Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy

Overview

General Information

Sample URL:https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy
Analysis ID:751071
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 6040 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 3932 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1616,i,10911142850393037891,9908778172277030038,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 972 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRySlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: xhdtsb3f.proventtus.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /300/150/?image=641 HTTP/1.1Host: picsum.photosConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: https://xhdtsb3f.proventtus.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://xhdtsb3f.proventtus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1Host: cstaticdun.126.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://xhdtsb3f.proventtus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /id/641/300/150.jpg?hmac=NtDp-xUbHoNWFSqQx3606nwHGc6F_LuquLped3Nb7dU HTTP/1.1Host: i.picsum.photosConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://xhdtsb3f.proventtus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: xhdtsb3f.proventtus.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://xhdtsb3f.proventtus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 21 Nov 2022 17:45:22 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Tue, 09 Aug 2022 14:43:04 GMTAccept-Ranges: bytesContent-Length: 583Vary: Accept-EncodingContent-Type: text/html
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: mal48.win@25/0@7/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1616,i,10911142850393037891,9908778172277030038,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1616,i,10911142850393037891,9908778172277030038,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy0%Avira URL Cloudsafe
https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy2%VirustotalBrowse
https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://xhdtsb3f.proventtus.com/favicon.ico0%Avira URL Cloudsafe
https://xhdtsb3f.proventtus.com/0%Avira URL Cloudsafe
https://xhdtsb3f.proventtus.com/2%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
i.picsum.photos
104.26.5.30
truefalse
    high
    xhdtsb3f.proventtus.com
    192.185.129.60
    truefalse
      unknown
      accounts.google.com
      172.217.168.45
      truefalse
        high
        www.google.com
        172.217.168.36
        truefalse
          high
          clients.l.google.com
          142.250.203.110
          truefalse
            high
            cstaticdun.126.net.w.kunluncan.com
            163.181.92.225
            truefalse
              unknown
              picsum.photos
              104.26.4.30
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  cstaticdun.126.net
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://i.picsum.photos/id/641/300/150.jpg?hmac=NtDp-xUbHoNWFSqQx3606nwHGc6F_LuquLped3Nb7dUfalse
                      high
                      https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                        high
                        https://cstaticdun.126.net//2.6.3/images/icon_light.f13cff3.pngfalse
                          high
                          https://picsum.photos/300/150/?image=641false
                            high
                            https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRytrue
                              unknown
                              https://xhdtsb3f.proventtus.com/favicon.icofalse
                              • Avira URL Cloud: safe
                              unknown
                              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                high
                                https://xhdtsb3f.proventtus.com/false
                                • 2%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                104.26.5.30
                                i.picsum.photosUnited States
                                13335CLOUDFLARENETUSfalse
                                163.181.92.225
                                cstaticdun.126.net.w.kunluncan.comUnited States
                                24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                142.250.203.110
                                clients.l.google.comUnited States
                                15169GOOGLEUSfalse
                                104.26.4.30
                                picsum.photosUnited States
                                13335CLOUDFLARENETUSfalse
                                172.217.168.45
                                accounts.google.comUnited States
                                15169GOOGLEUSfalse
                                192.185.129.60
                                xhdtsb3f.proventtus.comUnited States
                                46606UNIFIEDLAYER-AS-1USfalse
                                172.217.168.36
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                239.255.255.250
                                unknownReserved
                                unknownunknownfalse
                                IP
                                192.168.2.1
                                127.0.0.1
                                Joe Sandbox Version:36.0.0 Rainbow Opal
                                Analysis ID:751071
                                Start date and time:2022-11-21 18:44:20 +01:00
                                Joe Sandbox Product:CloudBasic
                                Overall analysis duration:0h 3m 50s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:browseurl.jbs
                                Sample URL:https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy
                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                Number of analysed new started processes analysed:12
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • HDC enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Detection:MAL
                                Classification:mal48.win@25/0@7/10
                                EGA Information:Failed
                                HDC Information:Failed
                                HCA Information:
                                • Successful, ratio: 100%
                                • Number of executed functions: 0
                                • Number of non-executed functions: 0
                                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                                • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                No simulations
                                No context
                                No context
                                No context
                                No context
                                No context
                                No created / dropped files found
                                No static file info
                                TimestampSource PortDest PortSource IPDest IP
                                Nov 21, 2022 18:45:20.398080111 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.398159981 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.398264885 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.400993109 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.401032925 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.401114941 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.402385950 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.402445078 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.402520895 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.454364061 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.454416990 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.454972029 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.454998970 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.455238104 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.455271006 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.526123047 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.534575939 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.534642935 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.535442114 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.535583973 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.536302090 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.536386967 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.549396992 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.549741983 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.549798012 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.551686049 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.551799059 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.820110083 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.826978922 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.827008009 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.828459978 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.828531981 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.882083893 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.882131100 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.882320881 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.882497072 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.882519960 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.883724928 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.883763075 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.884114027 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.884244919 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:20.884272099 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:20.884464025 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.884495020 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.884675980 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.884685040 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.884697914 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.921497107 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.921619892 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.921648026 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.921756029 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.921850920 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.927195072 CET49699443192.168.2.3142.250.203.110
                                Nov 21, 2022 18:45:20.927227020 CET44349699142.250.203.110192.168.2.3
                                Nov 21, 2022 18:45:20.934506893 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.934598923 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.934638977 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.934669018 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:20.934751034 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.936323881 CET49702443192.168.2.3172.217.168.45
                                Nov 21, 2022 18:45:20.936352968 CET44349702172.217.168.45192.168.2.3
                                Nov 21, 2022 18:45:21.001884937 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.153740883 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153779984 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153793097 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153855085 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153856039 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.153889894 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153903008 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.153939009 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.153948069 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.153948069 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.154011965 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.154104948 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.174259901 CET49700443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.174294949 CET44349700192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.378108978 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.378150940 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.378274918 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.378657103 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.378673077 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.381464005 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.381524086 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.381633043 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.381928921 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.381962061 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.438272953 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.441459894 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.480802059 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.480858088 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.481072903 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.481115103 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.484472990 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.484673023 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.485196114 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.485330105 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.487179995 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.487198114 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.487454891 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.487471104 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.487488985 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.487791061 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.487958908 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.487979889 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.573694944 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.573779106 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.573874950 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.574158907 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.574193954 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.617887974 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.617938042 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.619580030 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.619795084 CET44349707104.26.4.30192.168.2.3
                                Nov 21, 2022 18:45:21.619905949 CET49707443192.168.2.3104.26.4.30
                                Nov 21, 2022 18:45:21.673796892 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.673846960 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.673937082 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.674302101 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.674323082 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.691843033 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.692255020 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.692301035 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.693557978 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.693645000 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.695960999 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.695976019 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.696084976 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.696122885 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.696136951 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.698894024 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.698916912 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:21.725956917 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.726070881 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.726073027 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.726118088 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.726171970 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.740627050 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.741967916 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.742042065 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.744271994 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.744380951 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.770459890 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.770518064 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.770685911 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.770699978 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.770939112 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.773564100 CET49708443192.168.2.3163.181.92.225
                                Nov 21, 2022 18:45:21.773618937 CET44349708163.181.92.225192.168.2.3
                                Nov 21, 2022 18:45:21.798933029 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:21.817926884 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.817990065 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.870692968 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.870738029 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.870804071 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.870812893 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.870847940 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.870882034 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.870956898 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.871016979 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.874684095 CET49709443192.168.2.3104.26.5.30
                                Nov 21, 2022 18:45:21.874720097 CET44349709104.26.5.30192.168.2.3
                                Nov 21, 2022 18:45:21.890846968 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.890974998 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:21.891123056 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.891525984 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:21.891561985 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.240206957 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.240717888 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.240742922 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.241497040 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.242348909 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.242362022 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.242533922 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.242556095 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.242563009 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.328104019 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.587102890 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.587271929 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:22.587398052 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.598198891 CET49710443192.168.2.3192.185.129.60
                                Nov 21, 2022 18:45:22.598217010 CET44349710192.185.129.60192.168.2.3
                                Nov 21, 2022 18:45:31.448946953 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:31.449100018 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:45:31.449336052 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:33.320939064 CET49706443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:45:33.320981026 CET44349706172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.270390034 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:21.270467997 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.270582914 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:21.270787001 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:21.270814896 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.328555107 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.329324961 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:21.329349041 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.329822063 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.330549955 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:21.330573082 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.330656052 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:21.378964901 CET49741443192.168.2.3172.217.168.36
                                Nov 21, 2022 18:46:31.315712929 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:31.315853119 CET44349741172.217.168.36192.168.2.3
                                Nov 21, 2022 18:46:31.316282034 CET49741443192.168.2.3172.217.168.36
                                TimestampSource PortDest PortSource IPDest IP
                                Nov 21, 2022 18:45:20.290627003 CET5238753192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:20.291805029 CET5692453192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:20.292428017 CET6062553192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:20.309818029 CET53523878.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:20.311337948 CET53606258.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:20.318950891 CET53569248.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:21.233628988 CET5295553192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:21.250771999 CET53529558.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:21.259994984 CET6058253192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:21.265460014 CET5713453192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:21.287576914 CET53571348.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:21.536088943 CET53605828.8.8.8192.168.2.3
                                Nov 21, 2022 18:45:21.626162052 CET6205053192.168.2.38.8.8.8
                                Nov 21, 2022 18:45:21.649214983 CET53620508.8.8.8192.168.2.3
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Nov 21, 2022 18:45:20.290627003 CET192.168.2.38.8.8.80xe3a7Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:20.291805029 CET192.168.2.38.8.8.80x2ab0Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:20.292428017 CET192.168.2.38.8.8.80xcc12Standard query (0)xhdtsb3f.proventtus.comA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.233628988 CET192.168.2.38.8.8.80x4f89Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.259994984 CET192.168.2.38.8.8.80x8058Standard query (0)cstaticdun.126.netA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.265460014 CET192.168.2.38.8.8.80xcda4Standard query (0)picsum.photosA (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.626162052 CET192.168.2.38.8.8.80x9baaStandard query (0)i.picsum.photosA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Nov 21, 2022 18:45:20.309818029 CET8.8.8.8192.168.2.30xe3a7No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:20.311337948 CET8.8.8.8192.168.2.30xcc12No error (0)xhdtsb3f.proventtus.com192.185.129.60A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:20.318950891 CET8.8.8.8192.168.2.30x2ab0No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                Nov 21, 2022 18:45:20.318950891 CET8.8.8.8192.168.2.30x2ab0No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.250771999 CET8.8.8.8192.168.2.30x4f89No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.287576914 CET8.8.8.8192.168.2.30xcda4No error (0)picsum.photos104.26.4.30A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.287576914 CET8.8.8.8192.168.2.30xcda4No error (0)picsum.photos104.26.5.30A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.287576914 CET8.8.8.8192.168.2.30xcda4No error (0)picsum.photos172.67.74.163A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.netcstaticdun.126.net.163jiasu.comCNAME (Canonical name)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.163jiasu.comcstaticdun.126.net.w.kunluncan.comCNAME (Canonical name)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.225A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.231A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.228A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.229A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.232A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.230A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.227A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.536088943 CET8.8.8.8192.168.2.30x8058No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.226A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.649214983 CET8.8.8.8192.168.2.30x9baaNo error (0)i.picsum.photos104.26.5.30A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.649214983 CET8.8.8.8192.168.2.30x9baaNo error (0)i.picsum.photos172.67.74.163A (IP address)IN (0x0001)false
                                Nov 21, 2022 18:45:21.649214983 CET8.8.8.8192.168.2.30x9baaNo error (0)i.picsum.photos104.26.4.30A (IP address)IN (0x0001)false
                                • accounts.google.com
                                • xhdtsb3f.proventtus.com
                                • clients2.google.com
                                • https:
                                  • picsum.photos
                                  • cstaticdun.126.net
                                  • i.picsum.photos
                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                0192.168.2.349702172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:20 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                Host: accounts.google.com
                                Connection: keep-alive
                                Content-Length: 1
                                Origin: https://www.google.com
                                Content-Type: application/x-www-form-urlencoded
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                                2022-11-21 17:45:20 UTC0OUTData Raw: 20
                                Data Ascii:
                                2022-11-21 17:45:20 UTC3INHTTP/1.1 200 OK
                                Content-Type: application/json; charset=utf-8
                                Access-Control-Allow-Origin: https://www.google.com
                                Access-Control-Allow-Credentials: true
                                X-Content-Type-Options: nosniff
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Mon, 21 Nov 2022 17:45:20 GMT
                                Strict-Transport-Security: max-age=31536000; includeSubDomains
                                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                Content-Security-Policy: script-src 'report-sample' 'nonce-9DvH6Arkjc9rfOo7u3FK-w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                                Server: ESF
                                X-XSS-Protection: 0
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2022-11-21 17:45:20 UTC5INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                Data Ascii: 11["gaia.l.a.r",[]]
                                2022-11-21 17:45:20 UTC5INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                1192.168.2.349700192.185.129.60443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:20 UTC0OUTGET / HTTP/1.1
                                Host: xhdtsb3f.proventtus.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                sec-ch-ua-platform: "Windows"
                                Upgrade-Insecure-Requests: 1
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: navigate
                                Sec-Fetch-User: ?1
                                Sec-Fetch-Dest: document
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:21 UTC5INHTTP/1.1 200 OK
                                Date: Mon, 21 Nov 2022 17:45:21 GMT
                                Server: Apache
                                Upgrade: h2,h2c
                                Connection: Upgrade, close
                                Last-Modified: Mon, 21 Nov 2022 13:00:43 GMT
                                Accept-Ranges: bytes
                                Content-Length: 10868
                                Vary: Accept-Encoding,User-Agent
                                Content-Type: text/html
                                2022-11-21 17:45:21 UTC5INData Raw: 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 20 3c 74 69 74 6c 65 3e 43 61 70 74 63 68 61 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 2e 62 6c 6f 63 6b 7b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6c 65 66 74 3a 30 3b 74 6f 70 3a 30 7d 2e 73 6c 69 64 65 72 43 6f 6e 74 61 69 6e 65 72 7b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 77 69 64 74 68 3a 33 31 30 70 78 3b 68 65 69 67 68 74 3a 34 30 70 78 3b 6c 69 6e 65 2d 68 65 69 67 68 74 3a 34 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 35 70 78 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 76 65 72 64 61 6e 61 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 37 66 39 66 61 3b 66 6f 6e 74 2d 73 69 7a 65 3a 31 34 70 78 3b 63 6f 6c 6f 72 3a 23 34 35
                                Data Ascii: </body></html> <title>Captcha</title><style>.block{position:absolute;left:0;top:0}.sliderContainer{position:relative;text-align:center;width:310px;height:40px;line-height:40px;margin-top:15px;font-family:verdana;background:#f7f9fa;font-size:14px;color:#45
                                2022-11-21 17:45:21 UTC13INData Raw: 75 73 65 72 41 67 65 6e 74 2e 69 6e 64 65 78 4f 66 28 22 4d 53 49 45 22 29 29 6e 2e 62 6c 6f 63 6b 2e 73 74 79 6c 65 2e 6d 61 72 67 69 6e 4c 65 66 74 3d 22 2d 22 2b 28 6e 2e 78 2d 33 29 2b 22 70 78 22 3b 65 6c 73 65 7b 76 61 72 20 74 3d 6e 2e 62 6c 6f 63 6b 43 74 78 2e 67 65 74 49 6d 61 67 65 44 61 74 61 28 6e 2e 78 2d 33 2c 65 2c 6f 2c 6f 29 3b 6e 2e 62 6c 6f 63 6b 2e 77 69 64 74 68 3d 6f 2c 6e 2e 62 6c 6f 63 6b 43 74 78 2e 70 75 74 49 6d 61 67 65 44 61 74 61 28 74 2c 30 2c 65 29 7d 7d 2c 28 74 3d 76 28 22 69 6d 67 22 29 29 2e 63 72 6f 73 73 4f 72 69 67 69 6e 3d 22 41 6e 6f 6e 79 6d 6f 75 73 22 2c 74 2e 6f 6e 6c 6f 61 64 3d 65 2c 74 2e 6f 6e 65 72 72 6f 72 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 74 2e 73 72 63 3d 61 28 29 7d 2c 74 2e 73 72 63 3d 61 28 29 2c
                                Data Ascii: userAgent.indexOf("MSIE"))n.block.style.marginLeft="-"+(n.x-3)+"px";else{var t=n.blockCtx.getImageData(n.x-3,e,o,o);n.block.width=o,n.blockCtx.putImageData(t,0,e)}},(t=v("img")).crossOrigin="Anonymous",t.onload=e,t.onerror=function(){t.src=a()},t.src=a(),


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                2192.168.2.349699142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:20 UTC1OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                Host: clients2.google.com
                                Connection: keep-alive
                                X-Goog-Update-Interactivity: fg
                                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:20 UTC2INHTTP/1.1 200 OK
                                Content-Security-Policy: script-src 'report-sample' 'nonce-HCsy6iYVMXx_7uQje02mkA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Mon, 21 Nov 2022 17:45:20 GMT
                                Content-Type: text/xml; charset=UTF-8
                                X-Daynum: 5803
                                X-Daystart: 35120
                                X-Content-Type-Options: nosniff
                                X-Frame-Options: SAMEORIGIN
                                X-XSS-Protection: 1; mode=block
                                Server: GSE
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2022-11-21 17:45:20 UTC3INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 30 33 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 35 31 32 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5803" elapsed_seconds="35120"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                2022-11-21 17:45:20 UTC3INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                                Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                                2022-11-21 17:45:20 UTC3INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                3192.168.2.349707104.26.4.30443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:21 UTC16OUTGET /300/150/?image=641 HTTP/1.1
                                Host: picsum.photos
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                Origin: https://xhdtsb3f.proventtus.com
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: cors
                                Sec-Fetch-Dest: image
                                Referer: https://xhdtsb3f.proventtus.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:21 UTC17INHTTP/1.1 302 Found
                                Date: Mon, 21 Nov 2022 17:45:21 GMT
                                Content-Length: 0
                                Connection: close
                                location: https://i.picsum.photos/id/641/300/150.jpg?hmac=NtDp-xUbHoNWFSqQx3606nwHGc6F_LuquLped3Nb7dU
                                access-control-allow-origin: *
                                Cache-Control: no-cache, no-store, must-revalidate
                                vary: Origin
                                CF-Cache-Status: DYNAMIC
                                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=3zA4anefpVCqKIzvdqu5DxO0f7mwqJt%2FUIbTOOe6pWeNN7pNTRmkvBO258audz7hyRSCzLqWzNN15G2GMUwmdP8v65pDD3JSHod9%2BBZNP5ST6HZIAa0Ip57nTL6Pp4U%3D"}],"group":"cf-nel","max_age":604800}
                                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                Strict-Transport-Security: max-age=15552000
                                X-Content-Type-Options: nosniff
                                Server: cloudflare
                                CF-RAY: 76db3d155f3f9a0b-FRA
                                alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                4192.168.2.349708163.181.92.225443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:21 UTC17OUTGET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1
                                Host: cstaticdun.126.net
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://xhdtsb3f.proventtus.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:21 UTC18INHTTP/1.1 200 OK
                                Server: Tengine
                                Content-Type: image/png
                                Content-Length: 11413
                                Connection: close
                                Date: Mon, 21 Nov 2022 17:45:16 GMT
                                Timing-Allow-Origin: *, *
                                Accept-Ranges: bytes
                                Cache-Control: max-age=43200
                                Expires: Mon, 14 Nov 2022 21:34:56 GMT
                                Last-Modified: Mon, 07 Nov 2022 05:53:30 GMT
                                Ali-Swift-Global-Savetime: 1669052716
                                Via: cache11.l2de2[0,0,304-0,H], cache12.l2de2[1,0], ens-cache6.de5[2,2,200-0,H], ens-cache12.de5[4,0]
                                Age: 5
                                X-Cache: HIT TCP_REFRESH_HIT dirn:13:522376634
                                X-Swift-SaveTime: Mon, 21 Nov 2022 17:45:21 GMT
                                X-Swift-CacheTime: 55
                                Access-Control-Allow-Methods: GET,POST,OPTIONS,HEAD
                                Access-Control-Expose-Headers: *
                                Access-Control-Allow-Origin: *
                                EagleId: a3b55ca016690527217023385e
                                2022-11-21 17:45:21 UTC19INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 22 00 00 01 d7 08 06 00 00 00 d9 6f 88 dc 00 00 28 23 49 44 41 54 78 01 ec c1 0b bc 96 75 81 28 ea e7 ff 7f 5f 40 16 43 28 b8 80 c5 4d d2 b8 58 a0 96 34 a4 48 ba d4 12 67 d4 72 7b 9c 40 73 2b ba bb 88 a3 c7 19 c3 b1 b4 c6 1a 85 84 d4 69 4b 9b 71 cf 38 e9 2e 53 f7 74 53 2b 6b d2 96 06 69 1a b3 1b 45 72 c0 4b 10 02 4b 90 52 09 e4 b2 be f7 bf bf 73 5e 7e bf c5 92 75 f9 80 b5 d8 9e a3 cf 13 52 4a f6 40 03 7e 8c 2d 21 84 63 74 a3 a8 76 0d 68 c2 11 e8 ab 9b 45 b5 69 40 13 c6 61 39 4e d5 cd a2 ae 35 a0 09 e3 b0 1c 8d 58 a7 9b e5 78 18 f5 98 86 d5 da 6a 40 13 c6 61 39 1a b1 4e 0f 88 e8 8b 77 a3 09 23 b5 6a 40 13 c6 61 39 1a b1 4e 0f 89 38 0d cb 70 18 9a 30 12 0d 68 c2 38 2c 47 23 d6 e9 41 39 36 a0 11 4d 78
                                Data Ascii: PNGIHDR"o(#IDATxu(_@C(MX4Hgr{@s+iKq8.StS+kiErKKRs^~uRJ@~-!ctvhEi@a9N5Xxj@a9Nw#j@a9N8p0h8,G#A96Mx


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                5192.168.2.349709104.26.5.30443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:21 UTC30OUTGET /id/641/300/150.jpg?hmac=NtDp-xUbHoNWFSqQx3606nwHGc6F_LuquLped3Nb7dU HTTP/1.1
                                Host: i.picsum.photos
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                Origin: null
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: cors
                                Sec-Fetch-Dest: image
                                Referer: https://xhdtsb3f.proventtus.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:21 UTC30INHTTP/1.1 200 OK
                                Date: Mon, 21 Nov 2022 17:45:21 GMT
                                Content-Type: image/jpeg
                                Content-Length: 4404
                                Connection: close
                                Cache-Control: public, max-age=2592000
                                Cf-Bgj: h2pri
                                access-control-allow-origin: *
                                access-control-expose-headers: Content-Type, Picsum-Id
                                content-disposition: inline; filename="641-300x150.jpg"
                                picsum-id: 641
                                vary: Origin
                                Last-Modified: Tue, 15 Nov 2022 00:59:49 GMT
                                CF-Cache-Status: HIT
                                Accept-Ranges: bytes
                                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=DsPh2uullFC4qi5f8Vxem3Apr7SpQChLvhOEIJxTWF1PRxqzIgwQcs9B87%2BYNcirqo1myAh4xspjEcO2A83a1btqIfefxh1jGRvy%2FaxyfN1zMIIiVppP0p6%2B2NsY3IGB%2Fw%3D%3D"}],"group":"cf-nel","max_age":604800}
                                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                Strict-Transport-Security: max-age=15552000
                                X-Content-Type-Options: nosniff
                                Server: cloudflare
                                CF-RAY: 76db3d174ce89b88-FRA
                                alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
                                2022-11-21 17:45:21 UTC31INData Raw: ff d8 ff e1 00 de 45 78 69 66 00 00 49 49 2a 00 08 00 00 00 06 00 12 01 03 00 01 00 00 00 01 00 00 00 1a 01 05 00 01 00 00 00 56 00 00 00 1b 01 05 00 01 00 00 00 5e 00 00 00 28 01 03 00 01 00 00 00 02 00 00 00 13 02 03 00 01 00 00 00 01 00 00 00 69 87 04 00 01 00 00 00 66 00 00 00 00 00 00 00 48 00 00 00 01 00 00 00 48 00 00 00 01 00 00 00 07 00 00 90 07 00 04 00 00 00 30 32 31 30 01 91 07 00 04 00 00 00 01 02 03 00 86 92 07 00 16 00 00 00 c0 00 00 00 00 a0 07 00 04 00 00 00 30 31 30 30 01 a0 03 00 01 00 00 00 ff ff 00 00 02 a0 04 00 01 00 00 00 2c 01 00 00 03 a0 04 00 01 00 00 00 96 00 00 00 00 00 00 00 41 53 43 49 49 00 00 00 50 69 63 73 75 6d 20 49 44 3a 20 36 34 31 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12 13
                                Data Ascii: ExifII*V^(ifHH02100100,ASCIIPicsum ID: 641C
                                2022-11-21 17:45:21 UTC32INData Raw: 01 01 01 01 01 01 01 00 00 00 00 00 00 00 00 00 00 00 01 02 03 04 05 ff da 00 0c 03 01 00 02 10 03 10 00 00 01 ef d6 5f 93 b3 69 ca da 72 b6 98 c1 ca 03 50 00 02 18 21 a3 15 ad 45 25 c9 6c d0 12 89 82 1a 10 c3 23 42 5a 2b 23 0e 77 97 bc 6b 58 d4 69 e5 cd 69 e5 c6 84 2e 84 2e 8c b9 19 3d ab 00 00 50 62 67 34 09 94 46 5b c9 a3 3a 00 15 00 21 a0 40 71 b9 3e bc 6d a8 ea 5a b9 ea 5d bc 39 ad bc 35 de 78 bc 9d 63 de e8 f1 3a 2b d0 dc 6b cf a6 8c 92 e8 cb 1b c8 69 e0 8d 98 17 66 03 46 43 49 24 66 4a d2 ca 34 65 1e 7e a5 af 4f 92 ba 93 ce ac e3 a9 ab 38 ea 5a b8 b9 63 cd e8 4f 59 39 7b e4 ba e8 91 8d 58 91 35 52 41 62 2c a9 20 a9 21 6a 48 2a a6 92 aa 65 51 4d 14 24 14 53 49 c1 a9 eb d5 f3 f7 a9 b9 68 e7 a9 76 f0 e6 b6 f0 e5 8c 6d cd b9 4d c7 47 76 b9 6d 8d 50 c1
                                Data Ascii: _irP!E%l#BZ+#wkXii..=Pbg4F[:!@q>mZ]95xc:+kifFCI$fJ4e~O8ZcOY9{X5RAb, !jH*eQM$SIhvmMGvmP
                                2022-11-21 17:45:21 UTC33INData Raw: c3 47 6a df 2d 3b f4 5d 37 62 5f 52 5f 52 5f 52 5f 52 5f 53 35 5d 4c d5 75 33 3e a4 b3 33 33 d5 d4 f3 2a 3c ca 8f 32 a3 cc 66 76 67 66 76 67 7e 1d 0d c5 c7 65 a3 b4 be fa 7f 0d b7 7e 83 7f ff c4 00 2a 10 00 03 00 00 05 03 03 04 02 03 00 00 00 00 00 00 00 01 11 10 21 31 51 61 20 41 71 30 91 f1 40 50 81 e1 a1 c1 b1 d1 f0 ff da 00 08 01 01 00 01 3f 21 fa 36 93 23 9f b2 b7 ec b1 12 ef 26 84 ee ff 00 65 fc 15 6c c7 b8 2d f1 26 c2 f2 be a7 f8 3e 9c 5b 1c 03 8c 4f b1 3d 1a 52 94 b8 5e 97 f5 51 dd 8f da 48 ed df 0f e1 3e 96 e3 4a 26 52 94 a5 c1 90 a5 a3 2e 2f d8 85 98 69 24 f0 b4 0c 2a c9 2d 47 06 a6 5f 95 64 73 fc a1 6d b2 6a 33 45 29 4a 52 94 a5 29 4a 52 94 a5 29 4a 52 94 a2 c2 89 94 a5 29 93 c9 94 92 3c 8f e8 5f bc 09 13 97 ef ef 19 62 36 4d 66 2f 70 c6 d2 e0
                                Data Ascii: Gj-;]7b_R_R_R_R_S5]Lu3>33*<2fvgfvg~e~*!1Qa Aq0@P?!6#&el-&>[O=R^QH>J&R./i$*-G_dsmj3E)JR)JR)JR)<_b6Mf/p
                                2022-11-21 17:45:21 UTC34INData Raw: 52 05 d1 3d e6 58 1d 6b a5 47 a6 20 c1 d2 5c 18 38 83 88 37 06 0d 41 b9 72 e0 dc 35 3c cf 96 58 37 d4 c4 b8 67 d1 ae b1 4d 43 ed 2c d5 3d 88 aa bf 54 11 62 3d d9 4d a2 57 45 a8 b7 d1 cc 5b e8 67 09 24 a4 20 71 0e 10 60 c1 97 35 ba 73 d1 0d 28 5b a6 9c d3 b4 ba cf 11 ff 00 c1 b4 b9 70 65 cb 97 2e 0e 7d 17 2e 2c b9 71 71 2e 2c b9 49 64 b2 19 c3 4f 4c 93 28 74 8c 61 08 16 a0 72 b1 85 9d 69 7d 9a cf b2 53 c6 58 a2 37 74 0e ed bd a2 89 d4 d1 01 15 6b c9 9f ea 07 93 68 59 05 61 2c 79 4f 89 44 b4 59 65 d7 a0 9d 65 3d 07 54 78 7a 33 d3 65 e7 d0 c3 8f 41 9e b1 77 83 de 1d d2 dd e1 df 04 c2 00 45 04 04 4a 47 37 00 0e eb 75 b7 2d 8e d2 da 18 01 30 6e f3 8f e2 58 b5 da ab 64 84 dc a5 ad ef 97 cc 6d 44 03 87 06 be 94 3f f4 80 47 a4 df a5 ca 38 74 64 83 01 03 0c a1 8e
                                Data Ascii: R=XkG \87Ar5<X7gMC,=Tb=MWE[g$ q`5s([pe.}.,qq.,IdOL(tari}SX7tkhYa,yODYee=Txz3eAwEJG7u-0nXdmD?G8td


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                6192.168.2.349710192.185.129.60443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-21 17:45:22 UTC36OUTGET /favicon.ico HTTP/1.1
                                Host: xhdtsb3f.proventtus.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://xhdtsb3f.proventtus.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-21 17:45:22 UTC36INHTTP/1.1 404 Not Found
                                Date: Mon, 21 Nov 2022 17:45:22 GMT
                                Server: Apache
                                Upgrade: h2,h2c
                                Connection: Upgrade, close
                                Last-Modified: Tue, 09 Aug 2022 14:43:04 GMT
                                Accept-Ranges: bytes
                                Content-Length: 583
                                Vary: Accept-Encoding
                                Content-Type: text/html
                                2022-11-21 17:45:22 UTC37INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 2e 6c 6f 61 64 65 72 20 7b 20 62 6f 72 64 65 72 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 66 33 66 33 66 33 3b 20 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 36 70 78 20 73 6f 6c 69 64 20 23 33 34 39 38 64 62 3b 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 35 30 25 3b 20 77 69 64 74 68 3a 20 31 32 30 70 78 3b 20 68 65 69 67 68 74 3a 20 31 32 30 70 78 3b 20 61 6e 69 6d 61 74 69 6f 6e 3a 20 73 70 69 6e 20 32 73 20 6c 69 6e 65 61 72 20 69 6e 66 69 6e 69 74 65 3b 20 70 6f 73 69 74 69 6f 6e 3a 20 66 69 78 65 64 3b 20 74 6f 70 3a 20 34 30 25 3b 20 6c 65 66 74 3a 20 34 30 25 3b 20 7d 0a 20 20 20 20 20 20 20 20 40 6b 65 79 66 72 61 6d 65 73 20 73 70 69 6e 20 7b 20
                                Data Ascii: <html><head> <style> .loader { border: 16px solid #f3f3f3; border-top: 16px solid #3498db; border-radius: 50%; width: 120px; height: 120px; animation: spin 2s linear infinite; position: fixed; top: 40%; left: 40%; } @keyframes spin {


                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:0
                                Start time:18:45:14
                                Start date:21/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                Target ID:1
                                Start time:18:45:15
                                Start date:21/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1616,i,10911142850393037891,9908778172277030038,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                Target ID:2
                                Start time:18:45:16
                                Start date:21/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xhdtsb3f.proventtus.com/#eWF2dXouemFtYW5AZGlnaXR1cmsuY29tLnRy
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                No disassembly