Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=

Overview

General Information

Sample URL:https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=
Analysis ID:753253
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 6068 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5216 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1800,i,9322260435491250424,2161407301912172907,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 972 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20= MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 4293857.debournigerialtd.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /300/150/?image=817 HTTP/1.1Host: picsum.photosConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: https://4293857.debournigerialtd.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://4293857.debournigerialtd.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1Host: cstaticdun.126.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://4293857.debournigerialtd.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /id/817/300/150.jpg?hmac=HdVONQsKGjB2EtuX3iYA9vjWjORFBvJqqHWyqe-atvs HTTP/1.1Host: i.picsum.photosConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://4293857.debournigerialtd.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 4293857.debournigerialtd.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://4293857.debournigerialtd.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 24 Nov 2022 13:24:36 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeLast-Modified: Sun, 19 Jun 2022 19:42:56 GMTAccept-Ranges: bytesContent-Length: 746Vary: Accept-EncodingContent-Type: text/html
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: mal48.win@25/0@7/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1800,i,9322260435491250424,2161407301912172907,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1800,i,9322260435491250424,2161407301912172907,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=0%Avira URL Cloudsafe
https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://4293857.debournigerialtd.com/0%Avira URL Cloudsafe
https://4293857.debournigerialtd.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
i.picsum.photos
104.26.4.30
truefalse
    high
    accounts.google.com
    172.217.168.45
    truefalse
      high
      4293857.debournigerialtd.com
      108.167.161.63
      truefalse
        unknown
        www.google.com
        172.217.168.36
        truefalse
          high
          clients.l.google.com
          142.250.203.110
          truefalse
            high
            cstaticdun.126.net.w.kunluncan.com
            163.181.92.229
            truefalse
              unknown
              picsum.photos
              104.26.5.30
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  cstaticdun.126.net
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                      high
                      https://picsum.photos/300/150/?image=817false
                        high
                        https://4293857.debournigerialtd.com/false
                        • Avira URL Cloud: safe
                        unknown
                        https://cstaticdun.126.net//2.6.3/images/icon_light.f13cff3.pngfalse
                          high
                          https://i.picsum.photos/id/817/300/150.jpg?hmac=HdVONQsKGjB2EtuX3iYA9vjWjORFBvJqqHWyqe-atvsfalse
                            high
                            https://4293857.debournigerialtd.com/favicon.icofalse
                            • Avira URL Cloud: safe
                            unknown
                            https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=true
                              unknown
                              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                high
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                104.26.5.30
                                picsum.photosUnited States
                                13335CLOUDFLARENETUSfalse
                                163.181.92.229
                                cstaticdun.126.net.w.kunluncan.comUnited States
                                24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                142.250.203.110
                                clients.l.google.comUnited States
                                15169GOOGLEUSfalse
                                104.26.4.30
                                i.picsum.photosUnited States
                                13335CLOUDFLARENETUSfalse
                                172.217.168.45
                                accounts.google.comUnited States
                                15169GOOGLEUSfalse
                                108.167.161.63
                                4293857.debournigerialtd.comUnited States
                                46606UNIFIEDLAYER-AS-1USfalse
                                172.217.168.36
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                239.255.255.250
                                unknownReserved
                                unknownunknownfalse
                                IP
                                192.168.2.1
                                127.0.0.1
                                Joe Sandbox Version:36.0.0 Rainbow Opal
                                Analysis ID:753253
                                Start date and time:2022-11-24 14:23:30 +01:00
                                Joe Sandbox Product:CloudBasic
                                Overall analysis duration:0h 4m 24s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:browseurl.jbs
                                Sample URL:https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=
                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                Number of analysed new started processes analysed:12
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • HDC enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Detection:MAL
                                Classification:mal48.win@25/0@7/10
                                EGA Information:Failed
                                HDC Information:Failed
                                HCA Information:
                                • Successful, ratio: 100%
                                • Number of executed functions: 0
                                • Number of non-executed functions: 0
                                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                                • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                No simulations
                                No context
                                No context
                                No context
                                No context
                                No context
                                No created / dropped files found
                                No static file info
                                TimestampSource PortDest PortSource IPDest IP
                                Nov 24, 2022 14:24:31.574945927 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:31.575012922 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.575107098 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:31.575745106 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:31.575768948 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.639169931 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.643192053 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:31.643227100 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.643898964 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.644038916 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:31.644742966 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:31.644864082 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.213640928 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.213699102 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.213777065 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.214531898 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.214581013 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.214653015 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.215817928 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.215851068 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.216613054 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.216630936 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.217423916 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.217453957 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.218841076 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.218852997 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.219429970 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.255923986 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.256119013 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.256134033 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.256197929 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.287168026 CET49698443192.168.2.3142.250.203.110
                                Nov 24, 2022 14:24:33.287189960 CET44349698142.250.203.110192.168.2.3
                                Nov 24, 2022 14:24:33.319219112 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.327399969 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.417196989 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.417232037 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.417457104 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.417490005 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.420272112 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.420314074 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.420341015 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.420901060 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.420988083 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.421041012 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.500587940 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.634922981 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:33.635124922 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:33.856363058 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:33.856429100 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:33.856506109 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:33.861505985 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:33.861546993 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.027735949 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.027766943 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.027909994 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.028043032 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.028057098 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.087737083 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.087783098 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.087970972 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.088365078 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.088453054 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.088479996 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.088553905 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.088594913 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.090672016 CET49700443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.090704918 CET44349700172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.131612062 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.132086039 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.132114887 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.133332968 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.133430004 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.137129068 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.137149096 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.137269974 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.208933115 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.208960056 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:24:34.255842924 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.255876064 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.340903044 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.340934992 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.403857946 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:24:34.472285986 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472318888 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472326994 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472367048 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472387075 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472438097 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.472454071 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472469091 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:34.472505093 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.472534895 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.700541973 CET49703443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:34.700583935 CET44349703108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:35.071784019 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.071845055 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.071938038 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.072350025 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.072370052 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.121531010 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.175048113 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.175098896 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.176498890 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.176580906 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.176618099 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.200347900 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.200403929 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.200582027 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.200685978 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.200709105 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.249097109 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.249262094 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.278599977 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.278659105 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.278753042 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.280076027 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.280097961 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.341840982 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.444869995 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.444928885 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.445362091 CET49705443192.168.2.3104.26.5.30
                                Nov 24, 2022 14:24:35.445462942 CET44349705104.26.5.30192.168.2.3
                                Nov 24, 2022 14:24:35.446444988 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.446505070 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.446537018 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.448874950 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.448928118 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.449008942 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.449599981 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.449610949 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.450764894 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.450814009 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.451029062 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.542597055 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.543065071 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.543096066 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.544416904 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.544487953 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.548991919 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.549014091 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.549226999 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.550009012 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.550025940 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.555869102 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.555908918 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:35.566817045 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.566906929 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.566989899 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.567534924 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.567548990 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.582537889 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.582587957 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.582644939 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.582665920 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.582684040 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.582695961 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.582724094 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.613887072 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.614470959 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.614521980 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.615771055 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.615895033 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.620626926 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.620660067 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.620855093 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.621016026 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.621048927 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.655920982 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:35.666702986 CET49708443192.168.2.3163.181.92.229
                                Nov 24, 2022 14:24:35.666743040 CET44349708163.181.92.229192.168.2.3
                                Nov 24, 2022 14:24:35.700805902 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.752526045 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752578974 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752609968 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752644062 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752674103 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752706051 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752734900 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.752748966 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752784014 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.752815008 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.752865076 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.753500938 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.753573895 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.753602982 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.753628016 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.753657103 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.753705025 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.754295111 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.754437923 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.754497051 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.791507006 CET49710443192.168.2.3104.26.4.30
                                Nov 24, 2022 14:24:35.791569948 CET44349710104.26.4.30192.168.2.3
                                Nov 24, 2022 14:24:35.818558931 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:35.818605900 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:35.818743944 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:35.819205046 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:35.819221020 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.077697039 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.078222990 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:36.078250885 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.078712940 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.079338074 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:36.079350948 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.079437017 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.079535007 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:36.079544067 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.326359034 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.326476097 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:36.326567888 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:36.361366987 CET49711443192.168.2.3108.167.161.63
                                Nov 24, 2022 14:24:36.361411095 CET44349711108.167.161.63192.168.2.3
                                Nov 24, 2022 14:24:45.318613052 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:45.318721056 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:24:45.318916082 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:48.467444897 CET49707443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:24:48.467514038 CET44349707172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:19.216444016 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:25:19.216469049 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:25:35.063956022 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:25:35.064105034 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:25:35.064410925 CET44349701172.217.168.45192.168.2.3
                                Nov 24, 2022 14:25:35.064482927 CET49701443192.168.2.3172.217.168.45
                                Nov 24, 2022 14:25:35.066154957 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.066211939 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.066302061 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.066839933 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.066859007 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.118915081 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.170962095 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.242646933 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.242681980 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.243362904 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.247812033 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:35.247853994 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.247973919 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:35.296092987 CET49742443192.168.2.3172.217.168.36
                                Nov 24, 2022 14:25:45.112358093 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:45.112462997 CET44349742172.217.168.36192.168.2.3
                                Nov 24, 2022 14:25:45.112579107 CET49742443192.168.2.3172.217.168.36
                                TimestampSource PortDest PortSource IPDest IP
                                Nov 24, 2022 14:24:31.425371885 CET5799053192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:31.444614887 CET53579908.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:31.567991972 CET5238753192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:31.586164951 CET53523878.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:33.696897984 CET6062553192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:33.820245028 CET53606258.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:34.862111092 CET5295553192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:34.862839937 CET6058253192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:34.885446072 CET53529558.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:35.053473949 CET5713453192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:35.070600033 CET53571348.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:35.357801914 CET53605828.8.8.8192.168.2.3
                                Nov 24, 2022 14:24:35.541846037 CET5604253192.168.2.38.8.8.8
                                Nov 24, 2022 14:24:35.565623045 CET53560428.8.8.8192.168.2.3
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Nov 24, 2022 14:24:31.425371885 CET192.168.2.38.8.8.80x9c53Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:31.567991972 CET192.168.2.38.8.8.80x3f83Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:33.696897984 CET192.168.2.38.8.8.80xaaaStandard query (0)4293857.debournigerialtd.comA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:34.862111092 CET192.168.2.38.8.8.80xb864Standard query (0)picsum.photosA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:34.862839937 CET192.168.2.38.8.8.80x9591Standard query (0)cstaticdun.126.netA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.053473949 CET192.168.2.38.8.8.80xb1b2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.541846037 CET192.168.2.38.8.8.80x5d17Standard query (0)i.picsum.photosA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Nov 24, 2022 14:24:31.444614887 CET8.8.8.8192.168.2.30x9c53No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                Nov 24, 2022 14:24:31.444614887 CET8.8.8.8192.168.2.30x9c53No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:31.586164951 CET8.8.8.8192.168.2.30x3f83No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:33.820245028 CET8.8.8.8192.168.2.30xaaaNo error (0)4293857.debournigerialtd.com108.167.161.63A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:34.885446072 CET8.8.8.8192.168.2.30xb864No error (0)picsum.photos104.26.5.30A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:34.885446072 CET8.8.8.8192.168.2.30xb864No error (0)picsum.photos172.67.74.163A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:34.885446072 CET8.8.8.8192.168.2.30xb864No error (0)picsum.photos104.26.4.30A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.070600033 CET8.8.8.8192.168.2.30xb1b2No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.netcstaticdun.126.net.163jiasu.comCNAME (Canonical name)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.163jiasu.comcstaticdun.126.net.w.kunluncan.comCNAME (Canonical name)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.229A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.228A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.225A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.231A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.232A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.230A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.227A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.357801914 CET8.8.8.8192.168.2.30x9591No error (0)cstaticdun.126.net.w.kunluncan.com163.181.92.226A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.565623045 CET8.8.8.8192.168.2.30x5d17No error (0)i.picsum.photos104.26.4.30A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.565623045 CET8.8.8.8192.168.2.30x5d17No error (0)i.picsum.photos172.67.74.163A (IP address)IN (0x0001)false
                                Nov 24, 2022 14:24:35.565623045 CET8.8.8.8192.168.2.30x5d17No error (0)i.picsum.photos104.26.5.30A (IP address)IN (0x0001)false
                                • clients2.google.com
                                • accounts.google.com
                                • 4293857.debournigerialtd.com
                                • https:
                                  • picsum.photos
                                  • cstaticdun.126.net
                                  • i.picsum.photos
                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                0192.168.2.349698142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:33 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                Host: clients2.google.com
                                Connection: keep-alive
                                X-Goog-Update-Interactivity: fg
                                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:33 UTC0INHTTP/1.1 200 OK
                                Content-Security-Policy: script-src 'report-sample' 'nonce-sZu2xKRazutxuQ3Y_U51Uw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Thu, 24 Nov 2022 13:24:33 GMT
                                Content-Type: text/xml; charset=UTF-8
                                X-Daynum: 5806
                                X-Daystart: 19473
                                X-Content-Type-Options: nosniff
                                X-Frame-Options: SAMEORIGIN
                                X-XSS-Protection: 1; mode=block
                                Server: GSE
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2022-11-24 13:24:33 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 30 36 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 39 34 37 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5806" elapsed_seconds="19473"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                2022-11-24 13:24:33 UTC1INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                                Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                                2022-11-24 13:24:33 UTC2INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                1192.168.2.349700172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:34 UTC2OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                Host: accounts.google.com
                                Connection: keep-alive
                                Content-Length: 1
                                Origin: https://www.google.com
                                Content-Type: application/x-www-form-urlencoded
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                                2022-11-24 13:24:34 UTC3OUTData Raw: 20
                                Data Ascii:
                                2022-11-24 13:24:34 UTC3INHTTP/1.1 200 OK
                                Content-Type: application/json; charset=utf-8
                                Access-Control-Allow-Origin: https://www.google.com
                                Access-Control-Allow-Credentials: true
                                X-Content-Type-Options: nosniff
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Thu, 24 Nov 2022 13:24:34 GMT
                                Strict-Transport-Security: max-age=31536000; includeSubDomains
                                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                Content-Security-Policy: script-src 'report-sample' 'nonce-bxSwojUpX2l-lKWnxqn6Wg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                Server: ESF
                                X-XSS-Protection: 0
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2022-11-24 13:24:34 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                Data Ascii: 11["gaia.l.a.r",[]]
                                2022-11-24 13:24:34 UTC4INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                2192.168.2.349703108.167.161.63443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:34 UTC4OUTGET / HTTP/1.1
                                Host: 4293857.debournigerialtd.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                sec-ch-ua-platform: "Windows"
                                Upgrade-Insecure-Requests: 1
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: navigate
                                Sec-Fetch-User: ?1
                                Sec-Fetch-Dest: document
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:34 UTC5INHTTP/1.1 200 OK
                                Date: Thu, 24 Nov 2022 13:24:34 GMT
                                Server: Apache
                                Upgrade: h2,h2c
                                Connection: Upgrade, close
                                Last-Modified: Thu, 24 Nov 2022 11:57:13 GMT
                                Accept-Ranges: bytes
                                Content-Length: 10863
                                Vary: Accept-Encoding
                                Content-Type: text/html
                                2022-11-24 13:24:34 UTC5INData Raw: 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 20 3c 74 69 74 6c 65 3e 43 61 70 74 63 68 61 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 2e 62 6c 6f 63 6b 7b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6c 65 66 74 3a 30 3b 74 6f 70 3a 30 7d 2e 73 6c 69 64 65 72 43 6f 6e 74 61 69 6e 65 72 7b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 77 69 64 74 68 3a 33 31 30 70 78 3b 68 65 69 67 68 74 3a 34 30 70 78 3b 6c 69 6e 65 2d 68 65 69 67 68 74 3a 34 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 35 70 78 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 76 65 72 64 61 6e 61 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 37 66 39 66 61 3b 66 6f 6e 74 2d 73 69 7a 65 3a 31 34 70 78 3b 63 6f 6c 6f 72 3a 23 34 35
                                Data Ascii: </body></html> <title>Captcha</title><style>.block{position:absolute;left:0;top:0}.sliderContainer{position:relative;text-align:center;width:310px;height:40px;line-height:40px;margin-top:15px;font-family:verdana;background:#f7f9fa;font-size:14px;color:#45
                                2022-11-24 13:24:34 UTC13INData Raw: 6e 64 65 78 4f 66 28 22 4d 53 49 45 22 29 29 6e 2e 62 6c 6f 63 6b 2e 73 74 79 6c 65 2e 6d 61 72 67 69 6e 4c 65 66 74 3d 22 2d 22 2b 28 6e 2e 78 2d 33 29 2b 22 70 78 22 3b 65 6c 73 65 7b 76 61 72 20 74 3d 6e 2e 62 6c 6f 63 6b 43 74 78 2e 67 65 74 49 6d 61 67 65 44 61 74 61 28 6e 2e 78 2d 33 2c 65 2c 6f 2c 6f 29 3b 6e 2e 62 6c 6f 63 6b 2e 77 69 64 74 68 3d 6f 2c 6e 2e 62 6c 6f 63 6b 43 74 78 2e 70 75 74 49 6d 61 67 65 44 61 74 61 28 74 2c 30 2c 65 29 7d 7d 2c 28 74 3d 76 28 22 69 6d 67 22 29 29 2e 63 72 6f 73 73 4f 72 69 67 69 6e 3d 22 41 6e 6f 6e 79 6d 6f 75 73 22 2c 74 2e 6f 6e 6c 6f 61 64 3d 65 2c 74 2e 6f 6e 65 72 72 6f 72 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 74 2e 73 72 63 3d 61 28 29 7d 2c 74 2e 73 72 63 3d 61 28 29 2c 74 29 3b 74 68 69 73 2e 69 6d 67
                                Data Ascii: ndexOf("MSIE"))n.block.style.marginLeft="-"+(n.x-3)+"px";else{var t=n.blockCtx.getImageData(n.x-3,e,o,o);n.block.width=o,n.blockCtx.putImageData(t,0,e)}},(t=v("img")).crossOrigin="Anonymous",t.onload=e,t.onerror=function(){t.src=a()},t.src=a(),t);this.img


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                3192.168.2.349705104.26.5.30443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:35 UTC16OUTGET /300/150/?image=817 HTTP/1.1
                                Host: picsum.photos
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                Origin: https://4293857.debournigerialtd.com
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: cors
                                Sec-Fetch-Dest: image
                                Referer: https://4293857.debournigerialtd.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:35 UTC17INHTTP/1.1 302 Found
                                Date: Thu, 24 Nov 2022 13:24:35 GMT
                                Content-Length: 0
                                Connection: close
                                location: https://i.picsum.photos/id/817/300/150.jpg?hmac=HdVONQsKGjB2EtuX3iYA9vjWjORFBvJqqHWyqe-atvs
                                access-control-allow-origin: *
                                Cache-Control: no-cache, no-store, must-revalidate
                                vary: Origin
                                CF-Cache-Status: DYNAMIC
                                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=0mfiQZ%2FU%2BkYGEbanrtDdGHFHTsoJFk16tWzafdzZTZDjeigNvpu8kEc1GLNj7ACd0OOeL7ZEbYsyt0M4EbXjNF1veFGsmqNwH8KKNED4DxqZ1PZaVuyKvmLYLCX1YKE%3D"}],"group":"cf-nel","max_age":604800}
                                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                Strict-Transport-Security: max-age=15552000
                                X-Content-Type-Options: nosniff
                                Server: cloudflare
                                CF-RAY: 76f277380f109956-FRA
                                alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                4192.168.2.349708163.181.92.229443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:35 UTC17OUTGET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1
                                Host: cstaticdun.126.net
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://4293857.debournigerialtd.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:35 UTC18INHTTP/1.1 200 OK
                                Server: Tengine
                                Content-Type: image/png
                                Content-Length: 11413
                                Connection: close
                                Date: Thu, 24 Nov 2022 13:24:23 GMT
                                Timing-Allow-Origin: *, *
                                Accept-Ranges: bytes
                                Cache-Control: max-age=43200
                                Expires: Wed, 23 Nov 2022 01:18:16 GMT
                                Last-Modified: Mon, 07 Nov 2022 05:53:30 GMT
                                Ali-Swift-Global-Savetime: 1669296263
                                Via: cache11.l2de2[0,0,304-0,H], cache2.l2de2[1,0], ens-cache6.de5[5,4,200-0,H], ens-cache4.de5[7,0]
                                Age: 12
                                X-Cache: HIT TCP_REFRESH_HIT dirn:13:831198797
                                X-Swift-SaveTime: Thu, 24 Nov 2022 13:24:35 GMT
                                X-Swift-CacheTime: 48
                                Access-Control-Allow-Methods: GET,POST,OPTIONS,HEAD
                                Access-Control-Expose-Headers: *
                                Access-Control-Allow-Origin: *
                                EagleId: a3b55c9816692962755582121e
                                2022-11-24 13:24:35 UTC19INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 22 00 00 01 d7 08 06 00 00 00 d9 6f 88 dc 00 00 28 23 49 44 41 54 78 01 ec c1 0b bc 96 75 81 28 ea e7 ff 7f 5f 40 16 43 28 b8 80 c5 4d d2 b8 58 a0 96 34 a4 48 ba d4 12 67 d4 72 7b 9c 40 73 2b ba bb 88 a3 c7 19 c3 b1 b4 c6 1a 85 84 d4 69 4b 9b 71 cf 38 e9 2e 53 f7 74 53 2b 6b d2 96 06 69 1a b3 1b 45 72 c0 4b 10 02 4b 90 52 09 e4 b2 be f7 bf bf 73 5e 7e bf c5 92 75 f9 80 b5 d8 9e a3 cf 13 52 4a f6 40 03 7e 8c 2d 21 84 63 74 a3 a8 76 0d 68 c2 11 e8 ab 9b 45 b5 69 40 13 c6 61 39 4e d5 cd a2 ae 35 a0 09 e3 b0 1c 8d 58 a7 9b e5 78 18 f5 98 86 d5 da 6a 40 13 c6 61 39 1a b1 4e 0f 88 e8 8b 77 a3 09 23 b5 6a 40 13 c6 61 39 1a b1 4e 0f 89 38 0d cb 70 18 9a 30 12 0d 68 c2 38 2c 47 23 d6 e9 41 39 36 a0 11 4d 78
                                Data Ascii: PNGIHDR"o(#IDATxu(_@C(MX4Hgr{@s+iKq8.StS+kiErKKRs^~uRJ@~-!ctvhEi@a9N5Xxj@a9Nw#j@a9N8p0h8,G#A96Mx


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                5192.168.2.349710104.26.4.30443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:35 UTC30OUTGET /id/817/300/150.jpg?hmac=HdVONQsKGjB2EtuX3iYA9vjWjORFBvJqqHWyqe-atvs HTTP/1.1
                                Host: i.picsum.photos
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                Origin: null
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: cross-site
                                Sec-Fetch-Mode: cors
                                Sec-Fetch-Dest: image
                                Referer: https://4293857.debournigerialtd.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:35 UTC30INHTTP/1.1 200 OK
                                Date: Thu, 24 Nov 2022 13:24:35 GMT
                                Content-Type: image/jpeg
                                Content-Length: 15562
                                Connection: close
                                Cache-Control: public, max-age=2592000
                                Cf-Bgj: h2pri
                                access-control-allow-origin: *
                                access-control-expose-headers: Content-Type, Picsum-Id
                                content-disposition: inline; filename="817-300x150.jpg"
                                picsum-id: 817
                                vary: Origin
                                Last-Modified: Wed, 09 Nov 2022 00:54:37 GMT
                                CF-Cache-Status: HIT
                                Accept-Ranges: bytes
                                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=IYNWXqB0yyRx5DhoycZYoEw%2FWyztmKvkHKDnt%2FXYQvprHi1qbptyZJ8hUk%2B4wWA235A9TOpAC7yNgy%2BbEcJgDo%2Bsw0CEtGuvz2Updb2rJL4LhLBf8niz01MOUwldrzuh%2FA%3D%3D"}],"group":"cf-nel","max_age":604800}
                                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                Strict-Transport-Security: max-age=15552000
                                X-Content-Type-Options: nosniff
                                Server: cloudflare
                                CF-RAY: 76f2773afc449b76-FRA
                                alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
                                2022-11-24 13:24:35 UTC31INData Raw: ff d8 ff e1 00 de 45 78 69 66 00 00 49 49 2a 00 08 00 00 00 06 00 12 01 03 00 01 00 00 00 01 00 00 00 1a 01 05 00 01 00 00 00 56 00 00 00 1b 01 05 00 01 00 00 00 5e 00 00 00 28 01 03 00 01 00 00 00 02 00 00 00 13 02 03 00 01 00 00 00 01 00 00 00 69 87 04 00 01 00 00 00 66 00 00 00 00 00 00 00 48 00 00 00 01 00 00 00 48 00 00 00 01 00 00 00 07 00 00 90 07 00 04 00 00 00 30 32 31 30 01 91 07 00 04 00 00 00 01 02 03 00 86 92 07 00 16 00 00 00 c0 00 00 00 00 a0 07 00 04 00 00 00 30 31 30 30 01 a0 03 00 01 00 00 00 ff ff 00 00 02 a0 04 00 01 00 00 00 2c 01 00 00 03 a0 04 00 01 00 00 00 96 00 00 00 00 00 00 00 41 53 43 49 49 00 00 00 50 69 63 73 75 6d 20 49 44 3a 20 38 31 37 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12 13
                                Data Ascii: ExifII*V^(ifHH02100100,ASCIIPicsum ID: 817C
                                2022-11-24 13:24:35 UTC32INData Raw: 01 07 ff c4 00 19 01 00 03 01 01 01 00 00 00 00 00 00 00 00 00 00 00 00 01 02 03 04 05 ff da 00 0c 03 01 00 02 10 03 10 00 00 01 d7 26 5d 49 3a 73 b1 8d 66 9c 7a 2d 0d a7 71 50 d2 cd 5c 31 9a 67 e7 2a d2 8e 01 5b 9d 0a de 55 ee 1b b7 08 a5 75 9a 59 f8 35 e6 ea 5c 2a b9 af 83 1c 66 f3 e8 cf 67 5a 26 59 9a 30 ad 49 98 af a0 e8 e8 5b 65 5d 5a 51 18 9a d2 aa da dc 24 57 b7 11 c8 2c 7a aa c8 c2 c7 54 dd ac b1 fa c6 89 94 05 9a cb b0 4c d2 b2 69 60 24 17 02 41 62 0a 8a ae 59 6a 6a d2 24 42 1b 57 75 c6 81 5f 00 36 8d f2 4f 79 e9 f2 1b 34 cb 55 6b 75 15 53 5e ea f5 14 86 a2 5e b7 67 91 bd 91 95 c3 80 f1 23 94 5f 6a e1 46 a6 a3 bc db 98 ea 5b 28 6f 41 11 4c 8b c7 b5 b6 49 4a b8 79 6a d2 07 9b 2b 8f b5 46 96 1a 1b 28 68 d1 ec 73 93 02 d3 e7 ba c4 89 18 d9 ad 31 00
                                Data Ascii: &]I:sfz-qP\1g*[UuY5\*fgZ&Y0I[e]ZQ$W,zTLi`$AbYjj$BWu_6Oy4UkuS^^g#_jF[(oALIJyj+F(hs1
                                2022-11-24 13:24:35 UTC33INData Raw: 52 75 e5 95 56 64 24 ec 2e c0 f3 4f 5f 5f b0 59 8c dc 66 a5 74 eb d7 2b b2 aa d5 44 b4 27 c6 ce ae a9 14 d6 2a 32 bf c6 58 7a 8a 9f d2 9f cc fa cd 61 e1 d8 9a ed 16 57 c1 f6 d7 f7 68 f7 38 14 4a 5e 54 a2 c3 5c ad 77 29 87 17 f6 7f 90 3c 64 8e 6e ed 74 6a 51 76 1e 8e 68 fc 71 9a fb 02 a2 a8 ca c1 7b 30 03 8d 8d c3 4c d7 72 fa f2 97 8e 4f 54 d9 5d 3d 73 09 ca 86 5b 24 8d 7d da 71 1b a8 fc 73 76 6c a7 61 9e c4 a9 f9 df 6a 9a b3 f5 2d 5d 9d 93 43 3f b0 1c 8f a6 a7 b9 6e 5a fb 13 19 b9 b0 29 4f a5 37 c5 9b c9 4f e5 83 9e be f9 ef 95 a0 84 58 3d 9d ab df 15 7a 86 7e cc ea fa d6 85 c5 95 c7 81 a8 40 c5 d5 73 74 45 0b b7 b2 c6 ba f3 5d 48 2b b5 73 67 e7 84 fa 8d 3f 2b 53 4e 6c 03 b0 e2 8d fe 20 7e 41 4e 6f 0f ed f3 9f 89 04 1c 4d 4b 30 d5 fc 32 55 27 36 ff 00 84
                                Data Ascii: RuVd$.O__Yft+D'*2XzaWh8J^T\w)<dntjQvhq{0LrOT]=s[$}qsvlaj-]C?nZ)O7OX=z~@stE]H+sg?+SNl ~ANoMK02U'6
                                2022-11-24 13:24:35 UTC35INData Raw: c7 2d 2a b9 2e cd ba e3 75 34 4a 3e cd 12 8e 90 ec 93 55 48 a8 ed b6 25 c6 b2 7f 43 31 e4 59 a3 b2 7d 99 21 b1 d3 3b 17 f9 e3 91 fb 59 6f 48 2e 45 cb 13 d6 52 da 24 c7 8e 55 c0 af b1 49 7e 44 69 f6 4a 2e 2e 9f 8a 2e f8 d2 8d c4 96 de 51 24 fe 48 8c b8 1c 92 2e f9 14 2b 97 d1 d2 2c 4e b9 47 19 e3 7f 67 5e 11 d2 93 28 6b 83 1e 4f eb 21 c1 c7 98 9b 93 ec c9 1d ac c6 ad 96 e5 3a 27 4a 3f b3 a3 f6 26 e2 ed 13 4b 2c 77 c7 bf 04 85 15 5c 10 fb 47 27 09 1c 58 a4 d7 47 6f d8 e6 72 25 19 44 c7 97 6b 32 cf 73 f0 84 dc 1e e4 64 82 92 fe 48 68 90 85 c3 1c b9 37 0d e9 6f e8 72 b3 0c 1b e8 e2 4a d8 f0 f1 c1 54 ea 5e 30 c8 e0 ec 9c 63 7e bd 0b 49 f7 a5 59 1d 5a 13 a2 39 54 b8 90 a3 2b f5 23 24 fe 5e 2b c1 f7 a2 f1 7d e9 86 4e cc d1 5c 1f ff c4 00 25 11 00 02 02 02 02 02
                                Data Ascii: -*.u4J>UH%C1Y}!;YoH.ER$UI~DiJ...Q$H.+,NGg^(kO!:'J?&K,w\G'XGor%Dk2sdHh7orJT^0c~IYZ9T+#$^+}N\%
                                2022-11-24 13:24:35 UTC36INData Raw: e4 14 3e d7 58 dd ed 1c 39 07 ba 3c 39 1d 0e 0b 8c cb 7a 45 3e a0 b8 f4 ff 00 e6 3b ac 75 3a 3f 28 3d e3 2e 96 ec 9a 07 4e 7f 15 84 b9 4b c1 01 39 d4 9d de 35 94 5b 88 e2 3a 77 4f a4 e6 f1 0b 2e 02 27 86 70 d3 e5 63 7f 72 a7 53 11 6b f2 b2 81 58 3d a3 70 87 33 89 9c b7 72 7c f3 38 5c c6 43 60 9f 9e 97 fe 13 6a 36 ab 99 cb 17 d5 39 80 36 ad b2 9b 95 c3 2d 2d 0d d0 fe 88 89 50 e0 bb 94 1a da 80 4e eb 1b 8f c1 44 c7 75 86 05 ee e6 ac 33 dc b5 ca 79 db a0 8c 94 97 82 dc b2 d5 5c 82 75 80 b0 8c d7 1d d3 c2 68 cb de 72 2e 76 65 5d 47 98 2e 35 2e b1 f7 43 d2 3d 1e 30 bb da 30 ac 6f b3 46 41 10 dc 93 d8 e1 61 70 ed 97 19 dd 7f c2 2c 13 c4 8f 2e a8 d4 a9 d5 e5 1b 22 1a e0 d6 be e9 b5 04 60 7e cb da bd ce f2 34 aa b4 9a ec bc c5 34 fa a7 6c 17 58 67 fd ba 20 58 11
                                Data Ascii: >X9<9zE>;u:?(=.NK95[:wO.'pcrSkX=p3r|8\C`j696--PNDu3y\uhr.ve]G.5.C=00oFAap,."`~44lXg X
                                2022-11-24 13:24:35 UTC37INData Raw: ef 82 56 25 c3 6b 4b dd d9 12 39 5c 7c b9 84 29 d6 6c b9 bf fb 04 ea 98 b1 e8 2c 9d 55 af c2 06 72 8d d4 5a 7b ae 3d 4b 37 cb dc ac 1e 90 dc 7f b8 66 b1 51 38 c6 bb f8 60 70 15 1b df 44 f7 30 f3 b9 b0 06 de 1c 38 e6 42 9b 19 8e a1 cd 11 4a 9d b5 c2 b8 d5 32 1d 20 ae 21 e8 6e 5d ca e3 1c 87 47 f6 a6 a7 59 e8 5c 3a 96 0b f6 1c 8f ba 56 12 3a 0d 84 f5 39 5b 30 73 ee b1 68 8b 0a 14 d8 24 95 7b bb 32 47 8d b2 6f 32 24 89 e1 55 fb 15 51 8f e5 65 4f b2 14 bc c7 65 e9 43 50 c5 c3 ed 2d 4d 31 0e e9 5d ce 67 c0 3e 9f 5b 57 31 20 8d 75 58 1c 70 b7 de 19 7c d6 00 67 75 10 a9 d3 ff 00 1f e5 48 89 ce 54 8b 15 15 99 3f bd b9 ae 25 27 e2 6e e1 5c f8 00 c0 03 45 b2 41 a1 d0 c3 9a 6b 5a ee 9b 35 8d fe 51 6b 31 5b 51 92 14 00 2d a6 33 f8 23 fe 26 67 fd 23 5d c7 fd 9f da c2
                                Data Ascii: V%kK9\|)l,UrZ{=K7fQ8`pD08BJ2 !n]GY\:V:9[0sh${2Go2$UQeOeCP-M1]g>[W1 uXp|guHT?%'n\EAkZ5Qk1[Q-3#&g#]
                                2022-11-24 13:24:35 UTC39INData Raw: b4 90 4d 9e 9a 58 44 65 57 70 b1 5b 9c 1b 60 5e 21 cb cc b8 b0 70 11 82 dd 23 2a 52 92 2d d1 94 0e 4c e4 10 c1 4b 89 da 57 45 69 96 ce 21 8a df 0a 86 92 e8 e0 3c 44 f8 ad 9e d1 56 ea 5f 07 89 97 11 6c 78 f5 28 86 d5 39 8f ad c7 82 0c 3a e7 ca 67 27 51 a9 31 5a 8c 98 7c 39 33 7c c5 0c be 8e 6b dc 3b 4c 3c 06 52 22 cb c8 81 c4 02 d4 3c c0 89 13 36 1e 96 be 60 12 ce 06 07 d4 03 9b 15 dc f4 5c a6 3b 71 76 f6 f9 63 00 12 95 7b 0c b0 a5 30 ca 3c 50 96 b5 bf 31 2c ad 0a 6e 2d 8c 36 41 f0 4e 49 03 67 5f d9 ea 07 11 05 f9 a0 83 0d 9d b2 ea 5a 2d 42 e6 07 41 cc 04 37 41 c4 b3 6e 9d d3 e1 9d c4 ed 6e 61 76 4c b3 9f cc aa 8a 23 20 ed 85 a1 bf e9 8d 05 b8 35 50 a9 05 ed 6d e2 10 75 a8 df 7c 5b 6d 99 bd 9c 57 33 28 7e 67 5c c2 f8 83 e3 b7 a8 7a 21 a8 c0 40 da d7 93 2e
                                Data Ascii: MXDeWp[`^!p#*R-LKWEi!<DV_lx(9:g'Q1Z|93|k;L<R"<6`\;qvc{0<P1,n-6ANIg_Z-BA7AnnavL# 5Pmu|[mW3(~g\z!@.
                                2022-11-24 13:24:35 UTC40INData Raw: 19 e4 23 0d 10 d1 93 64 4b 0c 5e 61 ae 03 d4 0f 4c 1f 03 99 32 2c e3 8b 00 d0 2c 3e 6f e1 27 30 d9 31 70 7a 3a 76 6e 02 a2 ce eb 52 a1 43 78 25 43 5d 12 51 a0 cb 5c 40 b4 e0 06 9f 09 c2 71 17 88 0a dc 98 3b 45 15 75 1c 40 85 2d b7 ee 5c a4 4f d3 d4 ee 82 ed 48 3b 2f fe f8 ac 35 bc 86 ef 10 cd 03 b3 be 58 57 89 01 f0 12 d2 82 65 d9 2a 8d cc 73 57 12 d1 58 eb 95 42 df 23 1b 79 f1 e2 2f 2f c7 60 26 ff 00 fc 64 d7 ee 36 4e 3a 1d 3b 9b 22 5a 1c f5 14 60 b5 b6 d8 ee b8 39 8d d0 12 c8 77 d7 e6 5f 2d f5 62 38 c2 33 62 65 73 52 87 44 e5 4e 3d 91 ee ee 34 ff 00 62 85 cb 51 d9 29 ec d4 b7 2a 3f 05 59 f2 4b 33 7b 27 c7 53 6d 41 ff 00 55 4d 3d d7 ab fd 98 6e a3 fa e5 b8 d2 22 74 d8 bd 04 b2 99 2b 2e 20 4c 1c ca bb ef 17 54 fe 09 41 71 93 aa 1e e3 4f 96 5c 7c 7e 17 42
                                Data Ascii: #dK^aL2,,>o'01pz:vnRCx%C]Q\@q;Eu@-\OH;/5XWe*sWXB#y//`&d6N:;"Z`9w_-b83besRDN=4bQ)*?YK3{'SmAUM=n"t+. LTAqO\|~B
                                2022-11-24 13:24:35 UTC41INData Raw: 10 7a c2 d2 5e 76 d8 93 4f 23 b3 36 fe 93 fc 86 73 7b 0e 1c b7 85 ac a0 38 9d 83 b4 23 9c b7 96 9e 92 5d c8 05 8d 89 9f 76 ae a7 07 66 ec 3f 51 99 cb ca fd 8d c7 bf 56 f7 67 99 6b d8 0c a7 53 b1 05 c9 3e 37 9d b0 f5 6f e2 24 56 fb 30 08 96 42 df b8 e3 69 3f b7 03 fa d9 1b 7d 43 49 10 78 40 b4 ec c0 df 80 b6 d3 ed d7 3e 21 17 32 ea ec b0 c7 84 20 61 67 6f ec 3d db b4 7d e3 ff 00 56 c3 ad f5 63 a6 f2 c8 28 f9 f0 91 0f ec 83 7f 6e e0 db 04 d6 27 97 95 cc 88 ba 47 0c f8 cc 26 eb ac e5 a9 32 30 f6 d6 ed b0 f2 7b 2a 70 d3 eb 7b 92 9e bc 90 94 30 4f de ca 67 62 76 5c 4e 13 c9 15 8c cf 3b 27 25 e9 7b 7e 9b a7 dd 93 a8 53 0e 43 7b 97 9c 63 26 0b b2 81 60 1f 3e ec 7e 6e a2 07 da 3a dd bc f6 3d 26 65 89 6e 87 fc 25 9a d9 e2 3a 1f a9 d6 8e 5d f5 08 8c c0 4c 63 c9 91
                                Data Ascii: z^vO#6s{8#]vf?QVgkS>7o$V0Bi?}CIx@>!2 ago=}Vc(n'G&20{*p{0Ogbv\N;'%{~SC{c&`>~n:=&en%:]Lc
                                2022-11-24 13:24:35 UTC43INData Raw: e5 94 8a 8e 50 17 c5 e3 9b 8e ce 41 2d e9 ca e9 85 d0 a9 a8 10 48 d8 7c 46 9b a8 3f 2b b6 8b 3e 04 20 5c 19 f8 6e 2e e8 00 14 e0 bb ee 00 db 2a 07 29 5c be 25 a7 9b 00 23 8b d1 dc 62 b6 5e 0b b4 c6 c8 0d 69 bb c5 0b 2e 87 00 d2 1d aa 7f 12 c8 d4 82 6e 29 c6 e2 a9 72 ca 62 9d a5 6b ba 56 5f 36 2e fe 65 90 4a 07 5c 14 ba 83 40 2a 28 7e 46 70 5d 0b 69 e3 fe a1 c0 12 03 f0 ab f9 81 9b 25 8e 0b 6b c8 e1 a9 61 4f 7b 6d d3 08 18 14 44 e2 1d a8 45 0c 9c 0f fd 80 50 0a 2b b7 a6 f8 20 61 26 b1 97 a3 c8 b1 5d 88 60 d7 f3 fe 6a 10 91 ee 78 46 56 36 93 69 f8 20 07 e2 a3 4b ab 6a 69 f8 b5 68 f3 2e 0e f9 e7 e6 38 c0 2a bd 06 4f a9 6f 7b 85 af 21 e0 4f b9 80 85 39 2c 71 f2 2e b3 0c 8a 1b b0 a3 09 91 ee 6f 6a 57 08 35 60 da 70 73 0a 6e 1c 45 76 67 25 66 cf 98 0e 75 62 b4
                                Data Ascii: PA-H|F?+> \n.*)\%#b^i.n)rbkV_6.eJ\@*(~Fp]i%kaO{mDEP+ a&]`jxFV6i Kjih.8*Oo{!O9,q.ojW5`psnEvg%fub
                                2022-11-24 13:24:35 UTC44INData Raw: 2b e2 59 85 3a 14 37 55 d9 14 06 55 50 3e 9c 31 80 31 d3 d4 ca cd 9e 2f 00 39 7e 59 46 24 8a cd 4b c8 58 7e 25 f2 46 87 02 ee 98 c1 d6 e6 8f 98 9d 75 47 74 5c 4a 82 bc 56 0e ec d9 2e a4 b7 5e 3c 28 6d c8 70 b0 37 fc 32 8b 00 65 71 7f d4 5f cd aa 16 f1 08 2a 6d a5 a5 38 4e aa 55 69 46 ab 07 07 90 55 b4 7a c7 47 ac b5 a9 34 e8 1a 74 d4 7a 0b 43 01 22 9a f0 4c c0 2a 27 7d 99 ed 6d 99 4e f6 99 b5 8c 26 4b 17 3a 8c 2d 78 26 6a dd 69 12 ff 00 10 c5 09 05 d0 5d 2e 45 7f f6 67 36 2e 87 75 1d 6a 61 85 1c 93 52 36 ea 8b 6a 52 3d 6b 85 11 61 38 e2 fb bf 99 99 7f 15 63 e8 18 3e 82 13 c8 87 2c 0a b3 94 1b bd a0 8e a1 05 0b 2f 19 86 d6 05 a2 b7 cc e2 08 09 6b 05 c0 19 02 e5 8b ab 9c 94 69 e1 08 92 56 dc f6 bd af b1 a9 a5 bb b8 5a 4a f7 0c c5 98 83 6c 06 23 51 16 1a b9
                                Data Ascii: +Y:7UUP>11/9~YF$KX~%FuGt\JV.^<(mp72eq_*m8NUiFUzG4tzC"L*'}mN&K:-x&ji].Eg6.ujaR6jR=ka8c>,/kiVZJl#Q
                                2022-11-24 13:24:35 UTC45INData Raw: 51 c1 6a fa 84 9f 5c 0a a9 3b f1 85 55 4c 20 1f 66 a2 c5 c4 65 55 7c a5 2f a2 8b d3 f0 f3 16 e8 22 6b 69 7f 52 c4 49 f4 8e 08 9d 15 83 36 ef 90 75 03 05 96 13 56 d6 38 95 31 f3 81 d1 ec a1 80 9b 6e 2c 45 09 4c 43 5d fa 9e 63 1e f8 0c e5 94 3b af c5 c6 36 91 63 56 ec f2 28 b1 08 7f ac 4e 36 49 2d 82 89 a7 8a e3 31 fa 28 05 aa 55 f4 fe 00 e6 25 3d c6 e8 af eb 31 2f ea a8 b8 d2 ad 39 b1 2b 2a ea bb 34 b4 4e d2 96 3c 34 02 fa 4a b3 1a 67 9d e3 40 77 12 0e ca a9 38 03 8b f6 15 2c 87 37 30 61 3a 96 64 5f 90 81 09 65 24 c0 6c 7e a0 94 e9 46 51 57 9b 1a 5b c1 38 a2 25 66 33 c6 ff 00 71 eb b1 5a ca 2b f6 b1 3b 5e 2b 8a 6d f9 58 88 8a 11 d6 eb 6b f7 36 ed 8a 00 fa 70 7d ca 62 e2 f9 c0 01 7e 8d 79 12 c3 80 c3 7b c2 9f 08 28 80 73 ea b6 be a3 06 dd de b3 eb 8e a5 0d
                                Data Ascii: Qj\;UL feU|/"kiRI6uV81n,ELC]c;6cV(N6I-1(U%=1/9+*4N<4Jg@w8,70a:d_e$l~FQW[8%f3qZ+;^+mXk6p}b~y{(s
                                2022-11-24 13:24:35 UTC47INData Raw: 86 19 50 06 19 63 22 a6 00 bb e6 f7 71 f8 40 1e 3b 71 cf b0 fc 71 da 86 ca 0f 02 14 59 4b c1 17 a8 2a b5 8f 92 c2 84 65 90 4c 29 1f ec 3c 89 d2 6c 11 fc 73 e9 2e 80 6d 1c 63 a9 98 aa 5a c3 f2 73 38 a3 60 b5 ee b8 96 72 5a 6d 83 e3 11 32 a5 86 e9 2f a6 16 98 2e 14 07 55 84 ff d9
                                Data Ascii: Pc"q@;qqYK*eL)<ls.mcZs8`rZm2/.U


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                6192.168.2.349711108.167.161.63443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2022-11-24 13:24:36 UTC47OUTGET /favicon.ico HTTP/1.1
                                Host: 4293857.debournigerialtd.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://4293857.debournigerialtd.com/
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2022-11-24 13:24:36 UTC47INHTTP/1.1 404 Not Found
                                Date: Thu, 24 Nov 2022 13:24:36 GMT
                                Server: Apache
                                Upgrade: h2,h2c
                                Connection: Upgrade, close
                                Last-Modified: Sun, 19 Jun 2022 19:42:56 GMT
                                Accept-Ranges: bytes
                                Content-Length: 746
                                Vary: Accept-Encoding
                                Content-Type: text/html
                                2022-11-24 13:24:36 UTC47INData Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 78 2d 75 61 2d 63 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 34 30 34 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64
                                Data Ascii: <!doctype html><html lang="en"><head> <meta charset="utf-8"> <meta http-equiv="x-ua-compatible" content="ie=edge"> <title>404 Error</title> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta name="robots" content="noind


                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:0
                                Start time:14:24:28
                                Start date:24/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                Target ID:1
                                Start time:14:24:29
                                Start date:24/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1940 --field-trial-handle=1800,i,9322260435491250424,2161407301912172907,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                Target ID:2
                                Start time:14:24:30
                                Start date:24/11/2022
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://4293857.debournigerialtd.com/#YWxleGFuZGVyLmhhZ2VuQG1hbi1lcy5jb20=
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                No disassembly