22:19:07 UTC3INHTTP/1.1 200 OK
                                                                        Content-Type: application/json; charset=utf-8
                                                                        Access-Control-Allow-Origin: https://www.google.com
                                                                        Access-Control-Allow-Credentials: true
                                                                        X-Content-Type-Options: nosniff
                                                                        Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                        Pragma: no-cache
                                                                        Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                        Date: Thu, 18 Aug 2022 22:19:07 GMT
                                                                        Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                        Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                                                        Content-Security-Policy: script-src 'report-sample' 'nonce-rVSmkPEQjogcxRi9eYOw1g' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                                                        Content-Security-Policy: script-src 'nonce-rVSmkPEQjogcxRi9eYOw1g' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport
                                                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                        Cross-Origin-Opener-Policy: same-origin
                                                                        Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                                        Server: ESF
                                                                        X-XSS-Protection: 0
                                                                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                        Accept-Ranges: none
                                                                        Vary: Accept-Encoding
                                                                        Connection: close
                                                                        Transfer-Encoding: chunked
                                                                        2022-08-18 22:19:07 UTC5INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                                                        Data Ascii: 11["gaia.l.a.r",[]]
                                                                        2022-08-18 22:19:07 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                        Data Ascii: 0


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        10192.168.2.3619565.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:12 UTC333OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/favicon.ico HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:19:12 UTC333INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:12 GMT
                                                                        Content-Type: image/x-icon
                                                                        Content-Length: 894
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-37e"
                                                                        Expires: Sat, 17 Sep 2022 22:19:12 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:12 UTC333INData Raw: 00 00 01 00 01 00 10 10 00 00 01 00 18 00 68 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 18 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 5f 01 f1 7d 00 ef 7e 00 ef 7e 00 f3 7d 00 f0 7c 00 f1 7a 00 f1 7a 00 ef 77 00 f0 78 01 f0 75 01 ef 74 00 ef 72 00 ee 70 00 ed 70 00 ed 71 00 d6 69 00 f9 8a 00 f9 8a 00 f7 8a 00 fa 87 00 f8 88 00 f8 88 00 f9 86 00 f7 84 00 f6 81 00 f7 7f 01 f7 7e 00 f6 7d 00 f5 7a 00 f6 78 01 f6 78 01 db 6f 00 fc 91 00 ff 92 00 fc 91 00 fe 91 00 fb 8f 01 fc 8d 01 fd 8b 02 fa 88 00 f9 86 00 fa 84 01 f9 81 00 f8 80 00 f8 7c 00 f7 7a 00 f8 78 01 de 75 00 fe 99 01 ff 9a 01 ff 9b 00 ff 9b 00 fe 97 00 fc 95 00 ff 92 00 fc 8e 00 fb 8c 02 fa 87 01 fa 84 01 f8 82 00 f8 80 00 f8 7c 00 f7 7a 00 df
                                                                        Data Ascii: h( _}~~}|zzwxutrppqi~}zxxo|zxu|z


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        11192.168.2.3619585.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:12 UTC342OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/main.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:19:12 UTC343INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:12 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 247287
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-3c5f7"
                                                                        Expires: Sat, 17 Sep 2022 22:19:12 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:12 UTC343INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 45 00 00 02 34 08 06 00 00 00 3a 3b 48 26 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec fd 07 7c 9c e5 99 fd 8d 0b dc ad 6a f5 de 7b ef bd b7 51 ef bd 77 c9 6a 96 65 cb b2 e5 de c1 36 18 70 c1 54 d3 4d 07 d3 0c a1 97 40 48 23 24 d9 90 2d ef b2 e5 f7 6e de ff 6e 7e cb 66 53 20 f5 fc cf 7d 4b 23 cb c6 04 88 b1 90 cd 35 f9 5c 99 d1 94 67 9e e7 7e 2e 8b 99 af ce 75 8e c9 2f ff ef 7f 43 4a d6 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a e0 9b d2 03 26 df 94 03 95 e3 94 7f d4 d2 03 d2 03 d2 03 d2 03 d2 03 d2
                                                                        Data Ascii: PNGIHDRE4:;H&sRGBgAMAapHYsodIDATx^|j{Qwje6pTM@H#$-nn~fS }K#5\g~.u/CJ@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z&
                                                                        2022-08-18 22:19:12 UTC359INData Raw: dc a8 4c 76 51 10 94 be b5 8e bc cf 8a ff 36 ac 1c 5d 61 e5 e2 01 5b 2a 42 ed f8 1c 3b bf 20 d8 52 3d 6a e3 4d 2b 02 af 80 d9 b2 70 f3 85 15 95 a3 1e e1 b1 48 2e 28 47 63 df 08 c6 b6 ec 46 cf da 0d da 57 b4 6d fd 06 54 8d 8c 20 9b a3 fa 46 28 fa c2 5b ef 6a 28 fa d8 b3 2f 6b 5f 51 81 a2 f2 7d e3 52 7f df 90 ed 4b 8f 49 0f 7c b9 1e 10 28 2a 50 54 fe 4a 21 3d 20 3d 30 4f 3d 20 50 54 a0 d5 c5 40 2b 79 ad f4 cf a5 ec 81 cb 1d 8a fa 66 47 40 81 51 6f 02 2a 2b 3f 4f 0d e9 16 db 50 bd 68 4d c5 22 6b b9 35 61 a8 aa 99 04 fa b9 01 4b 97 0a 8a ea ed 5a 11 1c b2 96 b3 cc 08 1a 3d 7c dd 91 4b 25 63 5b 63 05 5a 6b ca 50 55 51 46 28 5a 83 ca 9a 26 ad 16 cd 63 6a 75 5e 01 bd 41 39 0a 5e 41 7f d0 aa fa 22 2a 49 73 90 41 95 60 1c 15 89 11 1c 89 0e a3 2f a4 67 02 47 7d e3
                                                                        Data Ascii: LvQ6]a[*B; R=jM+pH.(GcFWmT F([j(/k_Q}RKI|(*PTJ!= =0O= PT@+yfG@Qo*+?OPhM"k5aKZ=|K%c[cZkPUQF(Z&cju^A9^A"*IsA`/gG}
                                                                        2022-08-18 22:19:12 UTC407INData Raw: 0e 5c 83 b5 7b 77 a3 76 f5 6a 0c 53 29 aa 3c 45 35 14 fd fe fb 78 fe 95 37 71 fa cc 4b 78 e6 5b 92 3e 7f 39 7e 86 97 7d 96 ef 9e d2 03 57 6e 0f 08 14 15 28 2a 7f a5 90 1e 90 1e 98 a7 1e 10 28 2a 50 eb 52 42 2d d9 b6 f4 d7 c5 f4 c0 95 06 45 4b 6a 4a 90 98 91 01 07 0f bf 73 a0 a8 29 81 a8 2a 23 14 d5 5e 9f e7 41 51 a5 04 b5 65 02 f5 47 9f fc 01 bf a7 a6 eb 2f ac 8f ff 7c 6e bd fe 9d ef 62 df a1 c3 48 ce 62 72 37 e1 a0 52 5b ae 62 da b6 ba 6d ae c6 f4 a9 b0 54 c0 34 30 34 0c 87 6e b8 11 ef fe e8 47 f8 dd 9f fe 84 3f cd 68 c4 fe e5 5f fe 09 8f 3d 7c 1f d6 ad 1d 41 53 13 41 4d 49 85 06 a2 c5 a5 e5 28 ab a8 c4 fb 3f fd c9 4c bd cf eb f7 30 b5 75 12 4d 54 29 d6 37 55 51 39 9a a7 61 e8 63 a7 1f c2 4f 3e 78 0f ef fe e0 db 78 fb dd d7 99 28 9e a5 c7 ed 7f ff a7 df
                                                                        Data Ascii: \{wvjS)<E5x7qKx[>9~}Wn(*(*PRB-EKjJs)*#^AQeG/|nbHbr7R[bmT404nG?h_=|ASAMI(?L0uMT)7UQ9acO>xx(
                                                                        2022-08-18 22:19:12 UTC423INData Raw: d7 d0 68 84 87 b0 7d 3e 2c 1a ad 41 51 54 8a 16 e2 c6 fe b9 b8 7b d7 2d b8 ff f0 51 3c fa c0 a3 78 f4 f4 39 9c a0 1f e9 9d 84 a4 07 4f 9e c0 fd 67 cf 52 35 7a 04 fb 6e 39 88 3b ee 3b 89 47 9f 7d 89 e9 f3 ef e0 b9 37 7e a4 b5 cf 6b df bb 35 21 8a 36 07 b4 39 f0 2d 9c 03 1a 14 fd 16 5e 94 6f 1b c8 d1 8e 47 83 8b da 1c f8 db cc 01 0d 8a 6a d0 ea af 81 56 da 6b b5 f9 f3 f7 9c 03 ff ec 50 34 95 e1 4a 52 99 15 39 c8 aa cc 45 6e 6d 31 32 cb 0b 10 98 10 ad a0 9b 40 19 81 a1 36 1e 3e b0 72 f3 84 85 93 3b 5b e8 5d 55 99 d8 eb fc 45 f5 de a2 a2 7e b4 71 72 a3 a2 d2 05 06 53 8d 74 01 44 e3 45 b5 a8 80 d1 09 25 c0 54 94 a4 52 56 f6 f4 4e 34 31 55 ad f3 d6 92 74 cf 56 79 a5 12 35 b1 21 18 65 1a b7 c1 54 4c 32 32 45 70 78 04 3a 99 62 dd 37 dc 8f 61 82 1b 69 8b 2f 2c 2e
                                                                        Data Ascii: h}>,AQT{-Q<x9OgR5zn9;;G}7~k5!69-^oGjVkP4JR9Enm12@6>r;[]UE~qrStDE%TRVN41UtVy5!eTL22Epx:b7ai/,.
                                                                        2022-08-18 22:19:12 UTC439INData Raw: 00 ce 6f 98 83 a7 57 8e e2 99 c5 54 0e cf ed c0 91 d1 06 dc 32 a3 14 ab 6a 12 b0 ae 39 1d bb 18 62 75 68 51 37 f6 cf eb c0 ae c1 3a dc d8 53 82 bd 83 e5 38 b6 b0 0d c7 17 f7 e0 d6 d9 1d c8 0a f2 82 b1 89 05 55 a8 2e f4 12 75 57 35 11 8a 8a 5d 45 40 70 00 fa d9 66 bf b6 3b 1f 0b 0b 83 71 80 00 76 35 e7 e8 5d 4b fa a9 10 7d 1b e7 8f 1c 84 af 07 8f 6d 8a 03 2c fd a9 bc 0c 4c 66 31 c4 28 88 e0 97 6b 7b 5f da 28 d0 2f d5 25 32 1e 16 3e 01 70 0e 0c 45 7d 6b 17 ae 5f bd 19 3b b7 ec c1 9e db ee c1 ae 3b 8f 10 80 ee a5 8f e8 6a 74 cd 5d 80 99 cb 57 62 dd 8e 1d 58 bb 7b 07 ca 66 74 c3 29 31 0a 06 01 5e 54 78 26 20 ae be 1a d9 5d 6d c8 ee 6b 47 7c 7b 1d 42 f9 c3 83 24 cc 5b 14 f1 47 16 2a 7f 93 7a 9b 11 c7 cf 9c 67 3d ad 01 0a d3 60 95 1c 8d 49 be 9e 30 f0 e2 df 92
                                                                        Data Ascii: oWT2j9buhQ7:S8U.uW5]E@pf;qv5]K}m,Lf1(k{_(/%2>pE}k_;;jt]WbX{ft)1^Tx& ]mkG|{B$[G*zg=`I0
                                                                        2022-08-18 22:19:12 UTC490INData Raw: a1 a1 85 76 03 dd 35 3c df 66 cc 60 70 52 ff 9c 4e f4 31 3c a9 7d a0 01 75 7d d5 84 a0 f4 56 6d 2b 24 10 2d a2 37 68 31 4a 3b 4a 50 d5 5b a9 94 a2 5d f3 09 a8 17 0d 60 60 e9 4c f4 2f 1e c5 c0 92 39 5c cf 45 cf fc 51 b4 cf 19 66 ba fc 00 5a a9 1a 15 58 5a 4b 65 6e 6e 73 0d 12 ca 72 91 d7 58 81 aa be 56 54 ce 68 55 50 34 bf a3 16 b1 15 b9 08 ce 4b 42 68 41 2a 82 73 53 18 ea c4 a4 fa d6 06 2a 30 4f e0 ee 13 27 b1 6b ff 01 3c f8 e8 23 b8 6d c7 36 cc e2 7f 7f 47 b2 32 31 98 9b 8a 91 ca 3c 94 a7 47 61 70 a0 03 7e 31 91 98 c2 b4 76 03 fe b7 d7 d8 c5 1d 76 de 81 b0 f7 09 c2 64 7b 37 aa 6a 7d 30 d9 89 30 93 1e 9b 06 56 b2 0d 1f 73 f5 85 95 5f 98 52 88 3a 86 c4 2b d5 a8 40 51 d9 ce d8 3d 70 dc 4b 54 5a e6 05 86 da 7a 86 a8 32 92 a0 25 73 27 cc 5c b2 0e b7 dc 7d 1c
                                                                        Data Ascii: v5<f`pRN1<}u}Vm+$-7h1J;JP[]``L/9\EQfZXZKennsrXVThUP4KBhA*sS*0O'k<#m6G21<Gap~1vvd{7j}00Vs_R:+@Q=pKTZz2%s'\}
                                                                        2022-08-18 22:19:12 UTC506INData Raw: 33 b1 6f e3 3c ec da b4 40 d5 c1 ad 0b b0 73 c5 68 ec 5d 35 10 fb 57 f5 c7 e1 15 c3 b1 7e 51 25 86 8e ab 42 ec 80 e1 08 a3 82 37 98 50 b9 79 ef 01 68 5b 3c 12 1d fb 8c 40 48 7c 77 98 78 50 a5 1a 18 85 b6 f1 a9 e8 db 29 0b 23 bb 64 60 04 53 c6 f3 22 5b a2 77 87 0e 18 39 aa 02 41 91 91 0a 80 0a 14 ad 47 30 ae 27 ef f9 bf 09 45 05 98 2a 1f 52 26 d6 0b 1c ad 85 a2 1c bd b7 66 b2 fc 83 f1 79 1d 14 15 f5 a7 0e 8a 1a 38 f8 fd 46 29 fa af a0 68 42 6a 16 26 cc a9 c1 d8 99 d5 18 3d 79 1e e6 2c 5e fb 2f 95 a2 e2 29 fa 50 29 ca 74 7a 81 a2 c6 1c eb 97 31 f4 7f 05 46 8d e8 e7 29 8f 69 de 3a 11 fd 4a 46 21 93 81 54 5d 7b 16 62 ce d2 8d 68 9b 9e 4f 00 ea c9 cf 27 3d 3a 1d 24 59 be 76 d4 5f 77 bc b2 94 eb bf 07 a3 3a 38 2a 4b 01 a6 72 ff a3 a5 60 f0 03 78 aa 83 a2 02 46
                                                                        Data Ascii: 3o<@sh]5W~Q%B7Pyh[<@H|wxP)#d`S"[w9AG0'E*R&fy8F)hBj&=y,^/)P)tz1F)i:JF!T]{bhO'=:$Yv_w:8*Kr`xF
                                                                        2022-08-18 22:19:12 UTC522INData Raw: 63 e6 a8 a0 68 ef 76 b1 48 8b 89 80 b9 1d fd 44 05 8a f2 f3 a8 67 e7 82 3a 0c 25 32 a0 4a b4 be a1 39 7c 7d 02 10 15 11 07 67 7b 77 04 fa 05 21 98 3f 6e 94 27 45 e2 d9 31 03 b1 79 70 3e 56 0d c8 c5 e2 c1 d9 d8 3e 69 20 8e ce 1a 8a 23 53 8a b1 b7 aa 37 76 8c ea a5 96 1b 4a d2 b1 a3 32 97 aa d2 fe 78 6d 29 61 e8 9a f1 78 7f e3 14 bc 45 20 fa ca b2 51 78 69 49 b9 aa 57 96 94 e1 e5 ea 12 3c 37 67 20 f6 4f 2d c4 ae f1 4c 9e e7 68 fd da b1 05 88 0e 0b 85 b1 85 0b cc 6c 7d 61 e5 d2 10 d6 fe 0c 1c 0b 24 a4 6d e2 81 a8 50 7f fe a0 11 86 e6 51 ad d0 24 2a 8a ca f3 86 ea c7 95 7a d6 b6 30 f1 f0 86 85 4f 03 d8 51 2d ed e8 df 48 95 2b fd 74 9d 03 1a c3 da cb 47 83 a2 da f7 6f 4d 90 a2 f5 80 d6 03 4f 50 0f 68 50 f4 09 7a 33 34 68 a6 41 33 ad 07 fe b7 7b 40 83 a2 1a 78
                                                                        Data Ascii: chvHDg:%2J9|}g{w!?n'E1yp>V>i #S7vJ2xm)axE QxiIW<7g O-Lhl}a$mPQ$*z0OQ-H+tGoMOPhPz34hA3{@x
                                                                        2022-08-18 22:19:12 UTC538INData Raw: f2 cb 0b 1c ee 26 5b e7 d7 56 16 b0 be ba 88 9d d3 5b 2c 9e ba 80 8e a1 29 58 b8 06 50 f1 e9 86 63 84 a2 2a 35 e8 31 0b 17 7e ec c2 cc 50 57 99 1d aa 82 a1 22 4f 54 0e c1 a8 9e b5 07 8c 9d fc 69 97 0f 40 2c 55 a2 8d bc af 99 d3 17 31 bc b4 c1 9c cf 62 e4 11 8e 5e b8 7e 0f 4f df 7f 43 b6 cc 8b ec 50 71 7c f6 fe 3b 78 9b 80 f3 8d 77 be f3 28 4b f4 eb 84 a0 1f 7c ef 97 f8 ee 4f fe 14 df fd f9 5f e0 a3 9f fd 05 be f9 a3 3f c1 3b df f9 39 de fe f0 67 b4 ce b3 89 fe 1b 2c 5b 7a e3 43 8c 2f 9d c3 e0 dc 0e ce dd 7e 19 4f bf f6 4d dc 7b fd 03 8c ac ec f1 f1 78 f1 4d 00 2d 58 58 bb d0 46 6f 84 16 16 6f 6d 55 97 61 86 e0 da d1 cc 8a 4a 51 43 da e7 0d 71 4c db 88 50 d4 48 66 89 0a 20 2a 46 b6 d2 f3 73 87 b8 ef 87 09 ee b5 08 45 c5 ef 89 36 df fc 10 fb 90 1e c9 37 2f
                                                                        Data Ascii: &[V[,)XPc*51~PW"OTi@,U1b^~OCPq|;xw(K|O_?;9g,[zC/~OM{xM-XXFoomUaJQCqLPHf *FsE67/
                                                                        2022-08-18 22:19:12 UTC554INData Raw: e4 16 33 1f b4 0b 13 13 53 18 1e 1a 95 70 51 40 46 01 41 27 c7 26 25 10 cd ce cc 91 76 7a 71 5d 45 69 a5 84 a2 42 35 2a ec f3 02 8a e6 10 b2 b4 33 c7 73 7e 64 06 4d b4 d9 ba 85 85 d2 d2 bb af 14 15 56 77 57 4f 1f 54 56 d5 61 7a 76 51 42 d1 94 d4 4c 69 9b 57 53 3b 22 8b 9c 44 09 53 45 4d 3d 12 a8 4a 3d 68 9f 57 01 d2 4f 83 a2 a2 94 49 9d f7 a1 47 5b b9 b0 f6 0b 98 2b ec e3 4e 84 30 81 51 91 12 8a e6 53 c1 1a 1b 1e 47 e8 ea 04 2b 2b 0b d8 99 1e 82 93 99 1a 6c cd 0e a1 30 3d 18 0b 7d d5 d8 1a 69 c2 58 53 d1 27 66 b2 95 96 e3 de 5a 9c 66 53 f6 de ca 10 76 e6 7b 70 61 7d 14 b7 2f 2e e2 b9 9b 5b b8 77 75 0d b7 f6 16 70 89 e0 f3 fc c6 28 3f 37 8e 4b 9b 93 72 c4 e5 8b 6b e3 b8 ba c9 f6 f9 b3 0b b8 b3 bb 88 a7 59 ac a4 9a a7 ce 2e e2 a9 d3 0b b8 b7 bb 84 e7 f7 d6
                                                                        Data Ascii: 3SpQ@FA'&%vzq]EiB5*3s~dMVwWOTVazvQBLiWS;"DSEM=J=hWOIG[+N0QSG++l0=}iXS'fZfSv{pa}/.[wup(?7KrkY.
                                                                        2022-08-18 22:19:12 UTC570INData Raw: 35 80 c5 4e 7e cc 7f 74 62 d6 a3 a5 ad 23 6c a8 18 8d 4e 49 43 56 41 31 aa aa eb 51 cd 11 45 4b ad 04 53 1d 3c 37 5d 7d fd 2c cf a2 b2 96 d3 47 20 35 c8 1c d6 d1 f1 09 aa 43 f7 55 a2 42 2d 3a ce a2 2a 31 02 8c 8a 9c 50 15 04 15 20 54 c2 d0 95 4d 39 6b 54 fc ed ab 44 d9 fe fe 50 1d aa 52 88 0a 95 a8 6a 54 40 54 34 90 9f d9 bd 40 4b 35 95 89 7b 97 79 1e af fc ce 5c 20 98 bb c4 c2 9f 83 f3 31 fc dc 87 a0 02 88 fe 2e 14 bd 86 0b 97 69 99 bf 72 13 bb c2 92 4f 38 7a e9 f2 1d ac 9f be 84 49 5a cb a7 2f de c6 f2 ed 17 b1 72 e7 3e 36 9e 7e 0d db cf bd 89 33 2f 7d 0d e7 1f 7c 13 e7 08 45 cf be f6 4d 09 47 b7 5e fb 36 b6 5e fd 0e b6 df f8 1e d6 5e f9 0e a6 9e fb 3a 86 08 50 bb ee bc 8e 26 96 2d d5 ee 3d 8f 1a 96 31 95 9f 79 0e 39 ab 77 10 3b 7d 01 7e 93 db 08 9f 3b
                                                                        Data Ascii: 5N~tb#lNICVA1QEKS<7]},G 5CUB-:*1P TM9kTDPRjT@T4@K5{y\ 1.irO8zIZ/r>6~3/}|EMG^6^^:P&-=1y9w;}~;
                                                                        2022-08-18 22:19:12 UTC586INData Raw: 4f 49 a2 85 9e 59 aa e9 a9 48 df 79 14 95 2c 55 da 7b e1 36 f6 9d ba 8e 5d 27 ae a1 f5 d9 ab 68 3c 74 11 35 fb ce 63 0b c1 67 e3 b3 d7 54 e1 d2 b5 b7 3f c3 a9 17 de c3 51 02 d2 fd cf dd c5 ce f3 2f a1 ee f8 4d 54 9f 7a 01 19 fb 9e 83 6f d5 21 38 97 1d 40 d8 96 13 88 cd df 8a 9c 92 5a 64 97 17 23 a7 a2 88 16 7a b6 c2 13 8a d6 ee dc 89 c5 b6 ce 78 e2 69 43 3c be 72 33 3a 2f b3 46 0f 6e fb 1a da a3 df 06 47 8c b0 f1 c5 53 f6 01 4a 29 3a cf 33 02 4b 7c a2 60 18 9c 80 0d 81 09 58 eb 1b 89 65 1e 6d 50 74 ae b3 b7 82 a2 61 09 69 2c 31 24 c4 24 14 ad a9 a9 53 d0 b3 aa 9e 0a 58 05 44 ab da a1 68 35 ff 9b 5b 53 d3 06 48 cb f9 3e 8a 99 19 9a 4f bb 7c 7e 7e 21 8a 8b 4a 51 59 51 8d ea aa 5a 05 45 5b 09 45 77 ec da 89 86 e6 46 94 b2 a0 49 ae a7 fc 6c 70 f7 f6 81 8d 93
                                                                        Data Ascii: OIYHy,U{6]'h<t5cgT?Q/MTzo!8@Zd#zxiC<r3:/FnGSJ):3K|`XemPtai,1$$SXDh5[SH>O|~~!JQYQZE[EwFIlp
                                                                        2022-08-18 22:19:12 UTC602INData Raw: 3c f7 2e 9f 77 8b 4d f3 af b2 71 9e 1b 7c c8 e3 ee f0 f5 2e 71 ff 0b bc 7f 95 39 a6 3d 67 ae c2 e3 c3 fb 61 f2 d2 29 98 30 6f 26 2d f4 e3 31 67 c9 32 ac 32 da 88 c5 2b d7 60 f8 f8 89 e8 ca 6c d5 e1 8c 0f 98 c6 db ce 26 ab 91 1f 6a 86 2c af 65 c8 74 37 44 51 a8 0b 2a 33 e2 08 1d 13 d1 98 c7 26 6e 6f 7b d8 ac 5d 08 9b 8d cb b1 d1 68 09 a1 e8 7a ac da b8 0c 0b d7 2c c1 86 4d 04 cd ab 56 c2 c6 ca 16 e6 66 16 30 33 31 a5 1d de 06 4e 4e 4e 30 37 37 87 a9 e9 46 d8 6f b6 84 fd a6 0d 70 b3 b3 80 87 8b 33 fc 7d bd a9 0a b5 c4 66 3e 57 0a 67 92 08 18 13 68 23 ce 89 a7 ed 58 14 91 e1 41 68 48 0f c7 f6 74 7f b4 24 b9 a0 3a dc 12 a5 a1 36 6c b9 d7 61 77 49 0a 76 96 a7 13 8a e6 a0 32 3b 09 3a 1f da e7 09 42 ef 87 a1 72 5f e6 cb 76 fa 36 6b bd 1e 92 7a 79 79 28 20 2a 0a
                                                                        Data Ascii: <.wMq|.q9=ga)0o&-1g22+`l&j,et7DQ*3&no{]hz,MVf031NNN077Fop3}f>Wgh#XAhHt$:6lawIv2;:Br_v6kzyy( *
                                                                        2022-08-18 22:19:12 UTC618INData Raw: ba 34 9d 30 2d 65 da fc 95 53 bc 39 d3 be 21 29 3a cd a7 cf 2b cb 73 c6 bc 14 09 aa 3a a3 12 a2 33 e7 4c 0b 1e 55 73 74 c1 e2 b9 b6 70 c9 bc e0 71 ae 3f 37 75 2c 98 1b 64 86 86 7f 97 0c bd fa 9a ab 83 ae ed 0b 57 af b6 79 9b 77 da f2 db fe 62 1b ff f8 0f 6f b0 f4 2f bb ee de a7 6d fb 5f 9e b6 6b ef 7b da 36 bb 1c 5d 7a fb 23 36 fb e6 07 ec ca 6d 7f b2 e1 1b 76 5b ff 35 5e 1b 74 ed 4d d6 6b c3 ad d6 7b e3 1e eb b1 6a b7 5d be f1 4e 9b b8 f6 3a 1b 3f 6f a1 cd b8 da a7 e6 2f f6 29 e9 8b e7 79 76 a6 37 29 f2 71 e5 8c 39 36 6a c5 8d d6 fd 9a 3d de 68 69 43 50 53 b4 58 97 58 29 3a 39 55 8a 16 6b df df a5 68 2f 2b d6 ac b3 15 69 d8 c6 0a d4 68 6c 95 3a 76 b6 05 9b bd d1 d1 96 65 c1 be 6f dd 76 9d 6d 73 21 ba 7e c7 75 b6 69 db d6 d4 4c 51 35 4a 52 76 e8 96 ad aa
                                                                        Data Ascii: 40-eS9!):+s:3LUstpq?7u,dWywbo/m_k{6]z#6mv[5^tMk{j]N:?o/)yv7)q96j=hiCPSXX):9Ukh/+ihl:veovms!~uiLQ5JRv
                                                                        2022-08-18 22:19:12 UTC634INData Raw: 30 00 03 30 00 03 30 90 9b 18 40 8a 22 45 c9 12 84 01 18 88 88 01 a4 28 32 2b bb 64 16 eb 85 ad ac 60 00 29 ca 4d 50 6e ba 09 e2 58 e1 1d 06 60 00 06 60 00 06 60 00 29 1a 91 0c e1 cd c6 9b 0d 06 60 00 29 8a b8 ca 0a 71 c5 3a e0 28 bb 18 40 8a 72 9d e2 bb 0a 0c c0 00 0c c0 00 0c c0 00 0c e4 26 06 90 a2 48 51 b2 04 61 00 06 22 62 00 29 8a cc ca 88 cc 7a f6 bd 6f ed 8b ef 7e b6 5e 3b 5e b7 8c 3c 3f 2b 9f a3 6d bf fd d9 0f d6 70 f5 4b 91 6f 3b 2b 8f 83 75 65 ee bd 86 14 e5 26 28 37 dd 04 71 ac f0 0e 03 30 00 03 30 00 03 30 80 14 8d 48 86 f0 66 e3 cd 06 03 30 80 14 cd 9c a8 c9 6d 82 0b 29 0a 27 47 8a 79 a4 28 d7 29 be ab c0 00 0c c0 00 0c c0 00 0c c0 40 6e 62 00 29 8a 14 25 4b 10 06 60 20 22 06 90 a2 c8 ae 8c c8 2e a4 28 9c 64 84 93 ec 78 0e 52 94 9b a0 dc 74
                                                                        Data Ascii: 000@"E(2+d`)MPnX```)`)q:(@r&HQa"b)zo~^;^<?+mpKo;+ue&(7q000Hf0m)'Gy()@nb)%K` ".(dxRt
                                                                        2022-08-18 22:19:12 UTC650INData Raw: 59 bf d3 92 9e 14 55 cd 4e 75 7a d7 73 25 e6 d2 5b 24 12 1f 7e e5 ab 40 b8 4a 72 e6 f3 9a a5 ea 4a fe 82 77 81 8f 5d 24 df 6a 2d 7f 31 78 8e 24 e3 0e 9f c2 2f d1 18 8f 14 d5 b6 d4 54 a9 91 67 7a 6a 9f b4 ae f2 f3 9f b7 dd 4f 7e 66 9a 5e 1f 2e 92 7a ca a0 3d d0 fe 48 2e 86 fb ab d8 29 4b 54 92 51 8b b6 71 93 8b 56 49 41 bd 5e 31 da f2 e8 27 71 4b 51 09 ca 26 6b 53 c4 ef 46 6f e4 14 bb 8c bf fd b7 d9 aa e9 c5 56 fb a4 7d d3 be a8 6e a8 1e 25 9f 95 35 1b 2e 7a 8e 84 a6 8e 43 cf 39 7b ce b3 a6 c6 51 fa 7d 46 a4 a8 c4 aa 32 6d 15 cf 8e 5b 5f 4d 5d f7 c1 62 88 14 4d 24 0d 99 58 fb 82 14 8d ff 3a c1 b5 95 98 c1 00 0c c0 00 0c c0 00 0c c0 40 74 0c 20 45 91 a2 64 09 c2 00 0c 44 c4 40 14 52 34 b1 94 08 7b 73 a8 08 28 1b 53 d3 f7 d5 89 9e 85 08 24 5b 04 90 a2 d1 7d
                                                                        Data Ascii: YUNuzs%[$~@JrJw]$j-1x$/TgzjO~f^.z=H.)KTQqVIA^1'qKQ&kSFoV}n%5.zC9{Q}F2m[_M]bM$X:@t EdD@R4{s(S$[}


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        12192.168.2.3619595.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:12 UTC343OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/footer.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:19:12 UTC375INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:12 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 68010
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-109aa"
                                                                        Expires: Sat, 17 Sep 2022 22:19:12 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:12 UTC375INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 02 32 08 06 00 00 00 07 55 10 38 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec fd 0b 78 1c 69 7d ef fb fa 5c f6 b9 5f d6 da e7 d9 47 e7 ec 75 f6 e3 b5 cf de cf f6 59 e1 e2 10 48 14 16 09 5e b9 8a bb c3 d5 5c 63 92 81 08 c2 45 80 43 6c 88 03 98 c1 68 e2 04 0b 70 86 86 89 19 39 10 2f e1 84 48 8c 09 08 10 20 c3 18 84 01 8f 84 3c 6e d9 23 8d 7b ac 91 91 46 1e 59 d6 58 23 8d 35 b2 ff e7 ff be 55 d5 5d 55 5d d5 55 2d 75 b7 5a dd 5f 3d f1 13 46 ea ae 7a eb f3 d6 f5 57 ef 65 8b f0 83 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 34 91 c0 c2
                                                                        Data Ascii: PNGIHDRF2U8sRGBgAMAapHYsodIDATx^xi}\_GuYH^\cEClhp9/H <n#{FYX#5U]U]U-uZ_=FzWe 4
                                                                        2022-08-18 22:19:12 UTC391INData Raw: a3 ba 50 eb f9 c5 3f b1 15 2d 46 2b 7b b1 4f 3c d6 cb 0f 46 9d 89 08 27 7d e5 d4 7d cc 8c 35 ee b5 86 4e 6c 31 ea ec 07 85 31 f0 dd f3 b6 6f 22 be c0 b9 be ec 7b 88 30 61 52 30 ea 4e de 18 7a 46 08 5e f7 92 ef 29 bc 61 6a 72 be d5 fb 5f 54 26 ba e9 f7 92 82 51 ef 3e a3 dc e7 1d 5a 8c 56 f6 b0 62 69 08 20 10 2d 40 30 ca 9e d1 d8 02 6b 0d 46 c5 dc 44 8c 4a db 81 f0 4c c4 ce c0 e1 85 c9 8b 74 82 8d 51 6d c1 a8 13 9a d8 76 0c de c4 20 ee 04 27 f9 c9 99 f2 93 04 39 37 27 db 75 c6 c5 e9 25 af e5 43 68 c2 83 a2 09 91 a2 6e 36 8a ab 2d ee c6 21 f8 7b 77 22 24 df 04 21 d3 b9 cb d2 79 d4 9b 3c 2a 74 03 36 35 2e 6d 1a 96 74 9c 36 83 d8 eb 64 06 bd e7 dd d9 ec 0b 21 a6 99 70 c4 84 44 dd b9 1b b2 ec 36 94 8a 9e 7c c9 9b f0 c9 1b 0c 3f 3c f9 52 89 60 d4 d6 87 6f 72 26
                                                                        Data Ascii: P?-F+{O<F'}}5Nl11o"{0aR0NzF^)ajr_T&Q>ZVbi -@0kFDJLtQmv '97'u%Chn6-!{w"$!y<*t65.mt6d!pD6|?<R`or&
                                                                        2022-08-18 22:19:12 UTC455INData Raw: 10 40 00 01 04 10 40 00 01 04 10 40 a0 51 04 08 46 1b a5 26 d9 0e 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 48 2d 40 30 9a 9a 8a 0f 22 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 40 a3 08 10 8c 36 4a 4d b2 1d 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 90 5a 80 60 34 35 15 1f 44 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 81 46 11 20 18 6d 94 9a 64 3b 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 20 b5 00 c1 68 6a 2a 3e 88 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 8d 22 40 30 da 28 35 c9 76 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 40 6a 01 82 d1 d4 54 7c 10 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01
                                                                        Data Ascii: @@@QF&@@@@H-@0" @6JM Z`45D@@@@F md;@@@@@ hj*> "@0(5v @jT|@@@
                                                                        2022-08-18 22:19:12 UTC471INData Raw: 7b 28 6d 31 37 75 30 fa f8 6b 5f 2a b7 57 cb 6b 1d 9c 08 a3 b6 8f ef 7a 05 c1 68 22 14 1f 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 68 26 01 82 d1 66 aa ed 26 dc d6 cd 1c 8c b6 ff 60 56 7e f8 cb 25 f9 e5 93 4f db c6 96 49 3f 8f 2f af ca a7 7e 31 2f bf 96 30 03 7d 54 eb d4 a4 65 7b 7f 9f fb d0 1f c9 e3 1f f8 6d 59 fc d8 8b e2 c7 0f 35 e1 e8 cc b8 3c 7d f8 45 da 9d fe 19 b2 bc e7 19 f2 d4 fb 9f 2d 4b ef fe 55 59 7a c7 73 e5 c9 3b 7e 53 6e bc e5 05 b2 f4 86 df 91 e5 77 be 55 6e 3d 72 b9 e4 58 a4 93 2f 3c 24 e3 cf 3a 20 b9 df fa 74 da 62 6e ea 60 d4 4c aa b4 74 f2 5f 53 6f 6b 9a 0f 2e 7f f3 64 51 28 6a d6 c3 0f 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 cd 2c 40 30 da cc b5 df 04 db be 99 83 51 13 60 9a 90 f3 bd a7 af ca 3f eb ac f4 d9 6b 37 e5 c6 ca
                                                                        Data Ascii: {(m17u0k_*Wkzh"@@@h&f&`V~%OI?/~1/0}Te{mY5<}E-KUYzs;~SnwUn=rX/<$: tbn`Lt_Sok.dQ(j ,@0Q`?k7
                                                                        2022-08-18 22:19:12 UTC487INData Raw: c1 04 ac 88 1a 5e 70 c8 8b 8f 49 3d 7f e8 17 84 d1 4e 76 fe 56 a4 36 70 ac 23 af f0 c0 fa bd 69 cc 25 97 ca d2 cd d8 4d 95 80 9f 1b 79 e9 33 17 71 74 27 f6 ab 4b f2 b0 90 14 0b c2 7a 1b a7 00 19 cc bd b8 e9 3c d2 fb 63 37 df 97 b3 88 fb c2 be 5f 78 d9 2a 3f 4d 21 12 be 17 11 d5 a6 14 f1 f9 91 8b b9 9c 98 d5 56 ce a9 8b c1 8a d1 55 e1 de e6 7b 0d de f8 b9 b5 62 db d4 7d 65 57 ac f9 0f 9b 73 99 1c a3 8f 7b 7d a5 67 10 80 00 04 20 00 01 08 40 00 02 10 f8 1b 04 10 46 ff c6 3c 32 8a 24 01 15 43 fc 83 b5 8a 77 89 fc 9e 4e f7 99 77 2b c2 22 5e 7b 9a 3f b4 f0 16 b4 3f 4d 84 c7 37 14 69 69 12 3b ad 88 11 0b 85 75 81 25 35 36 15 4f e2 22 33 f5 bf 93 7d 13 f1 49 c2 ae 0b b1 42 db ad a4 06 70 82 52 4f d2 0c 94 79 3a 4f 66 3d 16 d1 44 44 44 87 ca 8d f7 14 f7 a9 32 de
                                                                        Data Ascii: ^pI=NvV6p#i%My3qt'Kz<c7_x*?M!VU{b}eWs{}g @F<2$CwNw+"^{??M7ii;u%56O"3}IBpROy:Of=DDD2


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        13192.168.2.3557155.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:06 UTC651OUTPOST /tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.php HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        Content-Length: 65
                                                                        Cache-Control: max-age=0
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        Upgrade-Insecure-Requests: 1
                                                                        Origin: https://internet-cheboksary.ru
                                                                        Content-Type: application/x-www-form-urlencoded
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: navigate
                                                                        Sec-Fetch-User: ?1
                                                                        Sec-Fetch-Dest: document
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:20:06 UTC652OUTData Raw: 75 73 65 72 69 64 3d 6d 79 6e 61 6d 65 26 70 61 73 73 77 6f 72 64 31 3d 31 32 33 34 71 77 65 72 26 66 6f 72 6d 69 6d 61 67 65 31 2e 78 3d 32 34 37 26 66 6f 72 6d 69 6d 61 67 65 31 2e 79 3d 31 39
                                                                        Data Ascii: userid=myname&password1=1234qwer&formimage1.x=247&formimage1.y=19
                                                                        2022-08-18 22:20:07 UTC652INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:07 GMT
                                                                        Content-Type: text/html
                                                                        Content-Length: 2238
                                                                        Connection: close
                                                                        Vary: Accept-Encoding
                                                                        X-Powered-By: PHP/7.4.25
                                                                        2022-08-18 22:20:07 UTC653INData Raw: 0d 0a 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 41 6d 65 72 69 63 61 6e 20 45 78 70 72 65 73 73 20 3a 20 4f 6e 6c 69 6e 65 20 53 65 72 76 69 63 65 73 20 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 49 53 4f 2d 38 38 35 39 2d 31 22 3e 0d 0a 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 64 69 76 23 63 6f 6e 74 61 69 6e 65 72 0d 0a 7b 0d
                                                                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><title>American Express : Online Services </title><meta http-equiv="content-type" content="text/html; charset=ISO-8859-1"><style type="text/css">div#container{


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        14192.168.2.3495235.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:07 UTC655OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/headsd.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.php
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:20:07 UTC655INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:07 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 12981
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-32b5"
                                                                        Expires: Sat, 17 Sep 2022 22:20:07 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:07 UTC656INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 00 62 08 06 00 00 00 9c 44 09 e6 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 32 4a 49 44 41 54 78 5e ed 9d 09 b0 65 c5 7d de 1f b6 13 2f 92 ab 64 c9 ae 24 8e a3 48 89 1c a7 22 95 ca 0e 76 12 47 89 6c 59 51 39 55 11 1a db b2 92 8a 2a 4e 6c c9 01 19 50 21 36 1b 88 00 49 2c cf 62 26 20 23 81 10 c8 12 12 82 17 18 b6 61 d0 80 87 41 30 0c cc b0 68 16 66 1e b3 33 cc f6 de 63 98 7d 7b b3 4f e7 7c 7d 4e 9f db 67 bb f7 dc e5 bd b9 e7 9e df 99 ea ba ef 9e a5 4f f7 d7 bf d3 77 ee 77 ff dd 3d 64 d8 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 a6 44 81 7f f3 97 23 66
                                                                        Data Ascii: PNGIHDRFbDsRGBgAMAapHYsod2JIDATx^e}/d$H"vGlYQ9U*NlP!6I,b& #aA0hf3c}{O|}NgOww=dPPPPPPPPD#f


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        15192.168.2.3572185.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:07 UTC668OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/maind.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.php
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:20:07 UTC672INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:07 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 106111
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-19e7f"
                                                                        Expires: Sat, 17 Sep 2022 22:20:07 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:07 UTC672INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 01 f2 08 06 00 00 00 27 55 14 11 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec 9d 07 9c 54 d5 f5 c7 29 a6 19 4d 62 41 c4 fc 63 2f 31 b1 23 96 a8 58 63 41 63 a7 83 9a a8 14 63 af 68 62 89 05 8c dd c4 ae 89 4a 07 e9 45 7a 15 e9 a8 c0 ee a2 48 b5 0b d6 08 98 a8 78 fe a7 dc fb de 9b d9 99 9d d9 32 3b 6f 66 7e fb 71 9c dd 99 37 ef de fb bb 67 d8 79 df fd 9d 73 1a 10 be a0 00 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 25 a4 c0 97 5f 7e 49 0d 4a 68 bd 58 2a 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 50 00 0a 40 01
                                                                        Data Ascii: PNGIHDRF'UsRGBgAMAapHYsodIDATx^T)MbAc/1#XcAcchbJEzHx2;of~q7gysP@(P@(%_~IJhX*P@(P@
                                                                        2022-08-18 22:20:07 UTC688INData Raw: fb b8 0c 6b a9 fa 66 59 01 dc 66 e8 5d fb f3 d7 52 9f 98 bd 3f 01 46 ab fb e9 17 c7 43 81 d2 51 00 60 b4 74 f6 1a 2b 2d 30 05 f2 79 f1 93 3c 36 c0 68 81 05 0f a6 5b e7 0a 48 57 fa cf 3f ff 3c 2f 37 38 46 01 c3 e2 f4 fb 00 73 29 dd 78 cc 07 18 15 77 62 c3 1d d9 f9 c6 60 af d7 83 fd f4 66 75 2e e5 b1 ba 00 4b b9 05 3f 15 15 ab a8 d7 fd fd d5 69 e9 e7 ec 53 cf 7d 7d cf da c0 2b 39 d7 7d f7 0f a0 f2 f2 d5 2e 55 db a7 72 33 28 75 80 50 c6 ee f5 40 6f 3b 46 9d 9e 9d 5c 83 20 07 d5 58 c7 f3 3a dd 45 65 cb 56 d0 f9 7c 6f ee ca f6 d4 e5 aa 47 a8 6f ff 49 61 1a b8 d6 79 15 f8 e8 9a 48 45 3b c5 4b 13 22 59 a3 ab 39 ba b4 62 a5 8e 59 9b b5 65 fb 5a 05 8c ae 9e 6a ef 01 13 e9 d2 2b 1f 74 e3 9a 23 74 8b 1d b8 3e aa 07 74 0e fe ca 31 7d fa 4f a8 fd fc 58 63 2d 39 a0 ae
                                                                        Data Ascii: kfYf]R?FCQ`t+-0y<6h[HW?</78Fs)xwb`fu.K?iS}}+9}.Ur3(uP@o;F\ X:EeV|oGoIayHE;K"Y9bYeZj+t#t>t1}OXc-9
                                                                        2022-08-18 22:20:07 UTC731INData Raw: bc 3c 26 4d 89 64 6e 06 50 1d 98 14 90 25 a9 cf fc a5 35 45 19 88 89 f3 4f be b4 86 a6 a6 30 1b 70 93 9a 9c 3e c5 dd a7 e8 2b 00 15 a7 a0 3b 9f 5f a7 d6 1e 15 17 a8 4b 31 17 70 36 62 f4 2c fd d9 6b 25 fa 49 a7 7a 69 e0 64 f5 4d 6d 2e 72 ce b0 a3 b9 38 56 c5 69 69 60 54 6b 85 2a d4 73 60 d0 d5 18 35 a7 e4 66 4b c9 f7 0e 43 57 a7 55 dd 8c da 08 ca 4a 00 78 f7 a2 87 ae d6 19 de b9 38 65 ef f8 fc 1e 02 cb 6b 7c 03 27 83 9b 9d 15 76 4a 39 84 60 cd ce 01 2b 20 5c dd a4 ea 7e 0d 1d a3 e2 d2 34 30 e9 e2 84 cf 23 e7 14 a7 a4 b9 31 b9 29 17 37 c1 12 60 2d ee dd 57 17 96 69 33 23 01 87 02 b3 7d 2a bb d7 d6 03 7a d5 92 e7 ae 30 d6 d5 6f 95 9f ef 7a a8 b7 ed a7 03 d2 12 87 3e 15 dd a7 d2 1b 08 95 38 b1 94 7e ab cd ea 1d bf 16 1b b2 46 4b ef b7 f2 0c 72 a0 80 7a 73 d2
                                                                        Data Ascii: <&MdnP%5EO0p>+;_K1p6b,k%IzidMm.r8Vii`Tk*s`5fKCWUJx8ek|'vJ9`+ \~40#1)7`-Wi3#}*z0oz>8~FKrzs
                                                                        2022-08-18 22:20:07 UTC747INData Raw: 59 dd e4 d8 42 58 13 e6 18 0f 90 83 7d c0 3e 20 06 ea 2e 06 00 46 01 46 eb e2 fd 04 30 0a 30 0a 30 9a be b6 68 43 76 8c 56 aa 2d ca cd 97 c4 1d d9 a0 29 3b 46 05 00 6a 6d d1 73 e8 d0 93 6e a0 45 cb d6 38 a7 e8 9b da e1 5d 20 e9 90 11 13 e8 b9 17 07 70 ca fc 68 86 a2 a3 a8 df 50 eb 3e 3f 69 fa 6c 9a b1 70 09 9d 71 fe 85 b4 db 4e bf a0 f6 27 ef 45 6d 4e 39 48 1d a1 02 3f 7f bb cf ff d1 91 fb ef 42 db 6f f3 63 ba b9 eb 89 34 ec 9f 5d e8 ea 3f 1e a7 69 f2 8d 18 98 9e 78 d8 de f4 c8 ad e7 d1 f9 ad 18 98 36 df 8b ae ec 76 12 3d 7b 67 07 4d a9 7f e8 c6 73 e9 d7 bb 8a d3 b4 11 dd d2 f5 14 3a f5 f8 7d e8 92 36 47 d3 fe fb fc 92 7e b9 c3 2f f4 71 39 47 87 d3 0f a5 0e 3c ee 2f 9b fc 88 ce 38 f7 22 6e 0c 55 ce 20 74 36 0d 64 c7 e8 a0 21 63 d5 dd fa af be 83 69 22 a7
                                                                        Data Ascii: YBX}> .FF000hCvV-);FjmsnE8] phP>?ilpqN'EmN9H?Boc4]?ix6v={gMs:}6G~/q9G</8"nU t6d!ci"
                                                                        2022-08-18 22:20:07 UTC763INData Raw: 5a bf 80 33 ab 54 30 d0 b3 7d fd 27 f1 64 f5 2b 71 7f b5 4b f1 5c f5 ab 71 ed 7f ff 8d 1b ae 3c 1f cd 6b 57 c7 a7 75 ab 9b cf c7 09 28 fd bf 93 8e 47 eb fa 8f e0 e6 ab cf c3 8b 8f 5e 8b 4f de 7f 10 e3 fa bc 85 e7 ee bf 02 f7 df 7c a9 71 8e 9e 7a ca 89 c6 2d aa f5 48 eb bf 54 0d 67 9c 1a 85 f2 ff 3e 17 71 69 99 f8 53 e6 95 bb 75 b7 49 a1 57 a8 ab 70 d7 38 46 05 8c ae 58 2b 2e 58 01 a3 6e 3a fd f2 cc d5 48 5e 2d a9 f4 02 45 b7 ec b5 5d e9 d7 ed d8 83 89 33 e3 2c 10 3d f5 76 c4 9c 7e bb a4 c8 4b 77 fa 72 16 90 ba 60 d4 07 47 25 85 de ed 52 6f c1 68 50 bd d1 90 60 d4 df 84 89 60 f4 48 be b9 f2 dc 54 20 b2 15 20 18 8d ec e7 c7 d9 97 62 05 f8 42 c6 97 72 c6 00 63 80 31 c0 18 60 0c 30 06 c2 25 06 08 46 09 46 09 46 fd 60 34 aa e2 d3 e2 0c 7d 56 a0 e8 53 88 ae a8
                                                                        Data Ascii: Z3T0}'d+qK\q<kWu(G^O|qz-HTg>qiSuIWp8FX+.Xn:H^-E]3,=v~Kwr`G%RohP``HT bBrc1`0%FFF`4}VS
                                                                        2022-08-18 22:20:07 UTC779INData Raw: 99 4a 5f 52 ef 9f bc 0e 15 38 56 15 20 18 3d 56 9f 3c ef 3b ec 15 28 8d 2f 55 bc 27 c2 02 c6 00 63 80 31 c0 18 60 0c 44 66 0c 1c 0c 18 b5 f5 35 ad 7b d0 36 04 72 d3 ae c5 85 27 2e 4c 85 a1 ba b4 e9 f4 8e 13 54 1c 9c ea ee 3c fb b3 54 f3 bb da e7 d3 b6 98 ba 9e 0f 0f 58 2d f5 44 b3 65 ac c6 c4 15 7b 4c 0d d2 09 29 3b 6d 07 fa 9c 7d 78 b4 ff 2a 8c 49 da 85 07 7a af 42 b5 9e 2b a5 76 69 06 6e e9 96 89 21 8b b7 99 7d b4 f6 e8 a3 72 8c 2e b5 f3 fc bc ac 7d f8 e5 77 01 ab fd 57 9b 63 b5 fe e8 23 b2 ae 5d ef ff fc eb 6f 0c 5a b8 05 6f fd 98 83 97 87 e6 e0 95 a1 b9 98 9d bd 07 49 1b f7 e2 a3 d1 eb f0 f2 77 6b f1 f2 b0 5c 34 1e b3 d6 71 88 da 3a a0 ea 72 34 f7 6c ba b7 3b 9d e6 1d a7 a8 cf 35 ea d6 e3 0c 48 b7 17 07 ad 42 e3 2a cf f8 ca 0e f8 75 13 ad e4 5c d1 15
                                                                        Data Ascii: J_R8V =V<;(/U'c1`Df5{6r'.LT<TX-De{L);m}x*IzB+vin!}r.}wWc#]oZoIwk\4q:r4l;5HB*u\
                                                                        2022-08-18 22:20:07 UTC795INData Raw: eb a0 c3 e2 23 f8 4b e3 e2 0e b8 e5 96 5b 70 4b 9d e1 c8 0e 09 1e b2 31 bc ce 2d 47 76 0e c7 10 f0 38 98 9f a5 62 1f 93 3d 1c 75 3a 2c ce f7 73 ab b1 74 4b 88 ed c5 3e 7f 91 9e d7 62 74 b8 a5 0e 86 67 07 c5 ae 67 6e 25 3b 9f 83 ff 19 f2 ff 0c f2 67 e1 c8 c4 ca c1 3f 9b d2 3a 9f 50 60 94 db 06 85 74 a1 51 17 ea c2 18 88 8c 18 38 5a ff 5e f3 95 97 0a 50 81 f0 52 80 60 34 bc 9e 07 67 43 05 4a 05 18 55 a8 a9 00 53 53 e3 83 c1 68 30 ec d4 f4 78 fd 87 68 cc ec 54 03 43 5d e0 e9 3d ce 9b 42 af e7 3d e8 5f 62 8a 01 10 2d 40 75 dd a0 1e f0 19 04 5f f2 81 d1 5d 99 18 58 4b 8e 73 5d a3 ce 35 dd 73 f9 80 a9 3b 97 16 5d 8c db d3 7c 1f e0 34 75 ce e3 7c e7 07 ad ee f9 bb a0 a5 5e 47 81 6e 5c b0 63 34 16 2d 3d 8e d8 96 b1 fe 17 fc c2 ee 2b c0 fd 7a 00 d7 eb e2 0e 47 16
                                                                        Data Ascii: #K[pK1-Gv8b=u:,stK>btggn%;g?:P`tQ8Z^PR`4gCJUSSh0xhTC]=B=_b-@u_]XKs]5s;]|4u|^Gn\c4-=+zG


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        16192.168.2.3616415.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:07 UTC669OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/logins.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.php
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:20:07 UTC671INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:07 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 813
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-32d"
                                                                        Expires: Sat, 17 Sep 2022 22:20:07 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:07 UTC671INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 6c 00 00 00 24 08 06 00 00 00 6c 6d df cc 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 02 c2 49 44 41 54 68 43 ed 9b bb 4f c2 50 14 c6 dd 98 7d ad e2 3f e2 44 d4 c5 07 8b 89 ba 9b 18 e3 e0 63 31 32 e8 e6 6c 62 88 4e 26 98 68 c4 f8 58 49 d4 84 84 49 16 a2 0b 61 f0 c1 a2 89 83 10 56 cb b1 a7 dc 96 02 95 1e ae b6 a5 e5 34 69 42 e8 ed bd 87 f3 3b df 77 0f 81 f6 95 cb 65 e0 d3 3f 39 e8 63 58 fe 81 85 ac 18 98 cf 1c 86 81 05 09 58 f2 fa 1e 22 d3 1b 30 10 9e 85 d0 f0 24 9f 0e e6 00 73 8c b9 be 50 73 de 6e 9b fa 55 61 5b 3b 47 0c c8 41 40 ed 04 80 b9 ff 0d 9a 25 30 a4 cc 8a f2 d6 51 d0 dd ac a0 59
                                                                        Data Ascii: PNGIHDRl$lmsRGBgAMAapHYsodIDAThCOP}?Dc12lbN&hXIIaV4iB;we?9cXX"0$sPsnUa[;GA@%0QY


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        17192.168.2.3570225.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:07 UTC670OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/down.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/index2.php
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:20:07 UTC704INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:07 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 27347
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-6ad3"
                                                                        Expires: Sat, 17 Sep 2022 22:20:07 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:07 UTC704INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 47 00 00 00 f6 08 06 00 00 00 f5 71 36 8d 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 6a 68 49 44 41 54 78 5e ed 9d 5b d0 26 47 79 df 75 e5 8b 54 aa 52 be 48 e5 2e 55 ae 24 37 4e 5c 39 6d e2 72 9c 4a 2e 52 06 5f 18 b6 ca 54 28 27 54 aa 12 c7 55 51 0e 5b 89 4b c1 96 30 b6 1c 63 7b 6d 67 91 44 62 b1 32 44 89 53 05 08 10 60 58 61 24 a0 84 89 01 8b 18 ac c3 ee 8a 43 38 09 90 b4 d2 ae 10 20 24 74 da d5 64 ba 67 7a e6 79 ba 9f ee 39 bc f3 7e df fb 7e f3 fb aa 5e 69 bf f7 9b e9 e9 fe 3d ff ee 99 f9 cf d3 3d 57 dd 7b ef fd 15 1f 18 a0 01 34 80 06 d0 00 1a 40 03 68 00 0d a0 01 34 80 06 d0 00 1a 40
                                                                        Data Ascii: PNGIHDRGq6sRGBgAMAapHYsodjhIDATx^[&GyuTRH.U$7N\9mrJ.R_T('TUQ[K0c{mgDb2DS`Xa$C8 $tdgzy9~~^i==W{4@h4@
                                                                        2022-08-18 22:20:07 UTC720INData Raw: 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00
                                                                        Data Ascii: `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        18192.168.2.3614025.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:08 UTC803OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/maind.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:20:09 UTC816INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:09 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 106111
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-19e7f"
                                                                        Expires: Sat, 17 Sep 2022 22:20:09 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:09 UTC816INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 01 f2 08 06 00 00 00 27 55 14 11 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec 9d 07 9c 54 d5 f5 c7 29 a6 19 4d 62 41 c4 fc 63 2f 31 b1 23 96 a8 58 63 41 63 a7 83 9a a8 14 63 af 68 62 89 05 8c dd c4 ae 89 4a 07 e9 45 7a 15 e9 a8 c0 ee a2 48 b5 0b d6 08 98 a8 78 fe a7 dc fb de 9b d9 99 9d d9 32 3b 6f 66 7e fb 71 9c dd 99 37 ef de fb bb 67 d8 79 df fd 9d 73 1a 10 be a0 00 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 25 a4 c0 97 5f 7e 49 0d 4a 68 bd 58 2a 14 80 02 50 00 0a 40 01 28 00 05 a0 00 14 80 02 50 00 0a 40 01
                                                                        Data Ascii: PNGIHDRF'UsRGBgAMAapHYsodIDATx^T)MbAc/1#XcAcchbJEzHx2;of~q7gysP@(P@(%_~IJhX*P@(P@
                                                                        2022-08-18 22:20:09 UTC832INData Raw: fb b8 0c 6b a9 fa 66 59 01 dc 66 e8 5d fb f3 d7 52 9f 98 bd 3f 01 46 ab fb e9 17 c7 43 81 d2 51 00 60 b4 74 f6 1a 2b 2d 30 05 f2 79 f1 93 3c 36 c0 68 81 05 0f a6 5b e7 0a 48 57 fa cf 3f ff 3c 2f 37 38 46 01 c3 e2 f4 fb 00 73 29 dd 78 cc 07 18 15 77 62 c3 1d d9 f9 c6 60 af d7 83 fd f4 66 75 2e e5 b1 ba 00 4b b9 05 3f 15 15 ab a8 d7 fd fd d5 69 e9 e7 ec 53 cf 7d 7d cf da c0 2b 39 d7 7d f7 0f a0 f2 f2 d5 2e 55 db a7 72 33 28 75 80 50 c6 ee f5 40 6f 3b 46 9d 9e 9d 5c 83 20 07 d5 58 c7 f3 3a dd 45 65 cb 56 d0 f9 7c 6f ee ca f6 d4 e5 aa 47 a8 6f ff 49 61 1a b8 d6 79 15 f8 e8 9a 48 45 3b c5 4b 13 22 59 a3 ab 39 ba b4 62 a5 8e 59 9b b5 65 fb 5a 05 8c ae 9e 6a ef 01 13 e9 d2 2b 1f 74 e3 9a 23 74 8b 1d b8 3e aa 07 74 0e fe ca 31 7d fa 4f a8 fd fc 58 63 2d 39 a0 ae
                                                                        Data Ascii: kfYf]R?FCQ`t+-0y<6h[HW?</78Fs)xwb`fu.K?iS}}+9}.Ur3(uP@o;F\ X:EeV|oGoIayHE;K"Y9bYeZj+t#t>t1}OXc-9
                                                                        2022-08-18 22:20:09 UTC848INData Raw: bc 3c 26 4d 89 64 6e 06 50 1d 98 14 90 25 a9 cf fc a5 35 45 19 88 89 f3 4f be b4 86 a6 a6 30 1b 70 93 9a 9c 3e c5 dd a7 e8 2b 00 15 a7 a0 3b 9f 5f a7 d6 1e 15 17 a8 4b 31 17 70 36 62 f4 2c fd d9 6b 25 fa 49 a7 7a 69 e0 64 f5 4d 6d 2e 72 ce b0 a3 b9 38 56 c5 69 69 60 54 6b 85 2a d4 73 60 d0 d5 18 35 a7 e4 66 4b c9 f7 0e 43 57 a7 55 dd 8c da 08 ca 4a 00 78 f7 a2 87 ae d6 19 de b9 38 65 ef f8 fc 1e 02 cb 6b 7c 03 27 83 9b 9d 15 76 4a 39 84 60 cd ce 01 2b 20 5c dd a4 ea 7e 0d 1d a3 e2 d2 34 30 e9 e2 84 cf 23 e7 14 a7 a4 b9 31 b9 29 17 37 c1 12 60 2d ee dd 57 17 96 69 33 23 01 87 02 b3 7d 2a bb d7 d6 03 7a d5 92 e7 ae 30 d6 d5 6f 95 9f ef 7a a8 b7 ed a7 03 d2 12 87 3e 15 dd a7 d2 1b 08 95 38 b1 94 7e ab cd ea 1d bf 16 1b b2 46 4b ef b7 f2 0c 72 a0 80 7a 73 d2
                                                                        Data Ascii: <&MdnP%5EO0p>+;_K1p6b,k%IzidMm.r8Vii`Tk*s`5fKCWUJx8ek|'vJ9`+ \~40#1)7`-Wi3#}*z0oz>8~FKrzs
                                                                        2022-08-18 22:20:09 UTC864INData Raw: 59 dd e4 d8 42 58 13 e6 18 0f 90 83 7d c0 3e 20 06 ea 2e 06 00 46 01 46 eb e2 fd 04 30 0a 30 0a 30 9a be b6 68 43 76 8c 56 aa 2d ca cd 97 c4 1d d9 a0 29 3b 46 05 00 6a 6d d1 73 e8 d0 93 6e a0 45 cb d6 38 a7 e8 9b da e1 5d 20 e9 90 11 13 e8 b9 17 07 70 ca fc 68 86 a2 a3 a8 df 50 eb 3e 3f 69 fa 6c 9a b1 70 09 9d 71 fe 85 b4 db 4e bf a0 f6 27 ef 45 6d 4e 39 48 1d a1 02 3f 7f bb cf ff d1 91 fb ef 42 db 6f f3 63 ba b9 eb 89 34 ec 9f 5d e8 ea 3f 1e a7 69 f2 8d 18 98 9e 78 d8 de f4 c8 ad e7 d1 f9 ad 18 98 36 df 8b ae ec 76 12 3d 7b 67 07 4d a9 7f e8 c6 73 e9 d7 bb 8a d3 b4 11 dd d2 f5 14 3a f5 f8 7d e8 92 36 47 d3 fe fb fc 92 7e b9 c3 2f f4 71 39 47 87 d3 0f a5 0e 3c ee 2f 9b fc 88 ce 38 f7 22 6e 0c 55 ce 20 74 36 0d 64 c7 e8 a0 21 63 d5 dd fa af be 83 69 22 a7
                                                                        Data Ascii: YBX}> .FF000hCvV-);FjmsnE8] phP>?ilpqN'EmN9H?Boc4]?ix6v={gMs:}6G~/q9G</8"nU t6d!ci"
                                                                        2022-08-18 22:20:09 UTC880INData Raw: 5a bf 80 33 ab 54 30 d0 b3 7d fd 27 f1 64 f5 2b 71 7f b5 4b f1 5c f5 ab 71 ed 7f ff 8d 1b ae 3c 1f cd 6b 57 c7 a7 75 ab 9b cf c7 09 28 fd bf 93 8e 47 eb fa 8f e0 e6 ab cf c3 8b 8f 5e 8b 4f de 7f 10 e3 fa bc 85 e7 ee bf 02 f7 df 7c a9 71 8e 9e 7a ca 89 c6 2d aa f5 48 eb bf 54 0d 67 9c 1a 85 f2 ff 3e 17 71 69 99 f8 53 e6 95 bb 75 b7 49 a1 57 a8 ab 70 d7 38 46 05 8c ae 58 2b 2e 58 01 a3 6e 3a fd f2 cc d5 48 5e 2d a9 f4 02 45 b7 ec b5 5d e9 d7 ed d8 83 89 33 e3 2c 10 3d f5 76 c4 9c 7e bb a4 c8 4b 77 fa 72 16 90 ba 60 d4 07 47 25 85 de ed 52 6f c1 68 50 bd d1 90 60 d4 df 84 89 60 f4 48 be b9 f2 dc 54 20 b2 15 20 18 8d ec e7 c7 d9 97 62 05 f8 42 c6 97 72 c6 00 63 80 31 c0 18 60 0c 30 06 c2 25 06 08 46 09 46 09 46 fd 60 34 aa e2 d3 e2 0c 7d 56 a0 e8 53 88 ae a8
                                                                        Data Ascii: Z3T0}'d+qK\q<kWu(G^O|qz-HTg>qiSuIWp8FX+.Xn:H^-E]3,=v~Kwr`G%RohP``HT bBrc1`0%FFF`4}VS
                                                                        2022-08-18 22:20:09 UTC896INData Raw: 99 4a 5f 52 ef 9f bc 0e 15 38 56 15 20 18 3d 56 9f 3c ef 3b ec 15 28 8d 2f 55 bc 27 c2 02 c6 00 63 80 31 c0 18 60 0c 44 66 0c 1c 0c 18 b5 f5 35 ad 7b d0 36 04 72 d3 ae c5 85 27 2e 4c 85 a1 ba b4 e9 f4 8e 13 54 1c 9c ea ee 3c fb b3 54 f3 bb da e7 d3 b6 98 ba 9e 0f 0f 58 2d f5 44 b3 65 ac c6 c4 15 7b 4c 0d d2 09 29 3b 6d 07 fa 9c 7d 78 b4 ff 2a 8c 49 da 85 07 7a af 42 b5 9e 2b a5 76 69 06 6e e9 96 89 21 8b b7 99 7d b4 f6 e8 a3 72 8c 2e b5 f3 fc bc ac 7d f8 e5 77 01 ab fd 57 9b 63 b5 fe e8 23 b2 ae 5d ef ff fc eb 6f 0c 5a b8 05 6f fd 98 83 97 87 e6 e0 95 a1 b9 98 9d bd 07 49 1b f7 e2 a3 d1 eb f0 f2 77 6b f1 f2 b0 5c 34 1e b3 d6 71 88 da 3a a0 ea 72 34 f7 6c ba b7 3b 9d e6 1d a7 a8 cf 35 ea d6 e3 0c 48 b7 17 07 ad 42 e3 2a cf f8 ca 0e f8 75 13 ad e4 5c d1 15
                                                                        Data Ascii: J_R8V =V<;(/U'c1`Df5{6r'.LT<TX-De{L);m}x*IzB+vin!}r.}wWc#]oZoIwk\4q:r4l;5HB*u\
                                                                        2022-08-18 22:20:09 UTC912INData Raw: eb a0 c3 e2 23 f8 4b e3 e2 0e b8 e5 96 5b 70 4b 9d e1 c8 0e 09 1e b2 31 bc ce 2d 47 76 0e c7 10 f0 38 98 9f a5 62 1f 93 3d 1c 75 3a 2c ce f7 73 ab b1 74 4b 88 ed c5 3e 7f 91 9e d7 62 74 b8 a5 0e 86 67 07 c5 ae 67 6e 25 3b 9f 83 ff 19 f2 ff 0c f2 67 e1 c8 c4 ca c1 3f 9b d2 3a 9f 50 60 94 db 06 85 74 a1 51 17 ea c2 18 88 8c 18 38 5a ff 5e f3 95 97 0a 50 81 f0 52 80 60 34 bc 9e 07 67 43 05 4a 05 18 55 a8 a9 00 53 53 e3 83 c1 68 30 ec d4 f4 78 fd 87 68 cc ec 54 03 43 5d e0 e9 3d ce 9b 42 af e7 3d e8 5f 62 8a 01 10 2d 40 75 dd a0 1e f0 19 04 5f f2 81 d1 5d 99 18 58 4b 8e 73 5d a3 ce 35 dd 73 f9 80 a9 3b 97 16 5d 8c db d3 7c 1f e0 34 75 ce e3 7c e7 07 ad ee f9 bb a0 a5 5e 47 81 6e 5c b0 63 34 16 2d 3d 8e d8 96 b1 fe 17 fc c2 ee 2b c0 fd 7a 00 d7 eb e2 0e 47 16
                                                                        Data Ascii: #K[pK1-Gv8b=u:,stK>btggn%;g?:P`tQ8Z^PR`4gCJUSSh0xhTC]=B=_b-@u_]XKs]5s;]|4u|^Gn\c4-=+zG


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        19192.168.2.3614015.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:08 UTC803OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/headsd.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:20:09 UTC803INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:09 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 12981
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-32b5"
                                                                        Expires: Sat, 17 Sep 2022 22:20:09 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:09 UTC803INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 00 62 08 06 00 00 00 9c 44 09 e6 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 32 4a 49 44 41 54 78 5e ed 9d 09 b0 65 c5 7d de 1f b6 13 2f 92 ab 64 c9 ae 24 8e a3 48 89 1c a7 22 95 ca 0e 76 12 47 89 6c 59 51 39 55 11 1a db b2 92 8a 2a 4e 6c c9 01 19 50 21 36 1b 88 00 49 2c cf 62 26 20 23 81 10 c8 12 12 82 17 18 b6 61 d0 80 87 41 30 0c cc b0 68 16 66 1e b3 33 cc f6 de 63 98 7d 7b b3 4f e7 7c 7d 4e 9f db 67 bb f7 dc e5 bd b9 e7 9e df 99 ea ba ef 9e a5 4f f7 d7 bf d3 77 ee 77 ff dd 3d 64 d8 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 50 00 05 a6 44 81 7f f3 97 23 66
                                                                        Data Ascii: PNGIHDRFbDsRGBgAMAapHYsod2JIDATx^e}/d$H"vGlYQ9U*NlP!6I,b& #aA0hf3c}{O|}NgOww=dPPPPPPPPD#f


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        2192.168.2.361356172.67.188.125443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:07 UTC1OUTGET /t6killx HTTP/1.1
                                                                        Host: kutt.it
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        Upgrade-Insecure-Requests: 1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                                                        Sec-Fetch-Site: none
                                                                        Sec-Fetch-Mode: navigate
                                                                        Sec-Fetch-User: ?1
                                                                        Sec-Fetch-Dest: document
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        2022-08-18 22:19:08 UTC5INHTTP/1.1 302 Found
                                                                        Date: Thu, 18 Aug 2022 22:19:08 GMT
                                                                        Content-Type: text/html; charset=utf-8
                                                                        Transfer-Encoding: chunked
                                                                        Connection: close
                                                                        content-security-policy: default-src 'self';base-uri 'self';block-all-mixed-content;font-src 'self' https: data:;frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
                                                                        content-security-policy: default-src 'self' http: https: data: blob: 'unsafe-inline'
                                                                        x-dns-prefetch-control: off
                                                                        expect-ct: max-age=0
                                                                        x-frame-options: SAMEORIGIN
                                                                        x-frame-options: SAMEORIGIN
                                                                        strict-transport-security: max-age=15552000; includeSubDomains
                                                                        strict-transport-security: max-age=31536000; includeSubDomains; preload
                                                                        x-download-options: noopen
                                                                        x-content-type-options: nosniff
                                                                        x-content-type-options: nosniff
                                                                        x-permitted-cross-domain-policies: none
                                                                        referrer-policy: no-referrer
                                                                        referrer-policy: no-referrer-when-downgrade
                                                                        x-xss-protection: 0
                                                                        x-xss-protection: 1; mode=block
                                                                        location: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        vary: Accept
                                                                        CF-Cache-Status: DYNAMIC
                                                                        2022-08-18 22:19:08 UTC6INData Raw: 52 65 70 6f 72 74 2d 54 6f 3a 20 7b 22 65 6e 64 70 6f 69 6e 74 73 22 3a 5b 7b 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 61 2e 6e 65 6c 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 5c 2f 72 65 70 6f 72 74 5c 2f 76 33 3f 73 3d 75 76 4b 46 44 6c 37 74 72 4b 63 66 31 6b 25 32 46 75 53 74 69 32 52 65 39 43 49 6e 57 6e 76 25 32 46 6d 41 6f 4a 69 77 6f 78 51 58 71 7a 25 32 42 45 74 33 50 44 4c 57 70 37 52 38 50 64 77 61 32 76 39 44 68 79 41 4f 30 77 62 38 6c 77 39 57 35 65 33 75 67 71 6d 34 41 58 6e 38 62 31 74 25 32 46 25 32 46 58 6b 71 32 74 73 47 45 6d 25 32 46 44 54 35 63 25 32 46 51 55 74 67 6f 77 6c 41 61 6f 39 41 74 78 22 7d 5d 2c 22 67 72 6f 75 70 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a 36 30 34 38 30 30 7d 0d 0a 4e 45 4c
                                                                        Data Ascii: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=uvKFDl7trKcf1k%2FuSti2Re9CInWnv%2FmAoJiwoxQXqz%2BEt3PDLWp7R8Pdwa2v9DhyAO0wb8lw9W5e3ugqm4AXn8b1t%2F%2FXkq2tsGEm%2FDT5c%2FQUtgowlAao9Atx"}],"group":"cf-nel","max_age":604800}NEL
                                                                        2022-08-18 22:19:08 UTC6INData Raw: 63 36 0d 0a 3c 70 3e 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 69 6e 74 65 72 6e 65 74 2d 63 68 65 62 6f 6b 73 61 72 79 2e 72 75 2f 74 6b 6b 74 2f 61 6d 65 72 69 63 61 6e 65 78 70 72 65 73 73 2e 63 6f 6d 2d 6c 6f 67 6f 6e 2f 41 4d 45 58 2f 41 6d 65 78 2f 68 6f 6d 65 2f 22 3e 68 74 74 70 73 3a 2f 2f 69 6e 74 65 72 6e 65 74 2d 63 68 65 62 6f 6b 73 61 72 79 2e 72 75 2f 74 6b 6b 74 2f 61 6d 65 72 69 63 61 6e 65 78 70 72 65 73 73 2e 63 6f 6d 2d 6c 6f 67 6f 6e 2f 41 4d 45 58 2f 41 6d 65 78 2f 68 6f 6d 65 2f 3c 2f 61 3e 3c 2f 70 3e 0d 0a
                                                                        Data Ascii: c6<p>Found. Redirecting to <a href="https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/">https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/</a></p>
                                                                        2022-08-18 22:19:08 UTC6INData Raw: 30 0d 0a 0d 0a
                                                                        Data Ascii: 0


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        20192.168.2.3614035.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:20:09 UTC896OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/down.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:20:09 UTC920INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:20:09 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 27347
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-6ad3"
                                                                        Expires: Sat, 17 Sep 2022 22:20:09 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:20:09 UTC921INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 47 00 00 00 f6 08 06 00 00 00 f5 71 36 8d 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 6a 68 49 44 41 54 78 5e ed 9d 5b d0 26 47 79 df 75 e5 8b 54 aa 52 be 48 e5 2e 55 ae 24 37 4e 5c 39 6d e2 72 9c 4a 2e 52 06 5f 18 b6 ca 54 28 27 54 aa 12 c7 55 51 0e 5b 89 4b c1 96 30 b6 1c 63 7b 6d 67 91 44 62 b1 32 44 89 53 05 08 10 60 58 61 24 a0 84 89 01 8b 18 ac c3 ee 8a 43 38 09 90 b4 d2 ae 10 20 24 74 da d5 64 ba 67 7a e6 79 ba 9f ee 39 bc f3 7e df fb 7e f3 fb aa 5e 69 bf f7 9b e9 e9 fe 3d ff ee 99 f9 cf d3 3d 57 dd 7b ef fd 15 1f 18 a0 01 34 80 06 d0 00 1a 40 03 68 00 0d a0 01 34 80 06 d0 00 1a 40
                                                                        Data Ascii: PNGIHDRGq6sRGBgAMAapHYsodjhIDATx^[&GyuTRH.U$7N\9mrJ.R_T('TUQ[K0c{mgDb2DS`Xa$C8 $tdgzy9~~^i==W{4@h4@
                                                                        2022-08-18 22:20:09 UTC936INData Raw: 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 60 95 04 30 47 57 19 76 1a 0d 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 60 8e a2 01 08 40 00
                                                                        Data Ascii: `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@ @ @`0GWv@ @ `@


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        3192.168.2.3532945.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:09 UTC6OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/ HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        Upgrade-Insecure-Requests: 1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                                                        Sec-Fetch-Site: none
                                                                        Sec-Fetch-Mode: navigate
                                                                        Sec-Fetch-User: ?1
                                                                        Sec-Fetch-Dest: document
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        2022-08-18 22:19:09 UTC7INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:09 GMT
                                                                        Content-Type: text/html
                                                                        Content-Length: 2049
                                                                        Connection: close
                                                                        Vary: Accept-Encoding
                                                                        X-Powered-By: PHP/7.4.25
                                                                        Set-Cookie: mycounter=Checked; expires=Fri, 19-Aug-2022 22:19:09 GMT; Max-Age=86400
                                                                        2022-08-18 22:19:09 UTC7INData Raw: 0d 0a 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 41 6d 65 72 69 63 61 6e 20 45 78 70 72 65 73 73 20 3a 20 4f 6e 6c 69 6e 65 20 53 65 72 76 69 63 65 73 20 3a 20 4c 6f 67 20 69 6e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 49 53 4f 2d 38 38 35 39 2d 31 22 3e 0d 0a 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 64 69 76 23 63 6f 6e 74 61
                                                                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><title>American Express : Online Services : Log in</title><meta http-equiv="content-type" content="text/html; charset=ISO-8859-1"><style type="text/css">div#conta


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        4192.168.2.3576065.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:10 UTC9OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/head.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:19:10 UTC12INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:10 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 8182
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-1ff6"
                                                                        Expires: Sat, 17 Sep 2022 22:19:10 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:10 UTC12INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 00 3b 08 06 00 00 00 b7 c5 50 d9 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 1f 8b 49 44 41 54 78 5e ed 9d 7f 70 1c 49 75 c7 5d f9 55 f9 41 42 12 52 18 42 8a ab 4a 2a b9 40 91 72 08 49 9c df 06 52 15 55 11 c0 f9 51 a9 23 55 21 fe 23 09 ae 0a 95 32 c4 10 9b 60 7e 38 c7 9d 88 c3 d9 70 07 d1 c1 39 c8 e4 70 8c 81 c8 c4 47 61 c0 80 04 18 8c 01 23 7b 65 4b b2 25 7b 6d 9d 7c d2 c9 96 64 59 3e c9 96 6d 5e de eb 99 d9 9d 5d ed 6a 76 ad 19 ed cc ee 67 aa b6 a4 9d 99 ed e9 fe 74 cf 4c f7 b7 5f bf b7 4a d8 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 b4 08 81
                                                                        Data Ascii: PNGIHDRF;PsRGBgAMAapHYsodIDATx^pIu]UABRBJ*@rIRUQ#U!#2`~8p9pGa#{eK%{m|dY>m^]jvgtL_J @ @


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        5192.168.2.3585975.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:10 UTC10OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/main.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:19:10 UTC22INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:10 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 247287
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-3c5f7"
                                                                        Expires: Sat, 17 Sep 2022 22:19:10 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:10 UTC22INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 45 00 00 02 34 08 06 00 00 00 3a 3b 48 26 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec fd 07 7c 9c e5 99 fd 8d 0b dc ad 6a f5 de 7b ef bd b7 51 ef bd 77 c9 6a 96 65 cb b2 e5 de c1 36 18 70 c1 54 d3 4d 07 d3 0c a1 97 40 48 23 24 d9 90 2d ef b2 e5 f7 6e de ff 6e 7e cb 66 53 20 f5 fc cf 7d 4b 23 cb c6 04 88 b1 90 cd 35 f9 5c 99 d1 94 67 9e e7 7e 2e 8b 99 af ce 75 8e c9 2f ff ef 7f 43 4a d6 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a 40 7a e0 9b d2 03 26 df 94 03 95 e3 94 7f d4 d2 03 d2 03 d2 03 d2 03 d2 03 d2
                                                                        Data Ascii: PNGIHDRE4:;H&sRGBgAMAapHYsodIDATx^|j{Qwje6pTM@H#$-nn~fS }K#5\g~.u/CJ@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z@z&
                                                                        2022-08-18 22:19:10 UTC38INData Raw: dc a8 4c 76 51 10 94 be b5 8e bc cf 8a ff 36 ac 1c 5d 61 e5 e2 01 5b 2a 42 ed f8 1c 3b bf 20 d8 52 3d 6a e3 4d 2b 02 af 80 d9 b2 70 f3 85 15 95 a3 1e e1 b1 48 2e 28 47 63 df 08 c6 b6 ec 46 cf da 0d da 57 b4 6d fd 06 54 8d 8c 20 9b a3 fa 46 28 fa c2 5b ef 6a 28 fa d8 b3 2f 6b 5f 51 81 a2 f2 7d e3 52 7f df 90 ed 4b 8f 49 0f 7c b9 1e 10 28 2a 50 54 fe 4a 21 3d 20 3d 30 4f 3d 20 50 54 a0 d5 c5 40 2b 79 ad f4 cf a5 ec 81 cb 1d 8a fa 66 47 40 81 51 6f 02 2a 2b 3f 4f 0d e9 16 db 50 bd 68 4d c5 22 6b b9 35 61 a8 aa 99 04 fa b9 01 4b 97 0a 8a ea ed 5a 11 1c b2 96 b3 cc 08 1a 3d 7c dd 91 4b 25 63 5b 63 05 5a 6b ca 50 55 51 46 28 5a 83 ca 9a 26 ad 16 cd 63 6a 75 5e 01 bd 41 39 0a 5e 41 7f d0 aa fa 22 2a 49 73 90 41 95 60 1c 15 89 11 1c 89 0e a3 2f a4 67 02 47 7d e3
                                                                        Data Ascii: LvQ6]a[*B; R=jM+pH.(GcFWmT F([j(/k_Q}RKI|(*PTJ!= =0O= PT@+yfG@Qo*+?OPhM"k5aKZ=|K%c[cZkPUQF(Z&cju^A9^A"*IsA`/gG}
                                                                        2022-08-18 22:19:10 UTC86INData Raw: 0e 5c 83 b5 7b 77 a3 76 f5 6a 0c 53 29 aa 3c 45 35 14 fd fe fb 78 fe 95 37 71 fa cc 4b 78 e6 5b 92 3e 7f 39 7e 86 97 7d 96 ef 9e d2 03 57 6e 0f 08 14 15 28 2a 7f a5 90 1e 90 1e 98 a7 1e 10 28 2a 50 eb 52 42 2d d9 b6 f4 d7 c5 f4 c0 95 06 45 4b 6a 4a 90 98 91 01 07 0f bf 73 a0 a8 29 81 a8 2a 23 14 d5 5e 9f e7 41 51 a5 04 b5 65 02 f5 47 9f fc 01 bf a7 a6 eb 2f ac 8f ff 7c 6e bd fe 9d ef 62 df a1 c3 48 ce 62 72 37 e1 a0 52 5b ae 62 da b6 ba 6d ae c6 f4 a9 b0 54 c0 34 30 34 0c 87 6e b8 11 ef fe e8 47 f8 dd 9f fe 84 3f cd 68 c4 fe e5 5f fe 09 8f 3d 7c 1f d6 ad 1d 41 53 13 41 4d 49 85 06 a2 c5 a5 e5 28 ab a8 c4 fb 3f fd c9 4c bd cf eb f7 30 b5 75 12 4d 54 29 d6 37 55 51 39 9a a7 61 e8 63 a7 1f c2 4f 3e 78 0f ef fe e0 db 78 fb dd d7 99 28 9e a5 c7 ed 7f ff a7 df
                                                                        Data Ascii: \{wvjS)<E5x7qKx[>9~}Wn(*(*PRB-EKjJs)*#^AQeG/|nbHbr7R[bmT404nG?h_=|ASAMI(?L0uMT)7UQ9acO>xx(
                                                                        2022-08-18 22:19:10 UTC102INData Raw: d7 d0 68 84 87 b0 7d 3e 2c 1a ad 41 51 54 8a 16 e2 c6 fe b9 b8 7b d7 2d b8 ff f0 51 3c fa c0 a3 78 f4 f4 39 9c a0 1f e9 9d 84 a4 07 4f 9e c0 fd 67 cf 52 35 7a 04 fb 6e 39 88 3b ee 3b 89 47 9f 7d 89 e9 f3 ef e0 b9 37 7e a4 b5 cf 6b df bb 35 21 8a 36 07 b4 39 f0 2d 9c 03 1a 14 fd 16 5e 94 6f 1b c8 d1 8e 47 83 8b da 1c f8 db cc 01 0d 8a 6a d0 ea af 81 56 da 6b b5 f9 f3 f7 9c 03 ff ec 50 34 95 e1 4a 52 99 15 39 c8 aa cc 45 6e 6d 31 32 cb 0b 10 98 10 ad a0 9b 40 19 81 a1 36 1e 3e b0 72 f3 84 85 93 3b 5b e8 5d 55 99 d8 eb fc 45 f5 de a2 a2 7e b4 71 72 a3 a2 d2 05 06 53 8d 74 01 44 e3 45 b5 a8 80 d1 09 25 c0 54 94 a4 52 56 f6 f4 4e 34 31 55 ad f3 d6 92 74 cf 56 79 a5 12 35 b1 21 18 65 1a b7 c1 54 4c 32 32 45 70 78 04 3a 99 62 dd 37 dc 8f 61 82 1b 69 8b 2f 2c 2e
                                                                        Data Ascii: h}>,AQT{-Q<x9OgR5zn9;;G}7~k5!69-^oGjVkP4JR9Enm12@6>r;[]UE~qrStDE%TRVN41UtVy5!eTL22Epx:b7ai/,.
                                                                        2022-08-18 22:19:10 UTC118INData Raw: 00 ce 6f 98 83 a7 57 8e e2 99 c5 54 0e cf ed c0 91 d1 06 dc 32 a3 14 ab 6a 12 b0 ae 39 1d bb 18 62 75 68 51 37 f6 cf eb c0 ae c1 3a dc d8 53 82 bd 83 e5 38 b6 b0 0d c7 17 f7 e0 d6 d9 1d c8 0a f2 82 b1 89 05 55 a8 2e f4 12 75 57 35 11 8a 8a 5d 45 40 70 00 fa d9 66 bf b6 3b 1f 0b 0b 83 71 80 00 76 35 e7 e8 5d 4b fa a9 10 7d 1b e7 8f 1c 84 af 07 8f 6d 8a 03 2c fd a9 bc 0c 4c 66 31 c4 28 88 e0 97 6b 7b 5f da 28 d0 2f d5 25 32 1e 16 3e 01 70 0e 0c 45 7d 6b 17 ae 5f bd 19 3b b7 ec c1 9e db ee c1 ae 3b 8f 10 80 ee a5 8f e8 6a 74 cd 5d 80 99 cb 57 62 dd 8e 1d 58 bb 7b 07 ca 66 74 c3 29 31 0a 06 01 5e 54 78 26 20 ae be 1a d9 5d 6d c8 ee 6b 47 7c 7b 1d 42 f9 c3 83 24 cc 5b 14 f1 47 16 2a 7f 93 7a 9b 11 c7 cf 9c 67 3d ad 01 0a d3 60 95 1c 8d 49 be 9e 30 f0 e2 df 92
                                                                        Data Ascii: oWT2j9buhQ7:S8U.uW5]E@pf;qv5]K}m,Lf1(k{_(/%2>pE}k_;;jt]WbX{ft)1^Tx& ]mkG|{B$[G*zg=`I0
                                                                        2022-08-18 22:19:10 UTC169INData Raw: a1 a1 85 76 03 dd 35 3c df 66 cc 60 70 52 ff 9c 4e f4 31 3c a9 7d a0 01 75 7d d5 84 a0 f4 56 6d 2b 24 10 2d a2 37 68 31 4a 3b 4a 50 d5 5b a9 94 a2 5d f3 09 a8 17 0d 60 60 e9 4c f4 2f 1e c5 c0 92 39 5c cf 45 cf fc 51 b4 cf 19 66 ba fc 00 5a a9 1a 15 58 5a 4b 65 6e 6e 73 0d 12 ca 72 91 d7 58 81 aa be 56 54 ce 68 55 50 34 bf a3 16 b1 15 b9 08 ce 4b 42 68 41 2a 82 73 53 18 ea c4 a4 fa d6 06 2a 30 4f e0 ee 13 27 b1 6b ff 01 3c f8 e8 23 b8 6d c7 36 cc e2 7f 7f 47 b2 32 31 98 9b 8a 91 ca 3c 94 a7 47 61 70 a0 03 7e 31 91 98 c2 b4 76 03 fe b7 d7 d8 c5 1d 76 de 81 b0 f7 09 c2 64 7b 37 aa 6a 7d 30 d9 89 30 93 1e 9b 06 56 b2 0d 1f 73 f5 85 95 5f 98 52 88 3a 86 c4 2b d5 a8 40 51 d9 ce d8 3d 70 dc 4b 54 5a e6 05 86 da 7a 86 a8 32 92 a0 25 73 27 cc 5c b2 0e b7 dc 7d 1c
                                                                        Data Ascii: v5<f`pRN1<}u}Vm+$-7h1J;JP[]``L/9\EQfZXZKennsrXVThUP4KBhA*sS*0O'k<#m6G21<Gap~1vvd{7j}00Vs_R:+@Q=pKTZz2%s'\}
                                                                        2022-08-18 22:19:10 UTC185INData Raw: 33 b1 6f e3 3c ec da b4 40 d5 c1 ad 0b b0 73 c5 68 ec 5d 35 10 fb 57 f5 c7 e1 15 c3 b1 7e 51 25 86 8e ab 42 ec 80 e1 08 a3 82 37 98 50 b9 79 ef 01 68 5b 3c 12 1d fb 8c 40 48 7c 77 98 78 50 a5 1a 18 85 b6 f1 a9 e8 db 29 0b 23 bb 64 60 04 53 c6 f3 22 5b a2 77 87 0e 18 39 aa 02 41 91 91 0a 80 0a 14 ad 47 30 ae 27 ef f9 bf 09 45 05 98 2a 1f 52 26 d6 0b 1c ad 85 a2 1c bd b7 66 b2 fc 83 f1 79 1d 14 15 f5 a7 0e 8a 1a 38 f8 fd 46 29 fa af a0 68 42 6a 16 26 cc a9 c1 d8 99 d5 18 3d 79 1e e6 2c 5e fb 2f 95 a2 e2 29 fa 50 29 ca 74 7a 81 a2 c6 1c eb 97 31 f4 7f 05 46 8d e8 e7 29 8f 69 de 3a 11 fd 4a 46 21 93 81 54 5d 7b 16 62 ce d2 8d 68 9b 9e 4f 00 ea c9 cf 27 3d 3a 1d 24 59 be 76 d4 5f 77 bc b2 94 eb bf 07 a3 3a 38 2a 4b 01 a6 72 ff a3 a5 60 f0 03 78 aa 83 a2 02 46
                                                                        Data Ascii: 3o<@sh]5W~Q%B7Pyh[<@H|wxP)#d`S"[w9AG0'E*R&fy8F)hBj&=y,^/)P)tz1F)i:JF!T]{bhO'=:$Yv_w:8*Kr`xF
                                                                        2022-08-18 22:19:10 UTC201INData Raw: 63 e6 a8 a0 68 ef 76 b1 48 8b 89 80 b9 1d fd 44 05 8a f2 f3 a8 67 e7 82 3a 0c 25 32 a0 4a b4 be a1 39 7c 7d 02 10 15 11 07 67 7b 77 04 fa 05 21 98 3f 6e 94 27 45 e2 d9 31 03 b1 79 70 3e 56 0d c8 c5 e2 c1 d9 d8 3e 69 20 8e ce 1a 8a 23 53 8a b1 b7 aa 37 76 8c ea a5 96 1b 4a d2 b1 a3 32 97 aa d2 fe 78 6d 29 61 e8 9a f1 78 7f e3 14 bc 45 20 fa ca b2 51 78 69 49 b9 aa 57 96 94 e1 e5 ea 12 3c 37 67 20 f6 4f 2d c4 ae f1 4c 9e e7 68 fd da b1 05 88 0e 0b 85 b1 85 0b cc 6c 7d 61 e5 d2 10 d6 fe 0c 1c 0b 24 a4 6d e2 81 a8 50 7f fe a0 11 86 e6 51 ad d0 24 2a 8a ca f3 86 ea c7 95 7a d6 b6 30 f1 f0 86 85 4f 03 d8 51 2d ed e8 df 48 95 2b fd 74 9d 03 1a c3 da cb 47 83 a2 da f7 6f 4d 90 a2 f5 80 d6 03 4f 50 0f 68 50 f4 09 7a 33 34 68 a6 41 33 ad 07 fe b7 7b 40 83 a2 1a 78
                                                                        Data Ascii: chvHDg:%2J9|}g{w!?n'E1yp>V>i #S7vJ2xm)axE QxiIW<7g O-Lhl}a$mPQ$*z0OQ-H+tGoMOPhPz34hA3{@x
                                                                        2022-08-18 22:19:10 UTC217INData Raw: f2 cb 0b 1c ee 26 5b e7 d7 56 16 b0 be ba 88 9d d3 5b 2c 9e ba 80 8e a1 29 58 b8 06 50 f1 e9 86 63 84 a2 2a 35 e8 31 0b 17 7e ec c2 cc 50 57 99 1d aa 82 a1 22 4f 54 0e c1 a8 9e b5 07 8c 9d fc 69 97 0f 40 2c 55 a2 8d bc af 99 d3 17 31 bc b4 c1 9c cf 62 e4 11 8e 5e b8 7e 0f 4f df 7f 43 b6 cc 8b ec 50 71 7c f6 fe 3b 78 9b 80 f3 8d 77 be f3 28 4b f4 eb 84 a0 1f 7c ef 97 f8 ee 4f fe 14 df fd f9 5f e0 a3 9f fd 05 be f9 a3 3f c1 3b df f9 39 de fe f0 67 b4 ce b3 89 fe 1b 2c 5b 7a e3 43 8c 2f 9d c3 e0 dc 0e ce dd 7e 19 4f bf f6 4d dc 7b fd 03 8c ac ec f1 f1 78 f1 4d 00 2d 58 58 bb d0 46 6f 84 16 16 6f 6d 55 97 61 86 e0 da d1 cc 8a 4a 51 43 da e7 0d 71 4c db 88 50 d4 48 66 89 0a 20 2a 46 b6 d2 f3 73 87 b8 ef 87 09 ee b5 08 45 c5 ef 89 36 df fc 10 fb 90 1e c9 37 2f
                                                                        Data Ascii: &[V[,)XPc*51~PW"OTi@,U1b^~OCPq|;xw(K|O_?;9g,[zC/~OM{xM-XXFoomUaJQCqLPHf *FsE67/
                                                                        2022-08-18 22:19:10 UTC233INData Raw: e4 16 33 1f b4 0b 13 13 53 18 1e 1a 95 70 51 40 46 01 41 27 c7 26 25 10 cd ce cc 91 76 7a 71 5d 45 69 a5 84 a2 42 35 2a ec f3 02 8a e6 10 b2 b4 33 c7 73 7e 64 06 4d b4 d9 ba 85 85 d2 d2 bb af 14 15 56 77 57 4f 1f 54 56 d5 61 7a 76 51 42 d1 94 d4 4c 69 9b 57 53 3b 22 8b 9c 44 09 53 45 4d 3d 12 a8 4a 3d 68 9f 57 01 d2 4f 83 a2 a2 94 49 9d f7 a1 47 5b b9 b0 f6 0b 98 2b ec e3 4e 84 30 81 51 91 12 8a e6 53 c1 1a 1b 1e 47 e8 ea 04 2b 2b 0b d8 99 1e 82 93 99 1a 6c cd 0e a1 30 3d 18 0b 7d d5 d8 1a 69 c2 58 53 d1 27 66 b2 95 96 e3 de 5a 9c 66 53 f6 de ca 10 76 e6 7b 70 61 7d 14 b7 2f 2e e2 b9 9b 5b b8 77 75 0d b7 f6 16 70 89 e0 f3 fc c6 28 3f 37 8e 4b 9b 93 72 c4 e5 8b 6b e3 b8 ba c9 f6 f9 b3 0b b8 b3 bb 88 a7 59 ac a4 9a a7 ce 2e e2 a9 d3 0b b8 b7 bb 84 e7 f7 d6
                                                                        Data Ascii: 3SpQ@FA'&%vzq]EiB5*3s~dMVwWOTVazvQBLiWS;"DSEM=J=hWOIG[+N0QSG++l0=}iXS'fZfSv{pa}/.[wup(?7KrkY.
                                                                        2022-08-18 22:19:10 UTC249INData Raw: 35 80 c5 4e 7e cc 7f 74 62 d6 a3 a5 ad 23 6c a8 18 8d 4e 49 43 56 41 31 aa aa eb 51 cd 11 45 4b ad 04 53 1d 3c 37 5d 7d fd 2c cf a2 b2 96 d3 47 20 35 c8 1c d6 d1 f1 09 aa 43 f7 55 a2 42 2d 3a ce a2 2a 31 02 8c 8a 9c 50 15 04 15 20 54 c2 d0 95 4d 39 6b 54 fc ed ab 44 d9 fe fe 50 1d aa 52 88 0a 95 a8 6a 54 40 54 34 90 9f d9 bd 40 4b 35 95 89 7b 97 79 1e af fc ce 5c 20 98 bb c4 c2 9f 83 f3 31 fc dc 87 a0 02 88 fe 2e 14 bd 86 0b 97 69 99 bf 72 13 bb c2 92 4f 38 7a e9 f2 1d ac 9f be 84 49 5a cb a7 2f de c6 f2 ed 17 b1 72 e7 3e 36 9e 7e 0d db cf bd 89 33 2f 7d 0d e7 1f 7c 13 e7 08 45 cf be f6 4d 09 47 b7 5e fb 36 b6 5e fd 0e b6 df f8 1e d6 5e f9 0e a6 9e fb 3a 86 08 50 bb ee bc 8e 26 96 2d d5 ee 3d 8f 1a 96 31 95 9f 79 0e 39 ab 77 10 3b 7d 01 7e 93 db 08 9f 3b
                                                                        Data Ascii: 5N~tb#lNICVA1QEKS<7]},G 5CUB-:*1P TM9kTDPRjT@T4@K5{y\ 1.irO8zIZ/r>6~3/}|EMG^6^^:P&-=1y9w;}~;
                                                                        2022-08-18 22:19:10 UTC265INData Raw: 4f 49 a2 85 9e 59 aa e9 a9 48 df 79 14 95 2c 55 da 7b e1 36 f6 9d ba 8e 5d 27 ae a1 f5 d9 ab 68 3c 74 11 35 fb ce 63 0b c1 67 e3 b3 d7 54 e1 d2 b5 b7 3f c3 a9 17 de c3 51 02 d2 fd cf dd c5 ce f3 2f a1 ee f8 4d 54 9f 7a 01 19 fb 9e 83 6f d5 21 38 97 1d 40 d8 96 13 88 cd df 8a 9c 92 5a 64 97 17 23 a7 a2 88 16 7a b6 c2 13 8a d6 ee dc 89 c5 b6 ce 78 e2 69 43 3c be 72 33 3a 2f b3 46 0f 6e fb 1a da a3 df 06 47 8c b0 f1 c5 53 f6 01 4a 29 3a cf 33 02 4b 7c a2 60 18 9c 80 0d 81 09 58 eb 1b 89 65 1e 6d 50 74 ae b3 b7 82 a2 61 09 69 2c 31 24 c4 24 14 ad a9 a9 53 d0 b3 aa 9e 0a 58 05 44 ab da a1 68 35 ff 9b 5b 53 d3 06 48 cb f9 3e 8a 99 19 9a 4f bb 7c 7e 7e 21 8a 8b 4a 51 59 51 8d ea aa 5a 05 45 5b 09 45 77 ec da 89 86 e6 46 94 b2 a0 49 ae a7 fc 6c 70 f7 f6 81 8d 93
                                                                        Data Ascii: OIYHy,U{6]'h<t5cgT?Q/MTzo!8@Zd#zxiC<r3:/FnGSJ):3K|`XemPtai,1$$SXDh5[SH>O|~~!JQYQZE[EwFIlp
                                                                        2022-08-18 22:19:10 UTC281INData Raw: 3c f7 2e 9f 77 8b 4d f3 af b2 71 9e 1b 7c c8 e3 ee f0 f5 2e 71 ff 0b bc 7f 95 39 a6 3d 67 ae c2 e3 c3 fb 61 f2 d2 29 98 30 6f 26 2d f4 e3 31 67 c9 32 ac 32 da 88 c5 2b d7 60 f8 f8 89 e8 ca 6c d5 e1 8c 0f 98 c6 db ce 26 ab 91 1f 6a 86 2c af 65 c8 74 37 44 51 a8 0b 2a 33 e2 08 1d 13 d1 98 c7 26 6e 6f 7b d8 ac 5d 08 9b 8d cb b1 d1 68 09 a1 e8 7a ac da b8 0c 0b d7 2c c1 86 4d 04 cd ab 56 c2 c6 ca 16 e6 66 16 30 33 31 a5 1d de 06 4e 4e 4e 30 37 37 87 a9 e9 46 d8 6f b6 84 fd a6 0d 70 b3 b3 80 87 8b 33 fc 7d bd a9 0a b5 c4 66 3e 57 0a 67 92 08 18 13 68 23 ce 89 a7 ed 58 14 91 e1 41 68 48 0f c7 f6 74 7f b4 24 b9 a0 3a dc 12 a5 a1 36 6c b9 d7 61 77 49 0a 76 96 a7 13 8a e6 a0 32 3b 09 3a 1f da e7 09 42 ef 87 a1 72 5f e6 cb 76 fa 36 6b bd 1e 92 7a 79 79 28 20 2a 0a
                                                                        Data Ascii: <.wMq|.q9=ga)0o&-1g22+`l&j,et7DQ*3&no{]hz,MVf031NNN077Fop3}f>Wgh#XAhHt$:6lawIv2;:Br_v6kzyy( *
                                                                        2022-08-18 22:19:10 UTC297INData Raw: ba 34 9d 30 2d 65 da fc 95 53 bc 39 d3 be 21 29 3a cd a7 cf 2b cb 73 c6 bc 14 09 aa 3a a3 12 a2 33 e7 4c 0b 1e 55 73 74 c1 e2 b9 b6 70 c9 bc e0 71 ae 3f 37 75 2c 98 1b 64 86 86 7f 97 0c bd fa 9a ab 83 ae ed 0b 57 af b6 79 9b 77 da f2 db fe 62 1b ff f8 0f 6f b0 f4 2f bb ee de a7 6d fb 5f 9e b6 6b ef 7b da 36 bb 1c 5d 7a fb 23 36 fb e6 07 ec ca 6d 7f b2 e1 1b 76 5b ff 35 5e 1b 74 ed 4d d6 6b c3 ad d6 7b e3 1e eb b1 6a b7 5d be f1 4e 9b b8 f6 3a 1b 3f 6f a1 cd b8 da a7 e6 2f f6 29 e9 8b e7 79 76 a6 37 29 f2 71 e5 8c 39 36 6a c5 8d d6 fd 9a 3d de 68 69 43 50 53 b4 58 97 58 29 3a 39 55 8a 16 6b df df a5 68 2f 2b d6 ac b3 15 69 d8 c6 0a d4 68 6c 95 3a 76 b6 05 9b bd d1 d1 96 65 c1 be 6f dd 76 9d 6d 73 21 ba 7e c7 75 b6 69 db d6 d4 4c 51 35 4a 52 76 e8 96 ad aa
                                                                        Data Ascii: 40-eS9!):+s:3LUstpq?7u,dWywbo/m_k{6]z#6mv[5^tMk{j]N:?o/)yv7)q96j=hiCPSXX):9Ukh/+ihl:veovms!~uiLQ5JRv
                                                                        2022-08-18 22:19:10 UTC313INData Raw: 30 00 03 30 00 03 30 90 9b 18 40 8a 22 45 c9 12 84 01 18 88 88 01 a4 28 32 2b bb 64 16 eb 85 ad ac 60 00 29 ca 4d 50 6e ba 09 e2 58 e1 1d 06 60 00 06 60 00 06 60 00 29 1a 91 0c e1 cd c6 9b 0d 06 60 00 29 8a b8 ca 0a 71 c5 3a e0 28 bb 18 40 8a 72 9d e2 bb 0a 0c c0 00 0c c0 00 0c c0 00 0c e4 26 06 90 a2 48 51 b2 04 61 00 06 22 62 00 29 8a cc ca 88 cc 7a f6 bd 6f ed 8b ef 7e b6 5e 3b 5e b7 8c 3c 3f 2b 9f a3 6d bf fd d9 0f d6 70 f5 4b 91 6f 3b 2b 8f 83 75 65 ee bd 86 14 e5 26 28 37 dd 04 71 ac f0 0e 03 30 00 03 30 00 03 30 80 14 8d 48 86 f0 66 e3 cd 06 03 30 80 14 cd 9c a8 c9 6d 82 0b 29 0a 27 47 8a 79 a4 28 d7 29 be ab c0 00 0c c0 00 0c c0 00 0c c0 40 6e 62 00 29 8a 14 25 4b 10 06 60 20 22 06 90 a2 c8 ae 8c c8 2e a4 28 9c 64 84 93 ec 78 0e 52 94 9b a0 dc 74
                                                                        Data Ascii: 000@"E(2+d`)MPnX```)`)q:(@r&HQa"b)zo~^;^<?+mpKo;+ue&(7q000Hf0m)'Gy()@nb)%K` ".(dxRt
                                                                        2022-08-18 22:19:10 UTC329INData Raw: 59 bf d3 92 9e 14 55 cd 4e 75 7a d7 73 25 e6 d2 5b 24 12 1f 7e e5 ab 40 b8 4a 72 e6 f3 9a a5 ea 4a fe 82 77 81 8f 5d 24 df 6a 2d 7f 31 78 8e 24 e3 0e 9f c2 2f d1 18 8f 14 d5 b6 d4 54 a9 91 67 7a 6a 9f b4 ae f2 f3 9f b7 dd 4f 7e 66 9a 5e 1f 2e 92 7a ca a0 3d d0 fe 48 2e 86 fb ab d8 29 4b 54 92 51 8b b6 71 93 8b 56 49 41 bd 5e 31 da f2 e8 27 71 4b 51 09 ca 26 6b 53 c4 ef 46 6f e4 14 bb 8c bf fd b7 d9 aa e9 c5 56 fb a4 7d d3 be a8 6e a8 1e 25 9f 95 35 1b 2e 7a 8e 84 a6 8e 43 cf 39 7b ce b3 a6 c6 51 fa 7d 46 a4 a8 c4 aa 32 6d 15 cf 8e 5b 5f 4d 5d f7 c1 62 88 14 4d 24 0d 99 58 fb 82 14 8d ff 3a c1 b5 95 98 c1 00 0c c0 00 0c c0 00 0c c0 40 74 0c 20 45 91 a2 64 09 c2 00 0c 44 c4 40 14 52 34 b1 94 08 7b 73 a8 08 28 1b 53 d3 f7 d5 89 9e 85 08 24 5b 04 90 a2 d1 7d
                                                                        Data Ascii: YUNuzs%[$~@JrJw]$j-1x$/TgzjO~f^.z=H.)KTQqVIA^1'qKQ&kSFoV}n%5.zC9{Q}F2m[_M]bM$X:@t EdD@R4{s(S$[}


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        6192.168.2.3606705.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:10 UTC11OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/sign.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:19:10 UTC20INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:10 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 1363
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-553"
                                                                        Expires: Sat, 17 Sep 2022 22:19:10 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:10 UTC21INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 20 00 00 00 3b 08 06 00 00 00 db e5 57 6c 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 04 e8 49 44 41 54 78 5e ed 9d 4b 4f 13 61 14 86 fb 07 0c fc 0a 17 ee 4d 48 d8 18 13 d7 c6 9d 31 ba 77 a5 c6 05 b0 72 a1 c4 1d 48 22 31 51 59 40 5c b9 50 42 30 46 13 a3 09 de 75 a1 20 8a 05 04 34 45 ae 55 c0 16 28 97 1e e7 0c 19 02 a4 cc d0 e9 94 43 db a7 c9 24 84 b6 f3 35 67 9e 3e df fb 5d da c6 84 1b 15 a0 02 54 c0 a8 02 31 a3 76 69 96 0a 50 01 2a 20 08 08 08 a8 00 15 30 ab 40 a0 80 ba fb e7 a5 b6 65 50 aa 1b fa 24 76 f1 13 07 35 80 01 18 08 64 40 7d a1 de 50 7f f8 dd 7c 05 d4 d9 37 17 d8 10 52 42 ca 30
                                                                        Data Ascii: PNGIHDR ;WlsRGBgAMAapHYsodIDATx^KOaMH1wrH"1QY@\PB0Fu 4EU(C$5g>]T1viP* 0@eP$v5d@}P|7RB0


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        7192.168.2.3538675.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:10 UTC11OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/footer.PNG HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:19:10 UTC54INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:10 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 68010
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-109aa"
                                                                        Expires: Sat, 17 Sep 2022 22:19:10 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:10 UTC54INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 02 32 08 06 00 00 00 07 55 10 38 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 ff a5 49 44 41 54 78 5e ec fd 0b 78 1c 69 7d ef fb fa 5c f6 b9 5f d6 da e7 d9 47 e7 ec 75 f6 e3 b5 cf de cf f6 59 e1 e2 10 48 14 16 09 5e b9 8a bb c3 d5 5c 63 92 81 08 c2 45 80 43 6c 88 03 98 c1 68 e2 04 0b 70 86 86 89 19 39 10 2f e1 84 48 8c 09 08 10 20 c3 18 84 01 8f 84 3c 6e d9 23 8d 7b ac 91 91 46 1e 59 d6 58 23 8d 35 b2 ff e7 ff be 55 d5 5d 55 5d d5 55 2d 75 b7 5a dd 5f 3d f1 13 46 ea ae 7a eb f3 d6 f5 57 ef 65 8b f0 83 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 34 91 c0 c2
                                                                        Data Ascii: PNGIHDRF2U8sRGBgAMAapHYsodIDATx^xi}\_GuYH^\cEClhp9/H <n#{FYX#5U]U]U-uZ_=FzWe 4
                                                                        2022-08-18 22:19:10 UTC70INData Raw: a3 ba 50 eb f9 c5 3f b1 15 2d 46 2b 7b b1 4f 3c d6 cb 0f 46 9d 89 08 27 7d e5 d4 7d cc 8c 35 ee b5 86 4e 6c 31 ea ec 07 85 31 f0 dd f3 b6 6f 22 be c0 b9 be ec 7b 88 30 61 52 30 ea 4e de 18 7a 46 08 5e f7 92 ef 29 bc 61 6a 72 be d5 fb 5f 54 26 ba e9 f7 92 82 51 ef 3e a3 dc e7 1d 5a 8c 56 f6 b0 62 69 08 20 10 2d 40 30 ca 9e d1 d8 02 6b 0d 46 c5 dc 44 8c 4a db 81 f0 4c c4 ce c0 e1 85 c9 8b 74 82 8d 51 6d c1 a8 13 9a d8 76 0c de c4 20 ee 04 27 f9 c9 99 f2 93 04 39 37 27 db 75 c6 c5 e9 25 af e5 43 68 c2 83 a2 09 91 a2 6e 36 8a ab 2d ee c6 21 f8 7b 77 22 24 df 04 21 d3 b9 cb d2 79 d4 9b 3c 2a 74 03 36 35 2e 6d 1a 96 74 9c 36 83 d8 eb 64 06 bd e7 dd d9 ec 0b 21 a6 99 70 c4 84 44 dd b9 1b b2 ec 36 94 8a 9e 7c c9 9b f0 c9 1b 0c 3f 3c f9 52 89 60 d4 d6 87 6f 72 26
                                                                        Data Ascii: P?-F+{O<F'}}5Nl11o"{0aR0NzF^)ajr_T&Q>ZVbi -@0kFDJLtQmv '97'u%Chn6-!{w"$!y<*t65.mt6d!pD6|?<R`or&
                                                                        2022-08-18 22:19:10 UTC134INData Raw: 10 40 00 01 04 10 40 00 01 04 10 40 a0 51 04 08 46 1b a5 26 d9 0e 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 48 2d 40 30 9a 9a 8a 0f 22 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 40 a3 08 10 8c 36 4a 4d b2 1d 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 90 5a 80 60 34 35 15 1f 44 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 81 46 11 20 18 6d 94 9a 64 3b 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 40 20 b5 00 c1 68 6a 2a 3e 88 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 8d 22 40 30 da 28 35 c9 76 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 08 20 80 40 6a 01 82 d1 d4 54 7c 10 01 04 10 40 00 01 04 10 40 00 01 04 10 40 00 01
                                                                        Data Ascii: @@@QF&@@@@H-@0" @6JM Z`45D@@@@F md;@@@@@ hj*> "@0(5v @jT|@@@
                                                                        2022-08-18 22:19:10 UTC150INData Raw: 7b 28 6d 31 37 75 30 fa f8 6b 5f 2a b7 57 cb 6b 1d 9c 08 a3 b6 8f ef 7a 05 c1 68 22 14 1f 40 00 01 04 10 40 00 01 04 10 40 00 01 04 10 68 26 01 82 d1 66 aa ed 26 dc d6 cd 1c 8c b6 ff 60 56 7e f8 cb 25 f9 e5 93 4f db c6 96 49 3f 8f 2f af ca a7 7e 31 2f bf 96 30 03 7d 54 eb d4 a4 65 7b 7f 9f fb d0 1f c9 e3 1f f8 6d 59 fc d8 8b e2 c7 0f 35 e1 e8 cc b8 3c 7d f8 45 da 9d fe 19 b2 bc e7 19 f2 d4 fb 9f 2d 4b ef fe 55 59 7a c7 73 e5 c9 3b 7e 53 6e bc e5 05 b2 f4 86 df 91 e5 77 be 55 6e 3d 72 b9 e4 58 a4 93 2f 3c 24 e3 cf 3a 20 b9 df fa 74 da 62 6e ea 60 d4 4c aa b4 74 f2 5f 53 6f 6b 9a 0f 2e 7f f3 64 51 28 6a d6 c3 0f 02 08 20 80 00 02 08 20 80 00 02 08 20 80 00 02 cd 2c 40 30 da cc b5 df 04 db be 99 83 51 13 60 9a 90 f3 bd a7 af ca 3f eb ac f4 d9 6b 37 e5 c6 ca
                                                                        Data Ascii: {(m17u0k_*Wkzh"@@@h&f&`V~%OI?/~1/0}Te{mY5<}E-KUYzs;~SnwUn=rX/<$: tbn`Lt_Sok.dQ(j ,@0Q`?k7
                                                                        2022-08-18 22:19:10 UTC166INData Raw: c1 04 ac 88 1a 5e 70 c8 8b 8f 49 3d 7f e8 17 84 d1 4e 76 fe 56 a4 36 70 ac 23 af f0 c0 fa bd 69 cc 25 97 ca d2 cd d8 4d 95 80 9f 1b 79 e9 33 17 71 74 27 f6 ab 4b f2 b0 90 14 0b c2 7a 1b a7 00 19 cc bd b8 e9 3c d2 fb 63 37 df 97 b3 88 fb c2 be 5f 78 d9 2a 3f 4d 21 12 be 17 11 d5 a6 14 f1 f9 91 8b b9 9c 98 d5 56 ce a9 8b c1 8a d1 55 e1 de e6 7b 0d de f8 b9 b5 62 db d4 7d 65 57 ac f9 0f 9b 73 99 1c a3 8f 7b 7d a5 67 10 80 00 04 20 00 01 08 40 00 02 10 f8 1b 04 10 46 ff c6 3c 32 8a 24 01 15 43 fc 83 b5 8a 77 89 fc 9e 4e f7 99 77 2b c2 22 5e 7b 9a 3f b4 f0 16 b4 3f 4d 84 c7 37 14 69 69 12 3b ad 88 11 0b 85 75 81 25 35 36 15 4f e2 22 33 f5 bf 93 7d 13 f1 49 c2 ae 0b b1 42 db ad a4 06 70 82 52 4f d2 0c 94 79 3a 4f 66 3d 16 d1 44 44 44 87 ca 8d f7 14 f7 a9 32 de
                                                                        Data Ascii: ^pI=NvV6p#i%My3qt'Kz<c7_x*?M!VU{b}eWs{}g @F<2$CwNw+"^{??M7ii;u%56O"3}IBpROy:Of=DDD2


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        8192.168.2.3598635.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:10 UTC331OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/favicon.ico HTTP/1.1
                                                                        Host: internet-cheboksary.ru
                                                                        Connection: keep-alive
                                                                        sec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"
                                                                        sec-ch-ua-mobile: ?0
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
                                                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                        Sec-Fetch-Site: same-origin
                                                                        Sec-Fetch-Mode: no-cors
                                                                        Sec-Fetch-Dest: image
                                                                        Referer: https://internet-cheboksary.ru/tkkt/americanexpress.com-logon/AMEX/Amex/home/
                                                                        Accept-Encoding: gzip, deflate, br
                                                                        Accept-Language: en-US,en;q=0.9
                                                                        Cookie: mycounter=Checked
                                                                        2022-08-18 22:19:10 UTC331INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:10 GMT
                                                                        Content-Type: image/x-icon
                                                                        Content-Length: 894
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-37e"
                                                                        Expires: Sat, 17 Sep 2022 22:19:10 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:10 UTC332INData Raw: 00 00 01 00 01 00 10 10 00 00 01 00 18 00 68 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 18 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 5f 01 f1 7d 00 ef 7e 00 ef 7e 00 f3 7d 00 f0 7c 00 f1 7a 00 f1 7a 00 ef 77 00 f0 78 01 f0 75 01 ef 74 00 ef 72 00 ee 70 00 ed 70 00 ed 71 00 d6 69 00 f9 8a 00 f9 8a 00 f7 8a 00 fa 87 00 f8 88 00 f8 88 00 f9 86 00 f7 84 00 f6 81 00 f7 7f 01 f7 7e 00 f6 7d 00 f5 7a 00 f6 78 01 f6 78 01 db 6f 00 fc 91 00 ff 92 00 fc 91 00 fe 91 00 fb 8f 01 fc 8d 01 fd 8b 02 fa 88 00 f9 86 00 fa 84 01 f9 81 00 f8 80 00 f8 7c 00 f7 7a 00 f8 78 01 de 75 00 fe 99 01 ff 9a 01 ff 9b 00 ff 9b 00 fe 97 00 fc 95 00 ff 92 00 fc 8e 00 fb 8c 02 fa 87 01 fa 84 01 f8 82 00 f8 80 00 f8 7c 00 f7 7a 00 df
                                                                        Data Ascii: h( _}~~}|zzwxutrppqi~}zxxo|zxu|z


                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                        9192.168.2.3619575.101.152.35443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        TimestampkBytes transferredDirectionData
                                                                        2022-08-18 22:19:12 UTC332OUTGET /tkkt/americanexpress.com-logon/AMEX/Amex/home/images/head.PNG HTTP/1.1
                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                        Host: internet-cheboksary.ru
                                                                        2022-08-18 22:19:12 UTC334INHTTP/1.1 200 OK
                                                                        Server: nginx-reuseport/1.21.1
                                                                        Date: Thu, 18 Aug 2022 22:19:12 GMT
                                                                        Content-Type: image/png
                                                                        Content-Length: 8182
                                                                        Last-Modified: Tue, 01 Dec 2020 23:38:36 GMT
                                                                        Connection: close
                                                                        ETag: "5fc6d3fc-1ff6"
                                                                        Expires: Sat, 17 Sep 2022 22:19:12 GMT
                                                                        Cache-Control: max-age=2592000
                                                                        Accept-Ranges: bytes
                                                                        2022-08-18 22:19:12 UTC334INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 05 46 00 00 00 3b 08 06 00 00 00 b7 c5 50 d9 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c3 00 00 0e c3 01 c7 6f a8 64 00 00 1f 8b 49 44 41 54 78 5e ed 9d 7f 70 1c 49 75 c7 5d f9 55 f9 41 42 12 52 18 42 8a ab 4a 2a b9 40 91 72 08 49 9c df 06 52 15 55 11 c0 f9 51 a9 23 55 21 fe 23 09 ae 0a 95 32 c4 10 9b 60 7e 38 c7 9d 88 c3 d9 70 07 d1 c1 39 c8 e4 70 8c 81 c8 c4 47 61 c0 80 04 18 8c 01 23 7b 65 4b b2 25 7b 6d 9d 7c d2 c9 96 64 59 3e c9 96 6d 5e de eb 99 d9 9d 5d ed 6a 76 ad 19 ed cc ee 67 aa b6 a4 9d 99 ed e9 fe 74 cf 4c f7 b7 5f bf b7 4a d8 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 40 00 02 10 80 00 04 20 00 01 08 b4 08 81
                                                                        Data Ascii: PNGIHDRF;PsRGBgAMAapHYsodIDATx^pIu]UABRBJ*@rIRUQ#U!#2`~8p9pGa#{eK%{m|dY>m^]jvgtL_J @ @


                                                                        Click to jump to process

                                                                        Target ID:1
                                                                        Start time:00:19:03
                                                                        Start date:19/08/2022
                                                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        Wow64 process (32bit):false
                                                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kutt.it/t6killx
                                                                        Imagebase:0x7ff68c970000
                                                                        File size:2438312 bytes
                                                                        MD5 hash:74859601FB4BEEA84B40D874CCB56CAB
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:low

                                                                        Target ID:3
                                                                        Start time:00:19:05
                                                                        Start date:19/08/2022
                                                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        Wow64 process (32bit):false
                                                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,11702765727564047898,12252251064509017740,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 /prefetch:8
                                                                        Imagebase:0x7ff68c970000
                                                                        File size:2438312 bytes
                                                                        MD5 hash:74859601FB4BEEA84B40D874CCB56CAB
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:low
                                                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                                                        No disassembly