Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t

Overview

General Information

Sample URL:https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
Analysis ID:1500121
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected suspicious crossdomain redirect

Classification

  • System is w10x64
  • chrome.exe (PID: 2076 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3752 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2336,i,26614888388893994,4439860193939050144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: www.google.com to https://megashopmedellin.com/kaku/z8xvf/captcha/aw5mb0bud2nvbxmuy29t
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1Host: emp.eduyield.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET ////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1Host: google.com.Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1Host: google.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1Host: www.google.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1Host: megashopmedellin.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: megashopmedellin.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ= HTTP/1.1Host: elvisgroup.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://megashopmedellin.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: elvisgroup.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: emp.eduyield.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: megashopmedellin.com
Source: global trafficDNS traffic detected: DNS query: elvisgroup.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 27 Aug 2024 20:41:04 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 708date: Tue, 27 Aug 2024 20:41:06 GMTalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@18/4@14/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2336,i,26614888388893994,4439860193939050144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2336,i,26614888388893994,4439860193939050144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t0%Avira URL Cloudsafe
https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=0%Avira URL Cloudsafe
https://elvisgroup.com/favicon.ico0%Avira URL Cloudsafe
https://google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t0%Avira URL Cloudsafe
https://megashopmedellin.com/favicon.ico0%Avira URL Cloudsafe
https://google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.206
truefalse
    unknown
    emp.eduyield.com
    3.211.51.78
    truefalse
      unknown
      elvisgroup.com
      148.163.69.161
      truefalse
        unknown
        www.google.com
        142.250.186.164
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            megashopmedellin.com
            107.182.225.19
            truefalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tfalse
              • Avira URL Cloud: safe
              unknown
              https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=false
              • Avira URL Cloud: safe
              unknown
              https://megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tfalse
                unknown
                https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=#info@nwcoms.comfalse
                  unknown
                  https://megashopmedellin.com/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  https://elvisgroup.com/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  https://google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://www.google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29tfalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.186.46
                    unknownUnited States
                    15169GOOGLEUSfalse
                    148.163.69.161
                    elvisgroup.comUnited States
                    53755IOFLOODUSfalse
                    107.182.225.19
                    megashopmedellin.comUnited States
                    32780HOSTINGSERVICES-INCUSfalse
                    142.250.181.238
                    unknownUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    3.211.51.78
                    emp.eduyield.comUnited States
                    14618AMAZON-AESUSfalse
                    142.250.186.164
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1500121
                    Start date and time:2024-08-27 22:40:05 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 59s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@18/4@14/8
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.181.227, 142.250.110.84, 142.250.185.206, 34.104.35.123, 40.68.123.157, 93.184.221.240, 192.229.221.95, 13.95.31.18, 20.242.39.171, 142.250.186.99
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:very short file (no magic)
                    Category:downloaded
                    Size (bytes):1
                    Entropy (8bit):0.0
                    Encrypted:false
                    SSDEEP:3:v:v
                    MD5:68B329DA9893E34099C7D8AD5CB9C940
                    SHA1:ADC83B19E793491B1C6EA0FD8B46CD9F32E592FC
                    SHA-256:01BA4719C80B6FE911B091A7C05124B64EEECE964E09C058EF8F9805DACA546B
                    SHA-512:BE688838CA8686E5C90689BF2AB585CEF1137C999B48C70B92F67A5C34DC15697B5D11C982ED6D71BE1E1E7F7B4E0733884AA97C3F7A339A8ED03577CF74BE09
                    Malicious:false
                    Reputation:low
                    URL:https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=
                    Preview:.
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:downloaded
                    Size (bytes):315
                    Entropy (8bit):5.0572271090563765
                    Encrypted:false
                    SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
                    MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
                    SHA1:A82190FC530C265AA40A045C21770D967F4767B8
                    SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
                    SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
                    Malicious:false
                    Reputation:low
                    URL:https://megashopmedellin.com/favicon.ico
                    Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Aug 27, 2024 22:40:48.706701994 CEST49675443192.168.2.4173.222.162.32
                    Aug 27, 2024 22:40:58.471143007 CEST49675443192.168.2.4173.222.162.32
                    Aug 27, 2024 22:40:59.458053112 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458086967 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:40:59.458153963 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458360910 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458368063 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:40:59.458436012 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458560944 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458570957 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:40:59.458769083 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:40:59.458776951 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.145410061 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.145679951 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.145699024 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.146694899 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.146712065 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.146770000 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.146919012 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.146925926 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.147887945 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.147917032 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.147948980 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.148000002 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.148403883 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.148408890 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.148852110 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.148915052 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.189311028 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.189317942 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.189445972 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.235996008 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.272597075 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.272669077 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.272726059 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.273072958 CEST49736443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:00.273082972 CEST443497363.211.51.78192.168.2.4
                    Aug 27, 2024 22:41:00.292632103 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.292649031 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.292710066 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.292897940 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.292907000 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.935405970 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:00.935430050 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:00.935502052 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:00.935787916 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:00.935800076 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:00.949100971 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.949471951 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.949493885 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.949882030 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.949953079 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.950566053 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.950625896 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.951535940 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.951591969 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:00.951745033 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:00.951751947 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:01.006716967 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:01.383654118 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:01.383730888 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:01.383776903 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:01.385114908 CEST49739443192.168.2.4142.250.186.46
                    Aug 27, 2024 22:41:01.385128021 CEST44349739142.250.186.46192.168.2.4
                    Aug 27, 2024 22:41:01.397294998 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:01.397325993 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:01.397396088 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:01.397636890 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:01.397650003 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:01.585038900 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:01.589315891 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:01.589328051 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:01.590219975 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:01.590270996 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:01.593637943 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:01.593693018 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:01.642668962 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:01.642679930 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:01.689255953 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:02.029234886 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.029489040 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.029501915 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.030082941 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.030139923 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.031194925 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.031243086 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.366974115 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:02.367002010 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:02.367070913 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:02.369587898 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:02.369597912 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:02.400815010 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.400990963 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.401000977 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.448499918 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.449237108 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.449244022 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.500127077 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.592596054 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.592868090 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.593090057 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.594754934 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.594763994 CEST44349741142.250.181.238192.168.2.4
                    Aug 27, 2024 22:41:02.594814062 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.594814062 CEST49741443192.168.2.4142.250.181.238
                    Aug 27, 2024 22:41:02.598150969 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:02.640499115 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:02.844705105 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:02.845118999 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:02.848135948 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:02.852032900 CEST49740443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:41:02.852046013 CEST44349740142.250.186.164192.168.2.4
                    Aug 27, 2024 22:41:03.017463923 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.017617941 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.042517900 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.042535067 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.042675018 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.043028116 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.043041945 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.044035912 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.044044971 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.044431925 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.100039959 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.103804111 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.148508072 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.290626049 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.290689945 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.290822983 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.290853024 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.290873051 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.290873051 CEST49742443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.290879011 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.290884972 CEST44349742184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.319953918 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.319981098 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.320204973 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.320382118 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:03.320390940 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.514147043 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.514388084 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.514404058 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.515373945 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.515434980 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.759577036 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.759680986 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.759896994 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.759912968 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.801158905 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.857008934 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.857367039 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.857423067 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.900933027 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.900944948 CEST44349743107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:03.900958061 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.901005983 CEST49743443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:03.953764915 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:03.953826904 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.134253979 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.134270906 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.134500027 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.138720036 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.180502892 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.324975967 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.325589895 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.325642109 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.425975084 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.425992966 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.426064014 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.428131104 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.428181887 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:04.428237915 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.430119038 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.430130005 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.430383921 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.430403948 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:04.431813002 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.431868076 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:04.431926012 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.432236910 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:04.432251930 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:04.524719954 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.524728060 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.524763107 CEST49744443192.168.2.4184.28.90.27
                    Aug 27, 2024 22:41:04.524766922 CEST44349744184.28.90.27192.168.2.4
                    Aug 27, 2024 22:41:04.886284113 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.900044918 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.900058985 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.900633097 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.906451941 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.906511068 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:04.906790972 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:04.948504925 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:05.002739906 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:05.002876997 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:05.003110886 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:05.005633116 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.012051105 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.012077093 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.013161898 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.013365030 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.016828060 CEST49745443192.168.2.4107.182.225.19
                    Aug 27, 2024 22:41:05.016845942 CEST44349745107.182.225.19192.168.2.4
                    Aug 27, 2024 22:41:05.083889008 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.084781885 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.084809065 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.088779926 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.088923931 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.404804945 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.404975891 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.404983044 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.405090094 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.408044100 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.408061028 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.458770990 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.458786011 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.458801031 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.502165079 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.795423985 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.795610905 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:05.795664072 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.946145058 CEST49747443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:05.946177959 CEST44349747148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:06.029247046 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:06.076498032 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:06.186292887 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:06.186342955 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:06.186384916 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:06.187458038 CEST49746443192.168.2.4148.163.69.161
                    Aug 27, 2024 22:41:06.187474966 CEST44349746148.163.69.161192.168.2.4
                    Aug 27, 2024 22:41:45.193080902 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:41:45.193099022 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:42:01.247883081 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:01.247883081 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:42:01.247911930 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:01.248018026 CEST443497353.211.51.78192.168.2.4
                    Aug 27, 2024 22:42:01.248106003 CEST49735443192.168.2.43.211.51.78
                    Aug 27, 2024 22:42:01.248106956 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:01.248363018 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:01.248378038 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:02.108740091 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:02.109240055 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:02.109258890 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:02.109545946 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:02.110171080 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:02.110223055 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:02.162419081 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:12.125976086 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:12.126029968 CEST44349757142.250.186.164192.168.2.4
                    Aug 27, 2024 22:42:12.126084089 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:12.131933928 CEST49757443192.168.2.4142.250.186.164
                    Aug 27, 2024 22:42:12.131947994 CEST44349757142.250.186.164192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Aug 27, 2024 22:40:57.734273911 CEST53531581.1.1.1192.168.2.4
                    Aug 27, 2024 22:40:57.742696047 CEST53560731.1.1.1192.168.2.4
                    Aug 27, 2024 22:40:58.810563087 CEST53620131.1.1.1192.168.2.4
                    Aug 27, 2024 22:40:59.427778959 CEST6444953192.168.2.41.1.1.1
                    Aug 27, 2024 22:40:59.427901983 CEST5770053192.168.2.41.1.1.1
                    Aug 27, 2024 22:40:59.444044113 CEST53644491.1.1.1192.168.2.4
                    Aug 27, 2024 22:40:59.457571030 CEST53577001.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.275969982 CEST5694353192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.276110888 CEST6037153192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.283112049 CEST53603711.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.283149004 CEST53569431.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.284935951 CEST5648753192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.285101891 CEST5065353192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.291673899 CEST53564871.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.292243958 CEST53506531.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.926888943 CEST4933753192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.927423000 CEST5430353192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:00.933718920 CEST53493371.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:00.934750080 CEST53543031.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:01.388917923 CEST5936053192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:01.389270067 CEST5483953192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:01.395757914 CEST53593601.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:01.395956039 CEST53548391.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:02.852849007 CEST6144853192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:02.856034994 CEST6163453192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:03.038569927 CEST53616341.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:03.038852930 CEST53614481.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:04.108676910 CEST4967053192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:04.109267950 CEST4926553192.168.2.41.1.1.1
                    Aug 27, 2024 22:41:04.398426056 CEST53492651.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:04.399393082 CEST53496701.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:16.012368917 CEST53641071.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:17.931685925 CEST138138192.168.2.4192.168.2.255
                    Aug 27, 2024 22:41:35.185461998 CEST53598221.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:56.746978998 CEST53588681.1.1.1192.168.2.4
                    Aug 27, 2024 22:41:57.686336994 CEST53524681.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Aug 27, 2024 22:40:59.427778959 CEST192.168.2.41.1.1.10x4194Standard query (0)emp.eduyield.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:40:59.427901983 CEST192.168.2.41.1.1.10xf2adStandard query (0)emp.eduyield.com65IN (0x0001)false
                    Aug 27, 2024 22:41:00.275969982 CEST192.168.2.41.1.1.10x40ceStandard query (0)google.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.276110888 CEST192.168.2.41.1.1.10x525bStandard query (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:00.284935951 CEST192.168.2.41.1.1.10xd3feStandard query (0)google.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.285101891 CEST192.168.2.41.1.1.10xf2feStandard query (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:00.926888943 CEST192.168.2.41.1.1.10x7506Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.927423000 CEST192.168.2.41.1.1.10x87f8Standard query (0)www.google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:01.388917923 CEST192.168.2.41.1.1.10xb6c4Standard query (0)google.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:01.389270067 CEST192.168.2.41.1.1.10xbee5Standard query (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:02.852849007 CEST192.168.2.41.1.1.10x13a8Standard query (0)megashopmedellin.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:02.856034994 CEST192.168.2.41.1.1.10x3408Standard query (0)megashopmedellin.com65IN (0x0001)false
                    Aug 27, 2024 22:41:04.108676910 CEST192.168.2.41.1.1.10xa84fStandard query (0)elvisgroup.comA (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:04.109267950 CEST192.168.2.41.1.1.10x40ccStandard query (0)elvisgroup.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Aug 27, 2024 22:40:59.444044113 CEST1.1.1.1192.168.2.40x4194No error (0)emp.eduyield.com3.211.51.78A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:40:59.444044113 CEST1.1.1.1192.168.2.40x4194No error (0)emp.eduyield.com107.23.245.109A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:40:59.444044113 CEST1.1.1.1192.168.2.40x4194No error (0)emp.eduyield.com54.165.150.163A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.283112049 CEST1.1.1.1192.168.2.40x525bNo error (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:00.283149004 CEST1.1.1.1192.168.2.40x40ceNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.291673899 CEST1.1.1.1192.168.2.40xd3feNo error (0)google.com142.250.186.46A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.292243958 CEST1.1.1.1192.168.2.40xf2feNo error (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:00.933718920 CEST1.1.1.1192.168.2.40x7506No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:00.934750080 CEST1.1.1.1192.168.2.40x87f8No error (0)www.google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:01.395757914 CEST1.1.1.1192.168.2.40xb6c4No error (0)google.com142.250.181.238A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:01.395956039 CEST1.1.1.1192.168.2.40xbee5No error (0)google.com65IN (0x0001)false
                    Aug 27, 2024 22:41:03.038852930 CEST1.1.1.1192.168.2.40x13a8No error (0)megashopmedellin.com107.182.225.19A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:04.399393082 CEST1.1.1.1192.168.2.40xa84fNo error (0)elvisgroup.com148.163.69.161A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:12.477685928 CEST1.1.1.1192.168.2.40xc325No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 27, 2024 22:41:12.477685928 CEST1.1.1.1192.168.2.40xc325No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:25.592143059 CEST1.1.1.1192.168.2.40x5ad6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 27, 2024 22:41:25.592143059 CEST1.1.1.1192.168.2.40x5ad6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:41:50.279447079 CEST1.1.1.1192.168.2.40x92a0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 27, 2024 22:41:50.279447079 CEST1.1.1.1192.168.2.40x92a0No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Aug 27, 2024 22:42:09.751270056 CEST1.1.1.1192.168.2.40x1e5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Aug 27, 2024 22:42:09.751270056 CEST1.1.1.1192.168.2.40x1e5No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    • emp.eduyield.com
                    • google.com.
                    • google.com
                    • www.google.com
                    • megashopmedellin.com
                    • fs.microsoft.com
                    • https:
                      • elvisgroup.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.4497363.211.51.784433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:00 UTC824OUTGET /el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1
                    Host: emp.eduyield.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:00 UTC263INHTTP/1.1 303 See Other
                    Date: Tue, 27 Aug 2024 20:41:00 GMT
                    Content-Type: text/html; charset=UTF-8
                    Content-Length: 0
                    Connection: close
                    Server: nginx/1.27.0
                    Location: http://google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449739142.250.186.464433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:00 UTC723OUTGET ////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1
                    Host: google.com.
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:01 UTC359INHTTP/1.1 301 Moved Permanently
                    Cache-Control: private
                    Content-Type: text/html; charset=UTF-8
                    Referrer-Policy: no-referrer
                    Location: https://google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    Content-Length: 282
                    Date: Tue, 27 Aug 2024 20:41:01 GMT
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-08-27 20:41:01 UTC282INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 6d 70 2f 73 2f 6d 65 67 61 73 68 6f 70 6d 65 64 65 6c 6c 69 6e 2e 63 6f 6d 2f 6b 61 6b 75 2f 7a 38 78 76 66 2f 63 61 70 74 63 68 61 2f 61 57 35 6d 62 30 42 75 64 32 4e 76 62 58 4d 75 59 32 39 74 22 3e
                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>301 Moved</TITLE></HEAD><BODY><H1>301 Moved</H1>The document has moved<A HREF="https://google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t">


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449741142.250.181.2384433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:02 UTC719OUTGET /amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1
                    Host: google.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:02 UTC903INHTTP/1.1 301 Moved Permanently
                    Location: https://www.google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    Content-Type: text/html; charset=UTF-8
                    Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-pk202NECsyuTdQMdUeg71A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                    Permissions-Policy: unload=()
                    Date: Tue, 27 Aug 2024 20:41:02 GMT
                    Expires: Thu, 26 Sep 2024 20:41:02 GMT
                    Cache-Control: public, max-age=2592000
                    Server: gws
                    Content-Length: 286
                    X-XSS-Protection: 0
                    X-Frame-Options: SAMEORIGIN
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-08-27 20:41:02 UTC286INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 6d 70 2f 73 2f 6d 65 67 61 73 68 6f 70 6d 65 64 65 6c 6c 69 6e 2e 63 6f 6d 2f 6b 61 6b 75 2f 7a 38 78 76 66 2f 63 61 70 74 63 68 61 2f 61 57 35 6d 62 30 42 75 64 32 4e 76 62 58 4d 75 59 32
                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>301 Moved</TITLE></HEAD><BODY><H1>301 Moved</H1>The document has moved<A HREF="https://www.google.com/amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449740142.250.186.1644433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:02 UTC723OUTGET /amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:02 UTC1210INHTTP/1.1 302 Found
                    Location: https://megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    Cache-Control: private
                    X-Robots-Tag: noindex
                    Content-Type: text/html; charset=UTF-8
                    Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-Xskl7DHlabjkXeeId8sQsg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                    Permissions-Policy: unload=()
                    P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                    Date: Tue, 27 Aug 2024 20:41:02 GMT
                    Server: gws
                    Content-Length: 265
                    X-XSS-Protection: 0
                    X-Frame-Options: SAMEORIGIN
                    Set-Cookie: NID=517=oZsvOHRhguEgWKY2HWw5CCEnuaQ8clMCudbZaXDkv3ilo39SqH7c_9G7Q05-kLRsBZwXXUdFD36-rigiGnlz_VFiVO8JziXdOFMHdJae-hGpFb6Qi0isfYdZNYVaE-jGkaRYQZ7glLF7SaZZbUTll4o1J6EmJL5UySZ2eXhRoZvLA1-PZ8RFfw; expires=Wed, 26-Feb-2025 20:41:02 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-08-27 20:41:02 UTC180INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 6d 65 67 61
                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://mega
                    2024-08-27 20:41:02 UTC85INData Raw: 73 68 6f 70 6d 65 64 65 6c 6c 69 6e 2e 63 6f 6d 2f 6b 61 6b 75 2f 7a 38 78 76 66 2f 63 61 70 74 63 68 61 2f 61 57 35 6d 62 30 42 75 64 32 4e 76 62 58 4d 75 59 32 39 74 22 3e 68 65 72 65 3c 2f 41 3e 2e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                    Data Ascii: shopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t">here</A>.</BODY></HTML>


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.449742184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:03 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-08-27 20:41:03 UTC466INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF17)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-weu-z1
                    Cache-Control: public, max-age=68363
                    Date: Tue, 27 Aug 2024 20:41:03 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.449743107.182.225.194433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:03 UTC702OUTGET /kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t HTTP/1.1
                    Host: megashopmedellin.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:03 UTC302INHTTP/1.1 200 OK
                    Date: Tue, 27 Aug 2024 20:41:03 GMT
                    Server: Apache
                    refresh: 0;url=https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=#info@nwcoms.com
                    Vary: User-Agent
                    Content-Length: 0
                    Connection: close
                    Content-Type: text/html; charset=UTF-8


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    6192.168.2.449744184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:04 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-08-27 20:41:04 UTC514INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF06)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-weu-z1
                    Cache-Control: public, max-age=72276
                    Date: Tue, 27 Aug 2024 20:41:04 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-08-27 20:41:04 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    7192.168.2.449745107.182.225.194433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:04 UTC635OUTGET /favicon.ico HTTP/1.1
                    Host: megashopmedellin.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:04 UTC164INHTTP/1.1 404 Not Found
                    Date: Tue, 27 Aug 2024 20:41:04 GMT
                    Server: Apache
                    Content-Length: 315
                    Connection: close
                    Content-Type: text/html; charset=iso-8859-1
                    2024-08-27 20:41:04 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    8192.168.2.449747148.163.69.1614433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:05 UTC761OUTGET /n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ= HTTP/1.1
                    Host: elvisgroup.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-Dest: document
                    Referer: https://megashopmedellin.com/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:05 UTC312INHTTP/1.1 200 OK
                    Connection: close
                    content-type: text/html; charset=UTF-8
                    content-length: 1
                    date: Tue, 27 Aug 2024 20:41:05 GMT
                    alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
                    2024-08-27 20:41:05 UTC1INData Raw: 0a
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    9192.168.2.449746148.163.69.1614433752C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-08-27 20:41:06 UTC662OUTGET /favicon.ico HTTP/1.1
                    Host: elvisgroup.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://elvisgroup.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9U21GRWVqWT0mdWlkPVVTRVIyOTA3MjAyNFUyNjA3MjkxMQ=
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-08-27 20:41:06 UTC396INHTTP/1.1 404 Not Found
                    Connection: close
                    cache-control: private, no-cache, no-store, must-revalidate, max-age=0
                    pragma: no-cache
                    content-type: text/html
                    content-length: 708
                    date: Tue, 27 Aug 2024 20:41:06 GMT
                    alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
                    2024-08-27 20:41:06 UTC708INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 34 34 34 3b 20 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 3a 20 6e 6f 72 6d 61 6c 20 31 34 70 78 2f 32 30 70 78 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73
                    Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title></head><body style="color: #444; margin:0;font: normal 14px/20px Arial, Helvetica, s


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:16:40:51
                    Start date:27/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:16:40:55
                    Start date:27/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2336,i,26614888388893994,4439860193939050144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:16:40:58
                    Start date:27/08/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://emp.eduyield.com/el?aid=2ekidda0e6c-1865-11ef-80aa-0217a07992df&rid=33766156&pid=771868&cid=497&dest=google.com.////amp/s/megashopmedellin.com/kaku/z8xvf/captcha/aW5mb0Bud2NvbXMuY29t"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly