Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://njanow.com/

Overview

General Information

Sample URL:http://njanow.com/
Analysis ID:743264

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic
Performs DNS queries to domains with low reputation

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://njanow.com/ MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6924 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1892 --field-trial-handle=1856,i,17332521273761336343,7925953552888964040,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
Timestamp:192.168.2.31.1.1.163858532023883 11/10/22-17:07:46.082806
SID:2023883
Source Port:63858
Destination Port:53
Protocol:UDP
Classtype:Potentially Bad Traffic

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownHTTPS traffic detected: 23.224.145.194:443 -> 192.168.2.3:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.83.25.141:443 -> 192.168.2.3:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.224.145.194:443 -> 192.168.2.3:49745 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2023883 ET DNS Query to a *.top domain - Likely Hostile 192.168.2.3:63858 -> 1.1.1.1:53
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: zhibo128x2.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: zb128e9.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: zb128e9.xyz
Source: DNS query: zhibo128x2.xyz
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:44 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeVary: Accept-EncodingContent-Encoding: gzipContent-Length: 9639Content-Type: text/html; charset=utf-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 7d 79 73 14 c9 b5 ef df 10 31 df a1 2d bf fb 04 cf b4 54 fb 02 12 b6 86 61 c2 e3 77 3d 63 3f cf 73 f8 5e 87 63 22 ab 2a 4b 6a e8 45 ee 6e 21 98 31 11 5a 10 5a d0 ca 0e 12 bb 36 10 48 20 34 20 b5 24 f8 30 ea ac ea fe 8b f7 11 de c9 aa 5e 91 ba 25 a0 ab 3c 13 a3 8e 96 ba 96 ac 93 27 4f fd f2 9c 93 27 b7 a6 5f 7d f1 cd 89 6f ff eb 4f 27 03 6d c9 48 f8 f8 67 07 9b 72 bf 07 9a da 30 32 e8 c1 81 a6 08 4e a2 40 14 45 70 73 dd 69 7c ae 33 16 37 12 75 01 3d 16 4d e2 68 b2 b9 8e f4 8d 64 56 d6 5a ec d4 9c b5 34 69 0f f6 5b 37 ee db f7 bb dd ab 99 b9 8b d9 87 13 2c c7 64 36 97 d2 eb af de 6d 0c a7 d7 fa 2a 7d b3 ab cf 68 82 d4 6d 6b 65 99 4c 6e a6 53 73 f6 f2 1b 72 a5 3b 97 60 b5 cb 4e bd 4d af 8e 90 91 07 05 3a 6e 02 32 32 40 a6 a7 20 01 19 4e a5 53 c3 f0 df 9e 1d 23 03 8f 77 a4 e6 b2 97 5e bd 42 13 3b 44 20 59 69 82 6c df 65 92 ba 51 4a 8d d2 59 ed b2 a6 9e da eb 1b 64 7c 20 bd 76 07 be ee 23 6e 82 ba 40 e3 36 49 19 38 a1 c7 43 ed c9 50 2c ba 2f ac 52 61 1d 71 09 b9 65 ce f1 e4 dc 96 39 f7 ec 88 fb 7c 29 d3 b9 63 87 e2 11 d2 fd da 7e 32 13 70 1f 0a e4 2f 3e 1f 23 cf a7 c9 cc 40 e6 d1 6a 7a ed 25 e9 1b b4 52 53 f0 b5 fb e6 40 cc 47 dc c4 99 c1 e5 ec fa 85 16 b8 e0 ca fa 08 5c 48 6f 0c c1 d7 de 9c 20 53 f3 20 b3 cc 5c 8f 3d 75 29 c7 dc e6 84 bd 70 eb 48 cb 5f ed 4b 1b 64 ec 52 ee 5d 39 94 4a 13 1f 49 a7 52 64 76 9d 3c 9f 20 b3 fd db e5 46 ae bf b6 9e af 14 20 92 0c 25 c3 f8 f8 bf 01 07 4d 8d 6e d6 45 a0 b6 25 93 ed 41 fc cf 8e d0 99 e6 ba 13 2e 42 83 df 9e 6b c7 25 78 4d e2 b3 c9 46 aa 12 8e 05 f4 36 14 4f e0 64 73 47 d2 0c 2a 75 c7 0f 6e a7 f1 b7 e0 ff 6d 09 9e 88 45 da 51 32 a4 85 4b c9 7c 75 b2 f9 64 a4 23 8c 92 f8 ab 93 2c 53 78 d8 ad 29 71 1c 35 70 1c c7 4b d2 77 62 ed 74 28 f9 af 10 0e ea 40 8e fe 26 92 28 6a bc f7 e0 99 10 ee 6c 8f c5 93 a5 0f 86 8c 64 5b b3 81 cf 84 74 1c 74 4e 8e 04 42 d1 50 32 84 c2 c1 84 8e c2 b8 99 6d 60 8e 04 22 e8 6c 28 d2 11 29 bd d4 91 c0 71 e7 1c 01 eb cd 0e 8f e1 50 f4 74 20 8e c3 cd 75 21 9d d6 e2 b6 38 36 9b eb 1a 93 38 d2 4e 8b d2 08 5c 36 86 22 a8 15 37 9a e8 0c 4d d2 00 ff ea 02 49 10 21 3c e2 dc 38 1b 74 1e 2d 23 96 48 9e 0b e3 44 1b c6 c9 9d 49 ea 89 44 a3 16 8b 25 13 c9 38 6a 6f 88 84 a2 0d 70 25 4f d6 79 21 f4 fc 83 49 82 24 23 b1 1a d1 6a 8b 84 e1 a7 36 b4 50 7b 7b 25 42 ae 06 2d bd 71 0a 9d 41 ee d5 ba 40 22 ae bf 4f ef 54 a2 f1 d4 3f 3b 70 fc 9c 23 b6 53 40 a4 a9 d1 4d fe 69 d4 c2 e8 fb 73 e1 18 32 3e 96 2c a0 37 19 d2 29 c1 b6 58 04 7f 04 05 5a cd 12 47 1b f3 fc 44 71 67 a2 31 a2 01 a1 df 9e 69 ae ff cd 1f 51 b2 ad 21 0e 15 24 16 39 74 f8 37 f5 3b 10 3f 7e 06 c5 01 f5 ba 1e 49 34 ff 50 07 15 b4 ad ee 68 5d dd 91 ba 48 c8 70 0f 3a e2 61 38 88 9e 42 d1 58 67 03 40 05 2e 75 a2 f6 1d ae 46 62 da 77 b4 38 1d 09 b8 c3 d4 9d 3f 56 cc 2b 10 08 34 39 6f 7c fb a
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Mon, 11 Apr 2022 16:13:35 GMTETag: "22d0-5dc6339e909c0-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 1928Content-Type: text/cssData Raw: 1f 8b 08 00 00 00 00 00 00 03 d5 59 eb 6f db 36 10 ff ee bf 82 40 50 a0 0d 22 47 92 65 f9 85 01 eb 92 05 2b e0 76 45 91 f5 6b c0 58 b2 2d 44 16 0d 49 4e dc 1a fe df c7 b7 48 8a 54 9c f5 31 54 01 42 99 3a f2 1e bc df dd 91 84 d3 35 7a 4c cb 43 0f e0 a7 4e f7 b5 97 a4 0b 54 c2 3a 43 c5 14 14 a8 48 67 bd 63 af d7 af b2 3a bd cd ea 3c 65 94 64 cc 32 47 4f 53 b0 ce 92 24 2d 66 60 9d 66 ab 75 3d 05 a3 e1 76 6f 0c 99 a7 cb 9a 0d c3 43 20 a6 c9 71 87 41 f3 89 8c d6 88 4a d2 33 a3 3d fa dc a4 27 cf 8a d4 6b 77 6f 61 92 64 c5 ca 2b d9 87 c0 17 1f 16 28 47 e5 f4 6c 40 1f ca fa 9e f2 fe 00 37 5c a3 25 2a 6a af ca be a6 d3 30 c6 a3 2c 1c f8 24 e0 cc f7 27 13 df 9f 49 6e 44 1d c1 0c cf 7c 79 0e de ff f9 e1 1f 70 7e 89 15 2c d1 d3 05 e8 2f f0 e4 10 4f 58 5e e0 d7 dc db 57 de 40 be 4d e4 5b 10 b2 d7 6a e3 c5 07 55 9f 29 f0 99 1a 1b 58 ae b2 82 fe 24 d6 db a4 c5 ee 13 7a 62 b4 4f 59 52 af a7 81 ef bf 9a 81 7b b8 78 58 95 68 57 24 9e 10 7a 09 c9 df ac 99 32 dc ee 81 cf fe cf c4 c4 ca bc f3 ac e2 eb 21 8c 30 88 ad d6 6f ba 4d 69 1b 93 06 92 86 ba 18 cc b3 55 a1 ba 81 60 a8 78 d8 c9 5c d5 19 17 69 51 a7 65 5b 9a 16 0f 50 6d 61 c1 18 25 59 b5 cd e1 97 29 c8 0a ca e1 3e 47 8b 07 b7 02 72 5a ec 12 74 cd e5 0b fb 7e 8f ca 24 2d bd 12 26 d9 ae a2 54 bc bf bd 24 dc 8f 14 07 c5 cb 44 1f 8b c2 a1 70 af 7e bd af df 5e 2b 96 32 a5 c4 34 bd 3e 4c ae 3f 5e bf fb 1c 60 e7 23 af 7f 6e b6 f5 17 f1 03 f7 ab dd 86 19 1a cc 4b 8a b0 8b 64 fe 1e 7b 36 25 c0 8e 2f 49 98 15 31 04 30 d5 ef 9b 34 c9 20 78 bd 81 7b 8f 79 29 98 8c b1 3a 6f 00 9b b7 c5 48 63 a6 ac c7 91 ea 66 9b 6f 34 e4 f3 35 13 be 48 7b 37 47 39 61 a3 27 7d 2e cf 75 73 60 55 d5 01 e6 22 19 0b 15 09 b7 10 f4 16 04 a8 28 88 c6 62 40 cb 31 f4 4f 2e 34 d8 f0 69 f2 6e b3 0d 23 27 5b fd 93 39 b5 4b 5d 53 44 16 02 9c 86 50 60 aa ad 50 1b aa 5d 0c a5 70 03 8c 54 0c 11 d1 36 14 06 68 07 da b7 6e e0 92 c7 06 de b6 c1 fc 66 cd 45 3c 0a 0e 6a 76 1a d1 47 00 eb af 9b 0b fa 3f 60 cd 80 35 11 6b 86 ac 89 0f 2c 70 7b f7 a8 ae d1 86 06 f5 d9 91 8d 06 d9 66 d5 ca 0c 3d e6 ba 5c a6 b8 1f 84 e1 e3 d3 4c 38 ef e5 f9 06 cf 25 43 2c 11 b8 f9 82 c1 26 be 8c f9 17 21 68 70 02 af 20 ec 87 51 e4 64 16 3b 99 05 b1 c1 6d 70 02 b7 30 ea 47 e3 b1 93 db c4 c9 2d 8c 0c 6e d1 09 dc 06 7e 27 b7 20 74 b2 1b 84 06 bb e1 29 ec e2 6e 76 43 27 bb c8 37 d8 c5 27 b0 8b c2 6e 76 63 37 3b c5 51 70 59 74 fd 11 bf 8a 18 cc 0b 1c 84 ab 30 5a 6a 2e b3 7d 9a 30 ce 5f bd ac 48 d2 3d 5e 26 fa 88 bc 4a 3d 9c a3 8e 96 5c fc 9d 15 7b fc 87 a9 85 10 05 ee 6a d4 64 35 cc ff 86 54 99 a6 10 65 9a e3 ca f7 31 15 d5 96 9e af 54 0e a0 cd 22 18 f7 47 43 6c 26 36 56 b5 50 53 1d 68 8e 3d 56 ba 29 8a 59 21 c9 44 55 ba cb 2e 15 9a 05 fc 26 71 1d 72 b5 b5 d0 0a 83 83 9d 85 63 b6
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 10 Dec 2021 13:24:24 GMTETag: "23af3-5d2caa4395200-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 21181Content-Type: text/cssData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 7d 6b 8f e4 38 92 d8 e7 59 60 fe 43 6e 0f 16 ee 9e ae cc 56 be 2b ab 31 05 9f d7 86 6f 81 db fb e0 5b 03 07 cc b6 01 a5 a4 ac d4 8e 32 95 2b 29 fb 31 67 fb b7 9b 0f 91 0a 92 11 24 95 55 3d b3 6b ac db b7 53 29 46 04 83 c1 60 30 18 24 83 ef be ff ed b7 bf 99 7c 3f f9 2f 75 dd b5 5d 93 5e 26 1f 97 b3 d5 6c 3e 79 7d ec ba 4b fb f0 ee dd 53 d1 ed 55 e1 2c ab 4f ef de 08 84 df d7 97 2f 4d f9 74 ec 26 8b 64 3e 9f b2 ff d9 4d fe f4 a9 ec ba a2 b9 9b fc e1 9c cd 04 d4 bf 94 59 71 6e 8b 7c 72 3d e7 45 33 f9 e3 1f fe 04 08 97 dd f1 ba 17 24 bb 4f fb f6 9d ae e5 dd be aa f7 ef 4e 69 cb 68 bd fb 97 3f fc fe bf fd eb bf fd 37 51 e9 bb 6f 7f c3 ff bd fb fe b7 93 73 dd 9c d2 aa fc b9 98 65 6d cb 79 4e 66 cb c9 ff 16 15 f4 75 b2 5f a0 86 73 91 d5 55 da be 33 f1 24 c5 63 77 aa 26 ff f1 ed 6f be 39 d4 e7 6e 7a 48 4f 65 f5 e5 61 d2 a6 e7 76 da 16 4d 79 78 cf 8a a6 a7 76 da 15 9f bb 69 cb 70 a7 69 fe 97 6b db 3d 4c e6 49 f2 3b 51 fa a9 d8 ff 54 76 04 c4 b7 bf f9 3f bc 9a 7d 9d 7f 11 d5 9c d2 e6 a9 3c 3f 4c 92 be 20 6d ba 32 ab 8a 3b f6 57 5b e6 fc bf 79 d1 a5 65 d5 b2 bf 0e e5 53 96 5e ba b2 3e cb 1f d7 86 97 1f 98 a8 98 9c 19 eb 45 9a cb 3f 9e 9a fa 7a 61 7f 9c d2 92 83 9e 8a f3 95 fd e7 9c 7e 64 ff db 16 59 4f a1 bd 9e 58 ed 92 8d bc 6c 2f 55 ca 5a ca c4 9d fd a4 78 b9 e6 65 cd 00 b3 f4 fc 31 e5 0c 5c 9a fa a9 29 5a fe e7 47 c6 5c 6d a2 96 e7 aa 3c 17 53 41 81 0b e2 63 c1 db 92 56 53 26 e3 27 d6 c4 7d da 16 1c 02 52 7f 38 d7 dd eb 1f 33 26 eb a6 ae da 0f 6f 4c 8a e7 fa 5c 70 4a c7 82 2b d7 20 a4 1f 8f 65 9e 17 e7 0f 8c 8f ae 38 31 d8 ae 70 11 55 35 a2 64 9f 66 3f 71 a9 9c f3 29 eb fb ba 79 98 30 e5 3a b7 97 b4 29 ce 9d 82 7c 48 99 68 3e 0a d9 3f 1c 6b c6 be 40 ad af 1d e7 1a 74 d1 7e df fc d8 95 5d 55 7c 90 b4 eb 86 c9 7d ba af bb ae 3e 0d 4c 8b fe cf 99 aa 35 29 17 f8 83 54 7b 4e ca d1 12 14 6a 92 33 82 45 2e 15 ae fe 39 0e 32 08 a4 f4 8f f7 3f 93 f9 f9 69 50 f6 4f bd 94 b7 89 6a 69 7e 38 0f c5 6d f7 a5 62 52 28 3b d6 9d 59 0f 70 9c 83 72 a6 ea 0f 93 45 71 7a 0f d4 7a b6 d9 16 27 2d 39 f6 f5 27 ab 3b 1e 26 df 1d 0e 09 47 e9 fb e5 bb 44 57 df b2 d1 59 d9 15 dc eb 31 d4 5e 45 2b ae 17 1b 64 bb 16 03 51 68 a3 56 1d fe e5 52 b7 a5 14 4b 53 30 a5 61 7d 1d a1 a7 aa 82 ae be 3c 4c a6 b3 75 71 1a ea ef fb 5f 76 fc 74 b6 18 0a cb d3 13 50 8e 41 79 da 8f 4f 42 e7 1f 1a 36 6c a5 ba 73 4d 3b 54 f5 a7 87 89 54 eb 1e 52 0e 70 c3 48 cc 99 2c 57 c9 e5 b3 92 be 54 50 a5 4a fb fa 33 17 40 79 7e 7a 98 f0 11 c5 34 9b 7f d3 0a e4 29 f7 14 d9 63 ef d2 f3 34 70 9d 5e bb ba 2f cc 6a 61 b2 7e da e7 c2 5a f0 bf db f4 74 71 0d ea a9 3e d7 6c f4 65 c5 dd f0 e7 7b b3 17 e7 5a 96 fb 2b 13 30 b7 58 e5 f9 72 ed d8 7f eb 4b a7 4c 1c eb 2a 66 d0 84 21 f
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 08 Jul 2022 17:12:52 GMTETag: "142d8-5e34e4ff58d00-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 14266Content-Type: text/cssData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 7d db 72 e3 c8 92 d8 f3 e8 2b e0 9e 18 9f ee 1e 91 83 0b c1 8b 14 3b 7b fc e0 88 f5 c3 fa d5 b1 5e 9f 38 01 02 a0 c4 6d 92 e0 90 50 b7 34 0c 7d 97 df fd 65 ae 7b 65 56 65 15 40 4d 1f fb ac 2d 69 5a 03 14 b2 b2 b2 ee 59 79 ab 75 d7 bc dc 26 cd f6 2b fb b3 63 ff 7a f6 af b9 4d 9e d8 73 c7 fe ed b6 b7 8f d9 6d f2 98 b3 7f 05 fb 37 63 ff 4a f6 6f 7e 9b 1c 4f ed 6d 52 77 4d 7b bb e9 4e fb db 64 b3 6d 77 cd b9 65 08 76 ed 43 7b 60 48 b6 87 e3 13 7b 5d 3f f5 7d 77 b8 ed db e7 be 3a b5 15 cb c9 d2 76 5d fd e5 b7 a7 ae 67 38 fa 47 f6 af 49 2e fb ea f4 b0 3d dc 25 e9 fd b1 6a 9a ed e1 81 3f be de 58 bc db fd 43 72 59 77 a7 a6 3d c9 4f 77 9b ae 7e 3a 27 97 ee a9 df 6d 0f ad 4c 64 79 4f ed f9 cc 68 ab 8e fd 96 15 9c d4 db 5e 93 9a 34 9b c3 6d bb 97 85 7e ad 4e ac 96 c7 fe e1 d4 3d 1d 93 cb a6 3b f4 93 73 ff b2 63 88 0e ac 4a d5 ee 5e 24 7d 6b b7 0f 8f bd 49 7b bd a1 5b e4 42 01 27 12 e9 f6 77 86 33 4b d3 9f 58 ee 73 7f ea 0e 0f 18 7a 91 0a ca d7 6b 46 50 55 b3 ef 2f 7b 58 53 01 cb a8 dd 56 07 48 07 6e df c4 34 f0 cd b9 dd b5 75 6f eb 26 9e 58 53 a8 3a 6e aa fd 76 f7 72 c7 fa e7 b1 3d 6d fb 7b 40 23 4e 92 6d a1 d3 7e 40 24 eb d4 d7 1b d9 b0 5f d6 ac c7 cf d5 9e 15 d6 f7 ba 31 61 bd 43 d4 26 92 da e4 f2 39 90 e7 5f fb 97 63 fb 0f 1f 58 a7 b6 fd 87 bf dc dd 4d f6 dd ef 13 d1 f3 93 ed e1 d0 9e 6e 11 98 c4 3f 0c 77 7e 5a ef b7 23 f0 6d b6 bb f6 c3 5f 92 5f 93 71 85 e8 5e 3b 74 87 d6 8c 63 de b9 7c 36 3d ed 92 cb 6e 7b 06 a3 8c 01 bd de f4 d5 7a d7 ea fe 9e d4 dd 6e 57 1d cf ec b3 7e ba 57 5f ce c7 aa 36 d3 42 8d ee 0b 6f c7 49 b5 db 3e b0 99 b3 6b 37 bc 43 ce bc c7 59 fd a8 5e b8 63 13 e5 cb 6d 72 f7 75 7b 66 b3 a2 49 f8 2c 65 33 48 60 69 da ba 3b 55 1c ab 21 0d ce d3 df 92 8b 78 3a 13 5f ef d6 2d 5b 05 5a 38 b1 ef aa 4d cf 1a 33 f9 cd 7c fb 4d 26 25 97 9a 91 d5 f2 a1 fc a7 3f dd 9b 67 85 73 5a ef da ea b4 d9 3e df 4e f9 a7 8a cd eb d3 64 b3 7b da 36 20 e1 76 ca d7 9c 89 1c dc d3 fd e3 6e c7 07 c7 25 f9 2c 32 df ad bb fe f1 3e f9 fc 7b d7 ed ef 32 88 53 d1 64 df 15 69 6e 51 06 ce 49 f6 c0 3d 40 03 62 09 d4 30 20 45 03 69 ca 35 88 79 97 00 17 b6 30 9f 8f bb ea e5 4e 0c 11 d3 56 1f 92 0f 64 ad 06 2a 41 10 e2 96 2b de 2f a0 15 59 31 8f db a6 69 0f 17 4d 0a ef a7 ff b0 dd 1f bb 53 cf 96 23 0e 70 7e ec be 99 cf 62 00 e0 ef 0c 41 8b b2 f3 c4 e3 d3 6e 37 e1 03 f6 56 3e 9e f8 b2 62 a0 b6 07 be a0 23 b8 cb 66 d7 55 fd 9d 1a e3 30 93 fc 20 9e f9 a0 94 0b 8c 5c 6e cc 2a a3 96 c4 23 6f 54 b4 08 7e f8 e7 2d 5b 70 cf dd a6 4f fe a5 7a 6c b7 1f 6e 93 0f ff d4 ee be b6 fd b6 ae 92 ff da 3e b5 2c c5 24 dc 26 ff 89 ad c2 3b be d2 1d ce 93 33 5b 01 37 f7 c9 eb 8d 40 fb ed 91 cd 28 31 49 ed 06 c2 be dd 7c be bd f9 ac 7b 9c 3d a9 39 70 93 b
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Sat, 21 May 2022 15:56:31 GMTETag: "abb-5df87a68709c0-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 1013Content-Type: text/cssData Raw: 1f 8b 08 00 00 00 00 00 00 03 8d 56 4d 8f dc 34 18 be cf af b0 16 21 ed 56 f5 d4 99 61 a6 dd e4 52 89 9f d0 13 27 e4 24 ce 8c d9 c4 8e 1c 4f 67 b6 ab b9 c1 09 c4 0a b5 08 09 84 84 38 71 a2 e5 02 65 69 f9 35 4d cb 9e f8 0b f8 2b 89 93 cd 74 49 56 2b c7 7e f3 7e 3c ef f3 bc 93 87 05 49 29 06 55 22 08 61 00 b3 14 1c 17 78 07 b7 34 95 eb 10 3c 58 a0 72 77 32 b9 00 25 4e 53 ca 56 21 40 11 28 b0 58 51 66 96 fb c9 14 17 b0 5a 63 41 02 70 31 01 ea ca 38 93 b0 a2 4f 48 08 82 59 b9 8b cc a6 24 3b 09 71 4e 57 ea b5 84 30 49 84 dd 87 5b 12 9f 51 09 a5 c0 ac ca b8 28 42 60 96 39 96 e4 93 e3 00 a1 0f 4f 9c 61 51 dd 6e 74 bb 17 3f 1c 95 94 b3 f0 46 06 60 8e 50 51 79 0e ad 1d 18 18 00 6b e1 70 d2 31 ec c6 13 48 59 4a 76 e1 0c a9 cb 6e c5 38 39 5b 09 be 61 29 4c 78 ce 45 08 3e c8 cc 65 8f 1d b4 50 f2 52 3b 6a 20 8b b9 48 89 80 02 a7 74 53 69 b0 dd ae 94 bc 30 8f 16 fb 82 a7 38 87 38 91 f4 31 01 17 07 20 d0 4d 8c 6e 43 1b 29 93 c3 30 eb d3 43 27 c0 4f 85 6f a4 ca a3 81 01 04 01 3a 8d fe 57 9f 6f ed f1 fb fa db 63 22 94 54 e6 c4 f1 b1 e2 39 4d 0d e2 3d 5c 15 da 30 27 99 6c 01 9e 0d 80 d7 06 82 ae d6 23 16 4d 17 51 70 1a a3 fb 51 47 fb 2d d1 2f 84 e0 a3 a6 f5 ad 54 bc c6 1e d2 82 2f 9c 07 da f8 66 49 61 88 33 65 af f0 75 49 36 74 08 ca 5d 53 68 9a e9 3b 52 49 2a d7 4c 25 73 74 14 81 94 56 65 8e cf 43 10 e7 3c 39 8b c0 da 25 da aa d9 63 5f 8f d3 7d 5c 33 ce 4d f8 5e 6d 5d 65 dd 90 30 9b de c9 67 9b 4a d2 ec 1c b6 49 55 25 4e 08 8c 89 dc aa b1 33 28 d5 45 99 9a c7 4f 63 c9 5c c0 31 f1 0c 0a f3 35 39 6f 24 39 aa bf 45 70 7a df ef 77 0f 43 b2 d4 f7 a8 0e 17 2d 09 36 a2 d2 be 4a 4e c7 7b d8 d2 65 9c 1a 39 65 04 36 7d 08 a6 b3 21 84 d3 e5 6c 41 8a 46 f7 87 48 e3 4f a8 61 9d 6e 50 11 5c 11 a3 4a 54 dd 6d aa 39 70 6e 7d 3e 26 42 d2 44 4f 15 1b af a0 69 9a 13 87 ed 9a 4a 02 4d f7 42 c0 f8 56 e0 32 32 f5 65 b8 a0 f9 79 78 54 ff fd eb 3f af 9f 5f ff f0 c5 f5 5f df 1c 99 c6 ca 4d 4c 31 77 3d 1c 9f 85 e3 13 4f dd 0a c3 4e 76 0e 2c bc 91 dc cd 5a ae b8 1f d8 35 57 59 67 39 df ba e3 fd 04 87 6b bd 77 31 69 e2 e0 19 da 4f da 74 72 aa 54 e4 b8 df aa c8 d0 7f a8 15 e5 15 ab 16 e9 61 d1 09 c7 44 69 a9 36 73 4a 71 be b1 72 dd 44 9d cf e7 37 5d 9a 6e a6 24 e1 02 9b d6 31 ce 88 ef 40 e1 ab 48 7f e3 b5 ce 80 16 2b 75 de 08 75 a6 c7 45 9b 9a 7b 1c a0 69 6b db fb f5 6b 04 bc 7e 94 bc 21 92 25 18 58 e8 aa 3c 03 41 4a a2 91 60 dc 2d 7b a7 96 f5 f3 a5 ea 98 fe 17 8d b5 3a 49 92 c8 97 b1 87 0c 65 46 10 0d e6 83 59 d8 16 67 5d f7 b4 63 b7 06 ad 5c 78 83 cc 1a 74 a5 db c1 02 a9 1a 46 5a 96 31 ef e3 40 0b bc 52 71 37 22 3f 3e 31 af 19 f3 78 d5 b7 72 55 88 55 8c 8f d1 5d e0 fe a6 cb 93 c8 fb 8d ee 7a 62 66 a9 a6 90 d9 e6 4a 3f 54 9e 9b 75 07 7b 46 77 24 8d 80 68 47 b3 99 c9 68 30 90 fd 5f 5
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 10 Dec 2021 11:25:34 GMTETag: "d35-5d2c8fb3e2780-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 1298Content-Type: application/javascriptData Raw: 1f 8b 08 00 00 00 00 00 00 03 ad 56 5b 73 d3 38 14 7e df 5f e1 f8 a1 48 44 51 92 5d 96 65 1d 4c 27 2d 65 17 b6 14 7a 63 b8 0c d3 91 e5 63 5b a9 6b 7b 7c 69 68 9b fc f7 3d b2 e3 c4 4e 68 e8 0e cb 30 a9 75 74 f4 e9 3b 77 f5 1f 77 8c 43 71 7b 63 1c c6 c2 35 86 fc 4f 3e 34 7a c6 db d7 67 46 a8 24 44 19 e0 6a 3f 4e 6e 52 e5 07 b9 f1 eb 60 38 e8 e1 cf 6f c6 5b 75 29 8c b3 a2 48 e2 50 18 8f fb bf 74 bc 22 92 b9 8a 23 22 98 c3 24 73 e9 dd b5 48 0d b0 05 71 e8 48 70 2f e2 21 5e 13 e2 2d f6 52 d5 a3 77 f5 b7 e1 93 ea 84 63 0f 46 8a 83 90 01 59 ea 55 3b 12 b1 f2 40 65 74 a4 3c d2 99 f0 ec 52 25 17 2a ba 56 99 72 42 98 cd 24 57 19 31 ad c5 da a4 14 d5 04 17 4e 7c 0d 79 00 79 9c 94 a7 d9 84 ce 66 82 87 e0 e5 b1 e7 80 af a2 5a 4c 47 10 a2 bd e5 29 07 c2 78 8a a7 bc 38 74 9b c7 4a 37 c4 5e 53 4c ef f0 44 b7 eb bc 98 70 4f a8 b0 48 e1 22 54 57 2a a7 29 e4 45 1a 75 86 f3 12 56 f2 1c 0f fb 90 12 53 24 09 88 d4 a4 0c 6d 9d d3 b9 b6 2d 60 ca ae f0 ec bb 3c 48 21 0b f0 06 6b c0 5a 88 b8 86 6b 88 72 cb cc 64 1a 87 a1 c9 c0 f3 40 ea 75 10 4f 4d 26 e3 28 17 2a 82 d4 72 98 2b 72 71 21 72 bc d3 29 72 b0 cc 18 2f 57 91 c0 33 6d b7 59 9d 01 ab f8 58 51 11 86 4c 07 a8 fa 4a 42 21 41 d3 40 3c 53 c3 59 ea 4a f8 d0 4f 22 7f e4 88 0c 9e 3e 61 ea c3 de bb 93 e9 e0 9f bf fc 78 8c ff 8e 4e cf 83 83 73 5f 7f 1e e8 9f bd fd f1 27 fd d7 7b 25 4f df e8 8f f1 c7 a3 d3 93 c1 eb 71 9a 3d 91 4f 8f b5 e0 24 3a 3e 1f ee 8d c7 fb df 26 d3 eb 67 9f 8e cf b5 f0 8d 3c 08 3e cb e9 78 fc 32 d3 4a 7f 1c 8c 3f 9f a7 2f 83 6c 71 c7 c9 de 87 bd e0 e3 a7 db e0 59 f7 fd 5e 1f e1 bd f1 20 3a 7a 5f ec 1f 96 77 1c 84 af ce 2e 4f 8b e3 ab fd 7d 73 3e aa 82 60 78 3b 3b c4 ed d8 b6 57 c7 a8 74 28 0a bd 76 d0 d6 14 98 0b 21 e4 60 b4 a5 94 55 50 95 f7 b3 04 c0 2d 91 aa f5 45 29 68 6f af 70 1a 42 ca 04 87 6f 39 44 2e 99 30 8f 52 16 d8 13 be 8c a1 6d db ee 6c d6 16 38 bb 60 09 d2 90 51 36 40 f1 84 97 69 c1 55 e4 c2 b7 77 1e a9 d3 83 ee ec 04 dc 51 1a bf d2 60 8d 8a 5a 38 06 cb 6e 4e 99 4e bd ef d6 9c 53 65 a5 ac ca d8 e1 3a 3d d0 b8 ce 90 11 c9 75 7a e1 65 a9 34 69 c5 76 5d d4 19 22 85 aa 2c d5 95 6f 96 8b 95 06 9b f0 46 8e 51 26 79 1c c1 b2 3a 9a 5c 75 bd 97 14 ab eb 4b c1 84 57 8a 15 4f d7 56 58 d2 91 9f 07 a3 7a 83 4b 11 86 04 2b 01 6b 74 2e 88 f9 1c 29 18 fd 17 26 ad 5c 62 6a ac d6 2d 15 4e cd 50 67 7c cf ec 4e 78 bb 92 e8 48 f2 40 b9 40 34 df a5 61 bb 2d bb 5c 6a 49 2e 33 dc 74 84 bc f4 d3 b8 88 dc 5e 59 3c 26 33 8b 34 24 8f cc ae db 35 1f 51 6c 01 f2 cb 64 91 13 5f c9 a4 95 41 d8 1e 96 ee 1e 8c 16 cd 94 fb 29 24 44 ad 68 8b 3a 92 1d b1 d0 9e 97 fd 51 61 c4 80 a2 8b b5 b0 b2 cd 6b fa 48 8b 6b 0f 79 da 43 73 da 34 e1 47 5e d0 fa 6c d0 d9 9a 7b f2 de dc ab 0d d3 19 b3 d1 15 e7 3a 21 61 11
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 08 Jul 2022 12:34:02 GMTETag: "17b8a-5e34a6ac60280-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 33758Content-Type: application/javascriptData Raw: 1f 8b 08 00 00 00 00 00 00 03 dd bd 6b 7b 1b c7 b1 2e fa 7d fd 0a 62 a2 45 cf 08 4d 90 94 ed ec 64 a0 21 8e 2c c9 b1 12 db b2 2d 39 b6 17 08 fb 99 1b 80 21 71 23 00 8a 94 09 e4 b7 9f 7a ab ba 7b 7a 2e 90 9c b5 f6 3e cf 7e 8e 13 11 73 e9 e9 7b 57 57 55 57 bd 75 fa b8 73 74 f5 fd 6d be 7e 7f f4 ee bc 77 fe a4 f7 d9 d1 ee c8 4f 03 f3 f0 cb e5 ed 22 8b b7 c5 72 41 cf af 6e f0 ac b7 5c 4f 4e 67 45 9a 2f 36 f9 d1 e3 d3 ff e8 8c 6f 17 29 52 f8 b1 4a 82 07 6f 99 5c e5 e9 d6 8b a2 ed fb 55 be 1c 1f cd 97 d9 ed 2c 3f 3e 3e f0 a2 97 df af 96 eb ed 66 50 bd 8d e2 5e b6 4c 6f e7 f9 62 3b 48 28 e7 ce 59 10 96 05 05 0f c5 d8 ef 94 49 82 ed 74 bd bc 3b 5a e4 77 47 2f d7 eb e5 da f7 74 fd d7 f9 cd 6d b1 ce 37 47 f1 d1 5d b1 c8 28 cd 5d b1 9d d2 9d f9 d2 0b fa eb 7c 7b bb 5e 1c 51 29 c1 3e e4 bf be 47 ad ce c7 c5 22 cf bc 8e a9 ae 7c 3f 90 9f 70 3b 2d 36 aa da f2 77 f1 fa 28 8d 86 23 95 39 95 57 79 94 f6 36 e8 2e 35 a6 ab 74 b9 48 e3 ad 9a d0 e5 ea 76 33 55 53 ba a0 0c f3 fb d7 63 55 44 0f 7b 75 15 15 bd ed f2 cd 76 5d 2c 26 ea 9a 6e a6 f1 e6 f5 dd e2 bb f5 72 95 af b7 ef d5 0c 89 e6 91 27 83 e5 a9 45 54 ad 84 6e 0c 7a 62 d1 1b 2f 28 f3 62 cb 6f f6 6a 19 9d fe 3a bc dc 5c de 7e f9 f2 cb 2f 2f ef 9f 9d 8d ba bb da fd a3 d3 89 5a 51 b2 93 f9 e6 e4 54 dd 44 a7 27 fe f0 32 8b 4f 7e 1f 05 a7 93 42 ad db 0b 4b a8 c6 3f ae a8 7e cf e3 4d ee 07 fb 3e 4a 8e 16 bd d5 7a b9 5d a2 f7 a2 07 99 3a e1 5c 51 07 6c b6 eb db 74 bb 5c 87 0b b5 c9 67 39 5f 7a 9e 9a e5 8b c9 76 1a 9e a9 ed f2 d9 7a 1d bf 2f 87 db 16 94 f7 d2 78 36 f3 d1 f7 d4 9e 49 be ad 4c 09 d3 f4 db d9 ac 13 c5 83 b3 8b 78 80 94 c3 b8 8b 9f 9e e4 3f 0a e5 d9 28 ac 66 86 d1 78 b3 8d d3 eb 4a 96 18 d2 84 5a 32 cf d7 93 9c 93 f6 9c 06 f8 81 8a cb e9 43 cd cd df bd e6 39 1e f1 ec 48 90 76 9b df cb ad b9 51 c9 5e e5 71 3a 6d ad 7a 0f 6f b8 1c ca 99 c6 39 5e b5 25 e3 ec 6c 85 7d aa 5e bc f2 ab 13 32 51 a9 4d 1e 4b 43 e9 11 a6 41 40 f9 f2 7c 6c e9 df 5a c6 79 2f 5e ad 66 ef 75 7d d6 13 9e d0 1b 64 30 2e d6 9b ed a1 0c f2 1b ff 8c d2 cc e2 0f 26 39 39 a7 34 f9 4d 4b 77 3b a3 a5 d2 a8 1b 77 7d 0c 65 12 9e d9 be ae d5 33 bd 88 ce 8e 8f 93 8b 74 30 e4 c1 4d 47 a3 70 38 42 f6 8b ec 60 2b ed 60 ed 76 cd 71 95 f9 10 4e d4 86 68 51 48 0b 98 7e d4 66 c5 dd 46 77 7c b1 57 34 5c f7 5b 2a 23 e2 95 a6 af 9d f2 d0 1c 5a 27 d4 ef 99 a2 e5 4f ab de 76 e2 f0 6c b4 db d1 4a 9e 46 e7 b4 ee ed 63 d3 ec ab a8 73 de 1f 83 8e 25 cb e5 2c 8f 17 25 d5 9c 1c 1f fb 57 d1 a4 92 d9 54 67 d6 ed 06 aa 41 66 27 bb 1d 91 81 cd 97 a6 5e 93 60 b7 f3 27 44 46 02 2a 3d 8a 0a ca 6f 22 13 76 7a 72 12 f4 8b 8b 69 1f 19 11 81 95 95 e4 e7 95 92 82 00 f5 ca 8e 0a 5a 8e 41 1c 4d 86 d9 88 46 29 c7 cf a4 13 45 29 aa 77 7c 8c 1f 94 fa dd 2c 2e
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:45 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Mon, 10 Oct 2022 04:35:49 GMTETag: "95a5-5eaa6b19ed340-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 9186Content-Type: application/javascriptData Raw: 1f 8b 08 00 00 00 00 00 00 03 dd 3d 6b 97 d4 c6 95 df fd 2b 84 d2 8b ba 69 d1 af 79 80 67 a6 87 c5 83 b1 49 20 26 3c 1c ef 62 cc d1 a8 d5 dd 02 75 ab 23 a9 e7 61 98 73 c0 89 6d e2 c7 da d9 25 71 9c e0 b5 c9 b1 13 92 ac c1 9b 64 6d 62 20 fe 31 4b f7 0c 9f fc 17 f6 de aa d2 ab 54 52 6b 06 6c 9f b3 3a 30 dd 5d 55 f7 d6 ad 5b b7 6e dd 7b eb a1 27 4e 7a 8e d9 ef 54 06 8e ed d9 de fa c0 a8 38 c6 c0 d2 74 e3 a0 65 49 52 53 6a 0f fb ba 67 da fd a2 5b 57 dd 46 e9 a2 e4 18 de d0 e9 4b 5e d7 74 fd a2 c5 be b1 2a 9d 30 3a 4f af 0d b0 98 dc e9 c9 25 2c 3c 2f 6d 3c 91 40 0f bf 7b cd 00 6b 0a c2 6a f1 a5 17 dd 3d a5 4b 45 f8 5b 28 55 3b aa 24 cb 04 dd 8a e6 48 cb 9a 6b cc 4e 3f dd d7 ed 96 b1 d4 d5 1c b7 29 1f 7c 6a e9 d0 d3 87 9f 79 f6 c8 f7 7f 70 f4 d8 0f 9f 3b fe a3 13 27 4f 9d 7e fe c7 2f fc cb bf 6a cb 7a cb 68 77 ba e6 f9 0b 56 af 6f 0f 7e e2 b8 de 70 65 75 6d fd e5 5a bd 31 35 3d 33 bb 6f ff 93 e5 aa 3c 1f 22 3e 64 84 88 b1 61 07 1d 47 5b 2f ee ad ab df ed bf d9 46 e4 fb 94 3a d3 50 67 e0 ef b4 3a 33 a3 ce cc aa 33 fb d4 99 fd ea cc 93 ea 6c 4d 9d 4d c1 50 53 eb 6a 43 9d 52 01 46 9d 55 f7 a9 fb d5 27 d5 3a 24 d6 d5 7a 43 ad 4f a9 f5 69 b5 3e a3 d6 67 d5 fa 3e b5 be 5f ad 3f a9 36 6a 6a 03 60 1a 6a 63 4a 6d 4c ab 8d 19 01 d6 c6 ac da d8 a7 36 f6 ab 8d 27 d5 a9 9a 3a 55 57 a7 a0 92 29 75 6a 5a 9d 9a 51 a7 66 d5 a9 7d ea d4 7e 75 ea 49 75 ba a6 4e d7 d5 e9 86 3a 0d 34 4c ab d3 33 ea f4 ac 3a bd 4f 9d de af 4e 3f a9 ce d4 d4 19 1e 79 69 de 17 14 d6 37 06 e9 f4 a2 eb 39 a5 8b d8 63 f6 d0 53 4d d5 32 fa a4 ff f4 ba aa 37 54 7d 6a 1e 12 9a 50 a6 02 9f 1d af 3b 6f 36 6b f3 50 b2 29 cb f3 ab 5d d3 32 8a e6 02 e4 94 2e ea 75 52 4a 87 ae 5e 02 b4 07 bd a2 59 2e 97 76 d7 d6 da ed 79 b3 5d 34 9b 4d 52 0c 40 cb cd 84 d0 11 30 00 d1 eb 8b 8b 20 ea d9 85 a0 14 a0 9d 2a 2d 2c 4c b3 a2 72 b3 29 cf 2f 3b 86 76 61 43 6f 88 c8 78 dc 14 44 49 b8 04 bf 1a f0 eb 70 ad b4 b8 38 5d 9a 4c 3d 29 0c a0 8d 80 fa 80 f8 29 21 f1 df 35 c5 51 92 11 76 0a 7e 2d 21 ec ec 44 58 52 76 ea 70 69 83 29 26 28 bd c1 89 61 cb 88 8b a1 2f 78 aa 3e 4d 04 91 88 a4 0a 80 79 25 b1 65 a3 30 26 f4 cf 99 34 f1 3c bb 11 01 df bd 1b 60 9b 38 5a 40 64 d8 57 d2 39 f3 88 b6 f1 08 68 1b 21 da 46 04 2d e1 1f 53 ec 6d c7 ee 2d 31 54 d8 63 3e c3 91 fd 53 7e 67 21 1d 42 39 09 c6 1a 64 37 67 eb a5 90 e5 f3 90 92 24 5c 9f e2 49 9c 0a 49 9c ca 45 22 21 ed 85 c3 81 54 91 de 5e 2a a1 40 52 42 a7 b3 09 9d 4e 10 3a 2d 22 74 9a 27 74 3a 24 74 3a 27 a1 48 5a 0d e5 7f b6 74 49 9f 16 0b e4 d0 6b d7 67 3d 7b bf 40 27 aa ba 2f 6b 9c 14 b6 6d a7 88 92 48 48 9b c7 e6 5d d4 13 8d 26 a4 16 f5 c5 26 d0 50 ab d5 4b bb 77 17 f5 05 f2 63 df e1 12 53 49 3e 0c 29 bf 61 58 ae 21 61 fb 16 a1 d4 be c3 87 59 21 51 e3 6
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:46 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 10 Dec 2021 11:26:38 GMTETag: "1fa-5d2c8ff0eb780-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 316Content-Type: image/svg+xmlData Raw: 1f 8b 08 00 00 00 00 00 00 03 5d 51 4d 6f 83 30 0c bd ef 57 44 de 65 3b 40 48 e9 18 9d 9a 1e b6 f3 76 da 1f c8 c0 85 68 90 a0 60 4a fb ef 67 28 4c 55 a3 48 fe c8 7b ce b3 bd ef 4f 95 18 6d 49 b5 86 4d 92 80 a8 d1 56 35 2d c1 c9 e2 f8 ee cf 1a 12 11 6d 95 48 73 a1 36 9c 3e b7 8d eb 35 d4 44 dd 9b 94 e3 38 c6 63 1a fb 50 49 26 25 92 2b 82 e8 29 f8 5f d4 f0 f8 82 d9 6b 9e c2 e1 41 f0 d9 57 e2 68 9b 46 83 f3 0e 61 f6 a3 30 34 8c c3 13 3a 5f 96 0b 6e c1 52 30 ae 3f fa d0 6a 98 dd c6 10 3e 29 a1 9e d7 fa d1 aa fc 86 37 73 0b 1b 8a 06 57 94 ef 4c 61 e9 a2 21 7e 01 51 70 3b 2a 67 7b b9 da 30 1b 79 57 a0 33 54 8b 52 c3 67 9a 09 95 17 49 b4 8b 77 db 28 8f 93 2c 52 f9 f5 de fd 39 d3 8c b3 2d 8b fc 5e 85 0b 43 14 ec cf 40 f8 65 5a 5c da 98 1e 40 d0 a5 e3 44 f0 c4 78 1e 45 f0 ed 34 66 c5 23 66 51 e4 35 a4 d9 7f 58 0e 93 ca 9e c5 62 87 86 3e fc e0 78 45 d6 95 78 b4 ce 32 ff 5e be 9c f4 df cc 52 56 cb 02 26 67 3f ad e8 f0 07 87 8a 98 e7 fa 01 00 00 Data Ascii: ]QMo0WDe;@Hvh`Jg(LUH{OmIMV5-mHs6>5D8cPI&%+)_kAWhFa04:_nR0?j>)7sWLa!~Qp;*g{0yW3TRgIw(,R9-^C@eZ\@DxE4f#fQ5Xb>xEx2^RV&g?
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 10 Nov 2022 16:07:51 GMTServer: ApacheUpgrade: h2Connection: Upgrade, closeLast-Modified: Fri, 08 Jul 2022 16:35:17 GMTETag: "25be-5e34dc98cfb40-gzip"Accept-Ranges: bytesVary: Accept-EncodingContent-Encoding: gzipContent-Length: 6727Content-Type: image/x-iconData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 9a 67 54 55 e7 d6 ef 7d c7 1d 77 dc 33 ce 38 39 27 51 63 6f 28 45 2c 60 ef 25 26 1a 4f 4c 8c d1 c4 a8 b1 c7 c4 de 35 62 6f 88 05 04 29 4a 93 22 45 05 14 01 41 50 50 04 15 3b 76 c5 82 0a 8a a2 d2 cb de ec fe bb 73 ad 8d 79 1d 49 de f3 f1 7e ba 1b 27 6b b3 ca f3 fc 67 fb cf f9 3c cb 06 0d fe 4b 7e ba 75 6b 20 bf db 35 88 b1 6b d0 a0 49 83 06 0d 3a 8a c8 a9 06 33 1a 58 cf ab 1f db 06 7f fa a0 07 74 60 16 a9 d4 40 71 0d bc ac 83 77 26 a8 90 4b 46 f5 86 77 22 85 22 45 22 2f 45 5e 88 14 88 bc 16 29 47 bd d3 2c 0f 62 00 93 f5 a0 8c 69 ac 95 63 dd fb bf 2d 22 d5 f2 a5 b2 7e 3c 19 cb f2 54 8e 65 f2 ac 32 e6 73 91 27 22 8f ac d7 2d 26 cc 95 d6 e7 8d 02 41 67 32 cb 30 75 e8 4d 65 98 0c 32 9f 45 c6 ab b3 58 c7 17 b1 88 e8 64 9e 0a 91 12 b9 bf 4c a4 d6 64 c4 68 2a b5 8e 67 ca e3 ce d9 bd ec df 36 01 b7 45 5f b0 65 fe 70 d6 cf 1b 8e ef d6 a9 9c 4b f6 a5 ba f8 8a 8c 23 3a 6a df 88 c8 c4 7a bd 3a a0 b1 4c f4 d3 c8 7c 35 af 29 ba 77 86 c4 d0 f5 6c 5a fc 05 2e b3 7a b2 69 e1 50 16 4d 1a 40 d4 9e a5 72 df 99 7a ec f7 e5 b9 87 18 4b df a2 98 4e 27 8f ea eb ac 26 b0 da 52 8c 6c ae b6 e2 d7 9a ad 86 32 69 e5 9c 7c 97 53 06 45 25 b1 a1 b6 ae 06 b3 a1 44 ae bf 12 85 ce 71 33 69 33 de 8b 7a b3 ec eb 4f 70 f9 ae 39 1b 26 d8 b0 72 6c 73 96 8d 6f cc 92 89 8d 59 34 a1 09 5b 16 74 e7 6c ec 6f 50 75 be de 9e e2 23 f3 5d 72 e2 37 b1 7a 46 17 e6 7c d3 08 97 a9 2d d9 f2 6b 1b d6 cd 6c cc ca 9f 1a 33 67 74 5b 96 4e 70 66 c7 8a 41 98 cb 8e 0b 96 2b aa 6f 6a 5f 3c f9 6f 3f 1a ac 98 c4 1a d4 18 ca a8 28 17 df d5 d5 61 ae 50 7c ae f8 b4 d6 7a a3 5c 57 02 c0 64 90 73 ba b7 56 bf 1a ee 71 35 d6 05 b7 29 6d 58 3b ea 6f 78 4f 6f 4e e8 7c 5b 82 7e 6d 8f f7 ac 16 78 cc 6e 88 c7 dc 86 b8 ce fc 88 cd 53 3f c2 7d 6e 2b 02 5d 9c f0 5b d6 19 d7 19 ad 70 9b d5 9a 4d 53 1a c9 b5 46 b8 cf 6e 26 f7 37 66 db f4 bf b3 e3 e7 bf e1 39 b7 09 fe cb fa e2 32 a1 3d 2b 44 ff a0 2d 43 79 7c c1 5d 82 e0 82 15 97 12 10 f2 cf 28 b0 aa 74 46 34 a6 3a ea 14 db 2b 7e 10 fb 5b 6a b4 f5 f8 df eb 20 be b1 88 4e 66 f1 b9 a5 58 b5 df fd 94 ed 44 ad 19 82 db b8 7f 10 24 36 3b ba cc 86 b0 5f 1a e2 37 f1 6f 04 4c ff 88 03 8b 1b 13 be f4 53 c2 16 37 21 60 ce bf d8 39 e9 7f e1 fa 43 03 bc a6 fd 43 ce b5 c2 7b c6 3f f1 9b f5 09 fb 44 4f 45 02 67 37 22 78 5e 23 02 66 7f 8c cf cc 7f b1 7d e2 27 c4 6e 1a c0 c6 9f fe 81 fb 7c f1 cb b4 96 14 5e f6 97 b9 c5 f7 b5 e5 98 35 26 89 61 6b 98 6b c5 b6 46 d5 c6 a2 4b 45 25 a7 93 53 e5 bc 46 b4 a9 13 35 75 72 55 63 d5 81 2a c1 2f b6 af ba ca 81 d5 c3 05 87 13 d1 0b da 91 b8 b2 1d 27 5c 5a 93 b0 b4 31 09 cb 3f 25 75 5d 1b 12 56 b5 24 72 c1 c7 44 2f 6a 48 da 66 3b ce 79 74 e3 d4 36 47 92 d6 b6 25 7e 75 6b c2 e6 fd 53 8e 6d 38 b1 a9 23 f1 2e ed e4
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: njanow.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/css/bootstrap.min.css HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/css/common.css HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/css/hmlcss.css HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/css/app.css HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/js/jquery.min.js HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/js/jquery.lazyload.min.js HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /static/js/home.js HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/image/loading.svg HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /21467675.js HTTP/1.1Host: js.users.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js-sdk-pro.min.js HTTP/1.1Host: sdk.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/image/video-play.png HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://njanow.com/template/web/css/hmlcss.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /Template/88888.png HTTP/1.1Host: nyc517.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /21467675.js HTTP/1.1Host: js.users.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /go1?id=21467675&rt=1668096467628&rl=1280*1024&lang=en-US&ct=unknow&pf=1&ins=1&vd=1&ce=1&cd=24&ds=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A&ing=1&ekc=&sid=1668096467628&tt=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E4%25B9%2585%25E4%25B9%2585%25E4%25B8%2580%25E7%25BA%25BF%25E4%25B8%258D%25E5%258D%25A1&kw=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E4%25B9%2585%25E4%25B9%2585%25E4%25B8%2580%25E7%25BA%25BF%25E4%25B8%258D%25E5%258D%25A1%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E7%25B2%25BE%25E5%2593%2581%25E5%258D%2588%25E5%25A4%259C%25E4%25B8%2580%25E5%258C%25BA%25E4%25BA%258C%25E5%258C%25BA%25E7%25A6%258F%25E5%2588%25A9%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E6%2597%25A0%25E7%25A0%2581%25E4%25B8%2593%25E5%258C%25BA%25E4%25B9%2585%25E4%25B9%2585%25EF%25BC%258C%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E9%2585%2592%25E5%25BA%2597%25E4%25B8%2580%25E5%258C%25BA%25E4%25BA%258C%25E5%258C%25BA%25EF%25BC%258C%25E4%25B8%2580%25E6%259C%25AC%25E7%25BB%25BC%25E5%2590%2588%25E4%25B9%259D%25E4%25B9%259D%25E5%259B%25BD%25E4%25BA%25A7%25E4%25BA%258C%25E5%258C%25BA&cu=http%253A%252F%252Fnjanow.com%252F&pu= HTTP/1.1Host: ia.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /template/web/image/favicon.ico HTTP/1.1Host: njanow.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: __vtins__JTOT3DIsInljibcD=%7B%22sid%22%3A%20%223d85983c-0412-59ac-8c44-db4e2131fc4d%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201668098266881%2C%20%22ct%22%3A%201668096466881%7D; __51uvsct__JTOT3DIsInljibcD=1; __51vcke__JTOT3DIsInljibcD=4e715fd6-3383-5359-8972-61638c677659; __51vuft__JTOT3DIsInljibcD=1668096466887; __tins__21467675=%7B%22sid%22%3A%201668096467628%2C%20%22vd%22%3A%201%2C%20%22expires%22%3A%201668098267628%7D; __51cke__=; __51laig__=1; Hm_lvt_f498742086015f4bea2ad896b142a079=1668096470; Hm_lpvt_f498742086015f4bea2ad896b142a079=1668096470
Source: global trafficHTTP traffic detected: GET /Template/88888.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: nyc517.com
Source: global trafficHTTP traffic detected: GET /template/web/image/loading.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: njanow.com
Source: global trafficHTTP traffic detected: GET /template/web/image/favicon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: njanow.com
Source: unknownHTTP traffic detected: POST /v6/collect?dt=4 HTTP/1.1Host: collect-v6.51.laConnection: keep-aliveContent-Length: 423User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Origin: http://njanow.comReferer: http://njanow.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Data Raw: 1f 8b 08 00 d2 21 6d 63 00 03 c5 92 cd 4a c3 40 14 85 5f 45 b2 14 c7 66 32 93 64 e2 4e 70 a3 1b 17 ea 03 d4 49 eb 5f 8d 62 1b 5d 88 60 17 d5 0a 2d fe 74 51 b0 15 aa 88 45 50 0a a5 48 9a b6 fa 32 99 a6 5d f9 0a e6 26 55 8a e8 52 84 21 b9 9c fb e5 cc cd e5 1c 4a 1b a6 34 33 21 2d 2c 2f 2e 93 b9 f9 f4 bc 95 da dc 58 e5 73 d2 d4 84 b4 97 09 3a 58 d3 98 6c 68 34 78 31 1c 88 19 10 25 91 2b 0e 5a ed 59 df ad f7 1b 15 ff ec b4 5f ae f9 b5 6c a4 0e ea 27 c3 bb 4b ac c8 83 5e c3 eb bc bc 77 0b 5e 3b f7 db 19 3a cf 00 b8 d7 fd 56 53 54 7a 9e 5b f7 9b af a2 94 1d 01 ce b1 ef be 79 4e 51 14 6f 61 a2 ad 83 7f ba fc cb 27 02 44 31 2f ee ab 01 20 0a ae e7 16 82 a7 ff 70 2e f2 8f 3f ba 45 e3 79 4e 09 e0 d0 24 c0 c6 81 61 ee 4a b8 e5 71 37 f0 71 8e fb d5 27 bf d3 15 17 79 af 7d 13 9c e8 93 08 80 65 98 e9 bf 59 06 78 a7 a3 54 10 93 a9 06 23 1c c9 14 2b 48 35 e2 1c 31 4e 29 32 57 69 42 c1 04 27 39 35 01 e7 36 d0 eb 99 cc ee 4c 2c 66 6d c6 ad 9d 83 69 be b3 1d 83 de 6e d8 0b f3 94 82 0a 2b 4c 9e c4 b2 42 41 4a c5 ad 35 10 13 16 5a 59 0a 9d c2 78 d9 d6 56 60 11 0e b2 0f 83 40 f0 78 e2 b3 00 45 a1 d0 0c c3 28 c3 2e f6 46 85 bd 9f e6 23 ce 8e fe 81 26 74 ac 26 4d 0d 11 c2 08 52 89 6a 20 66 e8 0a d2 b0 46 18 d7 74 5d 53 0d b8 c9 4e 7e 8f bb 7e f4 01 0f 56 a2 fd 1e 03 00 00 Data Ascii: !mcJ@_Ef2dNpI_b]`-tQEPH2]&UR!J43!-,/.Xs:Xlh4x1%+ZY_l'K^w^;:VSTz[yNQoa'D1/ p.?EyN$aJq7q'y}eYxT#+H51N)2WiB'956L,fmin+LBAJ5ZYxV`@xE(.F#&t&MRj fFt]SN~~V
Source: unknownHTTPS traffic detected: 23.224.145.194:443 -> 192.168.2.3:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.83.25.141:443 -> 192.168.2.3:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.224.145.194:443 -> 192.168.2.3:49745 version: TLS 1.2
Source: classification engineClassification label: mal52.troj.win@33/0@38/239
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://njanow.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1892 --field-trial-handle=1856,i,17332521273761336343,7925953552888964040,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1892 --field-trial-handle=1856,i,17332521273761336343,7925953552888964040,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://njanow.com/0%VirustotalBrowse
http://njanow.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://njanow.com/template/web/css/bootstrap.min.css0%Avira URL Cloudsafe
http://njanow.com/template/web/css/common.css0%Avira URL Cloudsafe
http://njanow.com/template/web/css/hmlcss.css0%Avira URL Cloudsafe
http://nyc517.com/Template/88888.png0%Avira URL Cloudsafe
http://njanow.com/template/web/css/app.css0%Avira URL Cloudsafe
http://njanow.com/template/web/image/favicon.ico0%Avira URL Cloudsafe
http://njanow.com/template/web/image/loading.svg0%Avira URL Cloudsafe
http://njanow.com/template/web/image/video-play.png0%Avira URL Cloudsafe
http://njanow.com/template/web/js/jquery.lazyload.min.js0%Avira URL Cloudsafe
http://njanow.com/template/web/js/jquery.min.js0%Avira URL Cloudsafe
http://njanow.com/static/js/home.js0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
dzk.cdn.gfdun.icu
103.143.12.30
truefalse
    unknown
    accounts.google.com
    172.217.18.13
    truefalse
      high
      vd004-np-ze01.tgtest.site
      148.66.22.179
      truefalse
        unknown
        t.me
        149.154.167.99
        truefalse
          high
          gtm-cn-tl32u3a9801.gtm-a2b4.com
          23.224.145.195
          truefalse
            unknown
            d2cb5ad7002c4066.huaweisafedns.cn
            103.143.19.103
            truefalse
              unknown
              hm.e.shifen.com
              103.235.46.191
              truefalse
                unknown
                t2gaue5b.zx990.com
                103.93.127.81
                truefalse
                  unknown
                  6gxk45ey.n.223333.cn
                  103.145.191.124
                  truefalse
                    unknown
                    e428b87fea828a0a.huaweisafedns.cn
                    103.143.19.103
                    truefalse
                      unknown
                      vip.govhebie.com
                      23.225.63.114
                      truefalse
                        unknown
                        njanow.com
                        23.80.82.204
                        truefalse
                          unknown
                          usa.xatrt.com
                          154.13.4.63
                          truefalse
                            high
                            nyc517.com
                            23.80.10.82
                            truefalse
                              unknown
                              gtm-cn-7mz2w8y2a0b.gtm-a2b4.com
                              154.197.21.247
                              truefalse
                                unknown
                                www.google.com
                                142.250.186.164
                                truefalse
                                  high
                                  clients.l.google.com
                                  142.250.185.238
                                  truefalse
                                    high
                                    ads-6686.top
                                    123.253.107.70
                                    truefalse
                                      unknown
                                      f7e5541e3e16f351.huaweisafedns.cn
                                      103.143.19.103
                                      truefalse
                                        unknown
                                        sdk.51.la
                                        47.253.50.2
                                        truefalse
                                          high
                                          asheng.dl556677.com
                                          154.83.25.141
                                          truefalse
                                            unknown
                                            1b5e7de2ce344d8a.huaweisafedns.cn
                                            103.143.19.103
                                            truefalse
                                              unknown
                                              bj-gov-cn.website
                                              unknown
                                              unknownfalse
                                                unknown
                                                sm42t.com
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  collect-v6.51.la
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    ia.51.la
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      sm45k.com
                                                      unknown
                                                      unknownfalse
                                                        unknown
                                                        js.users.51.la
                                                        unknown
                                                        unknownfalse
                                                          high
                                                          zhibo128x2.xyz
                                                          unknown
                                                          unknowntrue
                                                            unknown
                                                            mt66g.com
                                                            unknown
                                                            unknownfalse
                                                              unknown
                                                              zb128e9.xyz
                                                              unknown
                                                              unknowntrue
                                                                unknown
                                                                www.51.la
                                                                unknown
                                                                unknownfalse
                                                                  high
                                                                  clients2.google.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    jquery.news
                                                                    unknown
                                                                    unknownfalse
                                                                      unknown
                                                                      gdydsdl23.com
                                                                      unknown
                                                                      unknownfalse
                                                                        unknown
                                                                        6686tg150.app
                                                                        unknown
                                                                        unknownfalse
                                                                          unknown
                                                                          oi58s3.com
                                                                          unknown
                                                                          unknownfalse
                                                                            unknown
                                                                            hm.baidu.com
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              NameMaliciousAntivirus DetectionReputation
                                                                              http://sdk.51.la/js-sdk-pro.min.jsfalse
                                                                                high
                                                                                http://njanow.com/template/web/css/hmlcss.cssfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                http://njanow.com/template/web/css/bootstrap.min.cssfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                http://js.users.51.la/21467675.jsfalse
                                                                                  high
                                                                                  http://njanow.com/false
                                                                                    unknown
                                                                                    http://njanow.com/template/web/css/common.cssfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://nyc517.com/Template/88888.pngfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://njanow.com/template/web/css/app.cssfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://njanow.com/template/web/image/favicon.icofalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://njanow.com/template/web/image/loading.svgfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://njanow.com/template/web/image/video-play.pngfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://njanow.com/template/web/js/jquery.lazyload.min.jsfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://collect-v6.51.la/v6/collect?dt=4false
                                                                                      high
                                                                                      http://ia.51.la/go1?id=21467675&rt=1668096467628&rl=1280*1024&lang=en-US&ct=unknow&pf=1&ins=1&vd=1&ce=1&cd=24&ds=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A&ing=1&ekc=&sid=1668096467628&tt=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E4%25B9%2585%25E4%25B9%2585%25E4%25B8%2580%25E7%25BA%25BF%25E4%25B8%258D%25E5%258D%25A1&kw=%25E5%2585%258D%25E8%25B4%25B9A%25E7%25BA%25A7%25E6%25AF%259B%25E7%2589%2587%25E6%2597%25A0%25E7%25A0%2581%25E5%2585%258D%25E8%25B4%25B9%25E8%25A7%2586%25E9%25A2%2591120%25E8%25BD%25AF%25E4%25BB%25B6%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E4%25B9%2585%25E9%25B8%25AD%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E4%25B9%2585%25E4%25B9%2585%25E4%25B8%2580%25E7%25BA%25BF%25E4%25B8%258D%25E5%258D%25A1%25EF%25BC%258C%25E4%25B9%2585%25E4%25B9%2585%25E7%25B2%25BE%25E5%2593%2581%25E5%258D%2588%25E5%25A4%259C%25E4%25B8%2580%25E5%258C%25BA%25E4%25BA%258C%25E5%258C%25BA%25E7%25A6%258F%25E5%2588%25A9%25EF%25BC%258C%25E4%25BA%259A%25E6%25B4%25B2%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E6%2597%25A0%25E7%25A0%2581%25E4%25B8%2593%25E5%258C%25BA%25E4%25B9%2585%25E4%25B9%2585%25EF%25BC%258C%25E5%259B%25BD%25E4%25BA%25A7%25E7%25B2%25BE%25E5%2593%2581%25E9%2585%2592%25E5%25BA%2597%25E4%25B8%2580%25E5%258C%25BA%25E4%25BA%258C%25E5%258C%25BA%25EF%25BC%258C%25E4%25B8%2580%25E6%259C%25AC%25E7%25BB%25BC%25E5%2590%2588%25E4%25B9%259D%25E4%25B9%259D%25E5%259B%25BD%25E4%25BA%25A7%25E4%25BA%258C%25E5%258C%25BA&cu=http%253A%252F%252Fnjanow.com%252F&pu=false
                                                                                        high
                                                                                        http://njanow.com/false
                                                                                          unknown
                                                                                          http://njanow.com/template/web/js/jquery.min.jsfalse
                                                                                          • Avira URL Cloud: safe
                                                                                          unknown
                                                                                          http://njanow.com/static/js/home.jsfalse
                                                                                          • Avira URL Cloud: safe
                                                                                          unknown
                                                                                          • No. of IPs < 25%
                                                                                          • 25% < No. of IPs < 50%
                                                                                          • 50% < No. of IPs < 75%
                                                                                          • 75% < No. of IPs
                                                                                          IPDomainCountryFlagASNASN NameMalicious
                                                                                          103.143.19.103
                                                                                          d2cb5ad7002c4066.huaweisafedns.cnChina
                                                                                          139643I-SMART-AS-APiSmartBDfalse
                                                                                          9.9.9.9
                                                                                          unknownUnited States
                                                                                          19281QUAD9-AS-1USfalse
                                                                                          23.80.82.204
                                                                                          njanow.comUnited States
                                                                                          395954LEASEWEB-USA-LAX-11USfalse
                                                                                          34.104.35.123
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          172.217.18.13
                                                                                          accounts.google.comUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          142.250.186.163
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          123.253.107.70
                                                                                          ads-6686.topUnited States
                                                                                          32708ROOTNETWORKSUSfalse
                                                                                          142.250.185.238
                                                                                          clients.l.google.comUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          23.224.145.194
                                                                                          unknownUnited States
                                                                                          40065CNSERVERSUSfalse
                                                                                          23.80.10.82
                                                                                          nyc517.comUnited States
                                                                                          395954LEASEWEB-USA-LAX-11USfalse
                                                                                          23.224.145.195
                                                                                          gtm-cn-tl32u3a9801.gtm-a2b4.comUnited States
                                                                                          40065CNSERVERSUSfalse
                                                                                          103.235.46.191
                                                                                          hm.e.shifen.comHong Kong
                                                                                          55967BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtdfalse
                                                                                          239.255.255.250
                                                                                          unknownReserved
                                                                                          unknownunknownfalse
                                                                                          142.250.185.163
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          154.13.4.63
                                                                                          usa.xatrt.comUnited States
                                                                                          64249ENDOFFICEUSfalse
                                                                                          142.251.143.35
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          23.225.63.114
                                                                                          vip.govhebie.comUnited States
                                                                                          40065CNSERVERSUSfalse
                                                                                          142.250.186.132
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          172.217.18.99
                                                                                          unknownUnited States
                                                                                          15169GOOGLEUSfalse
                                                                                          47.253.50.2
                                                                                          sdk.51.laUnited States
                                                                                          45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                                                                                          154.83.25.141
                                                                                          asheng.dl556677.comSeychelles
                                                                                          62587ANT-CLOUDUSfalse
                                                                                          IP
                                                                                          192.168.2.1
                                                                                          127.0.0.1
                                                                                          Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                          Analysis ID:743264
                                                                                          Start date and time:2022-11-10 17:07:14 +01:00
                                                                                          Joe Sandbox Product:CloudBasic
                                                                                          Overall analysis duration:
                                                                                          Hypervisor based Inspection enabled:false
                                                                                          Report type:full
                                                                                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                          Sample URL:http://njanow.com/
                                                                                          Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                                                                          Number of analysed new started processes analysed:10
                                                                                          Number of new started drivers analysed:0
                                                                                          Number of existing processes analysed:0
                                                                                          Number of existing drivers analysed:0
                                                                                          Number of injected processes analysed:0
                                                                                          Technologies:
                                                                                          • EGA enabled
                                                                                          Analysis Mode:stream
                                                                                          Analysis stop reason:Timeout
                                                                                          Detection:MAL
                                                                                          Classification:mal52.troj.win@33/0@38/239
                                                                                          • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                                                                                          • Excluded IPs from analysis (whitelisted): 40.126.31.67, 20.190.159.23, 20.190.159.71, 40.126.31.71, 20.190.159.73, 40.126.31.73, 20.190.159.2, 20.190.159.0, 142.250.185.163, 34.104.35.123
                                                                                          • Excluded domains from analysis (whitelisted): fs.microsoft.com, prda.aadg.msidentity.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, login.live.com, ctldl.windowsupdate.com, clientservices.googleapis.com, login.msa.msidentity.com, www.tm.a.prd.aadg.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                                                                                          • Not all processes where analyzed, report is missing behavior information
                                                                                          • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                          • VT rate limit hit for: http://njanow.com/
                                                                                          • VT rate limit hit for: http://njanow.com/static/js/home.js
                                                                                          • VT rate limit hit for: http://njanow.com/template/web/image/favicon.ico
                                                                                          • VT rate limit hit for: http://njanow.com/template/web/image/loading.svg
                                                                                          • VT rate limit hit for: http://njanow.com/template/web/image/video-play.png
                                                                                          • VT rate limit hit for: http://njanow.com/template/web/js/jquery.lazyload.min.js
                                                                                          • VT rate limit hit for: http://njanow.com/template/web/js/jquery.min.js
                                                                                          • VT rate limit hit for: http://nyc517.com/Template/88888.png
                                                                                          No created / dropped files found
                                                                                          No static file info