Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://bit.ly/INQUIRYNO03875

Overview

General Information

Sample URL:https://bit.ly/INQUIRYNO03875
Analysis ID:1523265
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 3740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2248,i,17017703825588552381,14886282017310328945,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/INQUIRYNO03875" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://virtltra.us/loading.phpHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:55981 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:55979 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknownTCP traffic detected without corresponding DNS query: 4.175.87.197
Source: global trafficHTTP traffic detected: GET /INQUIRYNO03875 HTTP/1.1Host: bit.lyConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /loading.php HTTP/1.1Host: virtltra.usConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: virtltra.usConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://virtltra.us/loading.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rUuBHBGwzs6Nykd&MD=8AydGKhD HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rUuBHBGwzs6Nykd&MD=8AydGKhD HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: bit.ly
Source: global trafficDNS traffic detected: DNS query: virtltra.us
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 423Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 01 Oct 2024 09:34:44 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-EncodingLast-Modified: Mon, 09 Sep 2024 07:56:19 GMTCache-Control: max-age=14400CF-Cache-Status: MISSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Speculation-Rules: "/cdn-cgi/speculation"Server: cloudflareCF-RAY: 8cbb75678b395e71-EWR
Source: chromecache_109.2.drString found in binary or memory: https://virtltra.us/dl/INQUIRY059688.pdf.rar
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55983
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55981 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 55983 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55981
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.4:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.4:55981 version: TLS 1.2
Source: classification engineClassification label: clean0.win@22/6@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2248,i,17017703825588552381,14886282017310328945,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/INQUIRYNO03875"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2248,i,17017703825588552381,14886282017310328945,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://bit.ly/INQUIRYNO038752%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
virtltra.us
188.114.97.3
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      unknown
      bit.ly
      67.199.248.10
      truefalse
        unknown
        www.google.com
        172.217.18.4
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://bit.ly/INQUIRYNO03875false
              unknown
              https://a.nel.cloudflare.com/report/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3Dfalse
                unknown
                https://virtltra.us/loading.phpfalse
                  unknown
                  https://virtltra.us/favicon.icofalse
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://virtltra.us/dl/INQUIRY059688.pdf.rarchromecache_109.2.drfalse
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      172.217.18.4
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      188.114.97.3
                      virtltra.usEuropean Union
                      13335CLOUDFLARENETUSfalse
                      35.190.80.1
                      a.nel.cloudflare.comUnited States
                      15169GOOGLEUSfalse
                      67.199.248.10
                      bit.lyUnited States
                      396982GOOGLE-PRIVATE-CLOUDUSfalse
                      IP
                      192.168.2.4
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1523265
                      Start date and time:2024-10-01 11:33:45 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 3m 35s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:https://bit.ly/INQUIRYNO03875
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:8
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean0.win@22/6@8/6
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 142.250.185.163, 74.125.71.84, 142.250.186.142, 34.104.35.123, 142.250.185.234, 216.58.206.74, 172.217.18.10, 142.250.186.138, 142.250.185.170, 172.217.23.106, 142.250.184.202, 142.250.185.202, 142.250.185.138, 142.250.184.234, 142.250.186.106, 142.250.181.234, 142.250.185.74, 142.250.185.106, 172.217.16.202, 216.58.212.138, 93.184.221.240, 192.229.221.95, 13.95.31.18, 172.217.16.195, 216.58.206.46
                      • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, update.googleapis.com, clients.l.google.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtSetInformationFile calls found.
                      No simulations
                      InputOutput
                      URL: https://virtltra.us/loading.php Model: jbxai
                      {
                      "brand":[],
                      "contains_trigger_text":false,
                      "trigger_text":"",
                      "prominent_button_name":"Copy",
                      "text_input_field_labels":"unknown",
                      "pdf_icon_visible":false,
                      "has_visible_captcha":false,
                      "has_urgent_text":false,
                      "has_visible_qrcode":false}
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:HTML document, ASCII text, with very long lines (634)
                      Category:downloaded
                      Size (bytes):2966
                      Entropy (8bit):5.285494210168886
                      Encrypted:false
                      SSDEEP:48:Swbq+g8d7+CZirJpGs3kGKsljbMeiHr6Gn3kIVhlK6uHqIYPqNpAu07C3kIS73kL:SuC51MHr6G1LXCNpk7MesB
                      MD5:16F9BECDACAE380114A1C99BB4D528E7
                      SHA1:D7C4E5B15078C8A9EA1CF452BEAFBA8EB45C4C95
                      SHA-256:D9CD6DFCA94282619431285858508ADF7A4552A70C2BB6DC4F30B0C83D9B1615
                      SHA-512:41BD0206EB091E9649954A35EACBE0C1F56F04CAA49C68D5982C81F23EF3AEF688B775F0DE8EC57807DA354D8D4439D0E0F6484432814C1FA73C0EF7D7D013A8
                      Malicious:false
                      Reputation:low
                      URL:https://virtltra.us/favicon.ico
                      Preview:<!DOCTYPE html>.<html lang="en">..<head>...<meta charset="utf-8" />...<meta name="viewport" content="width=device-width, initial-scale=1" />...<title>Page Not Found</title>...<style>....body {.....background-color: #f5f5f5;.....margin-top: 8%;.....color: #5d5d5d;.....font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial,......"Noto Sans", sans-serif, "Apple Color Emoji", "Segoe UI Emoji", "Segoe UI Symbol",......"Noto Color Emoji";.....text-shadow: 0px 1px 1px rgba(255, 255, 255, 0.75);.....text-align: center;....}.....h1 {.....font-size: 2.45em;.....font-weight: 700;.....color: #5d5d5d;.....letter-spacing: -0.02em;.....margin-bottom: 30px;.....margin-top: 30px;....}......container {.....width: 100%;.....margin-right: auto;.....margin-left: auto;....}......animate__animated {.....animation-duration: 1s;.....animation-fill-mode: both;....}......animate__fadeIn {.....animation-name: fadeIn;....}......info {.....color: #5594cf;.....fill: #5594cf;....}
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):16
                      Entropy (8bit):3.75
                      Encrypted:false
                      SSDEEP:3:HdhkYn:R
                      MD5:F1F187E22DE12A01774C36D3F0DF9FA9
                      SHA1:C1F869A1CA62C4AAD0020ADC3FD7F2FA85163B61
                      SHA-256:6F99AD71696E2328CD909DDDCC3AB4CD831C5FF71112C4FC60AF03F82C296222
                      SHA-512:4CF15FA065B1CC37B9F21D372574AF3CCF174AE9A3E8FF38B4E4E8D486251B47049BF2B644AB2BE459F17860E7117F6FBF3D6A0EAF21C436A9931766A1B81186
                      Malicious:false
                      Reputation:low
                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAlGBLIMl2cxrhIFDQprpws=?alt=proto
                      Preview:CgkKBw0Ka6cLGgA=
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:HTML document, ASCII text
                      Category:downloaded
                      Size (bytes):2916
                      Entropy (8bit):4.151014603646156
                      Encrypted:false
                      SSDEEP:48:hd9PVhdUCCGiDPFWasCZGg9w6h2qNpGFOtL8:jdVhdZCGiDPFWasCZnNh2qyAL8
                      MD5:83B7C0F7CE08ABAEA173FE6CDBC1D688
                      SHA1:507F36A6926CEF65741A4003AAA3A2F7A026A20C
                      SHA-256:955D1D71F44F10EADD12BD778D5B1EAFB5E3DDD409D79316B38FB372EE8214A5
                      SHA-512:1C2D3C0F102DE27AD96DA3D482DC348F8A703E5FB65E9FCADDD41390A72B79E747E633E97507AFD2F0C142E448368D986BFB388D18ADA83315C3EFE10293702C
                      Malicious:false
                      Reputation:low
                      URL:https://virtltra.us/loading.php
                      Preview:. <!DOCTYPE html>. <html lang='en'>. <head>. <meta charset='UTF-8'>. <meta name='viewport' content='width=device-width, initial-scale=1.0'>. <meta http-equiv='X-UA-Compatible' content='ie=edge'>. <title>Browser Not Supported</title>. <style>. body {. font-family: Arial, sans-serif;. background-color: #f2f2f2;. margin: 0;. padding: 0;. display: flex;. justify-content: center;. align-items: center;. height: 100vh;. }. .container {. text-align: center;. background-color: white;. padding: 30px;. box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);. border-radius: 8px;. }. h1 {. color: #ff4d4d;. font-size: 24px;. }. p {. font-size: 16px;.
                      No static file info
                      TimestampSource PortDest PortSource IPDest IP
                      Oct 1, 2024 11:34:29.757225990 CEST49675443192.168.2.4173.222.162.32
                      Oct 1, 2024 11:34:39.365638018 CEST49675443192.168.2.4173.222.162.32
                      Oct 1, 2024 11:34:40.428699970 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.428756952 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.428818941 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.428864956 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.428930998 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.428987026 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.429068089 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.429084063 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.429208994 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.429241896 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.895015955 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.895334005 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.895358086 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.896248102 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.896266937 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.896339893 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.896889925 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.896940947 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.897351027 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.897411108 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.897562027 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.898603916 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.898683071 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.899436951 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.899527073 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.939461946 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.949465036 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:40.949486017 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:40.996818066 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.012522936 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:41.012981892 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:41.013298988 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.013319016 CEST4434973567.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:41.013351917 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.013382912 CEST49735443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.040635109 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.040662050 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.040720940 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.041049004 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.041060925 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.090394020 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.090416908 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:34:41.140955925 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:34:41.553097963 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.553570986 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.553584099 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.554434061 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.554495096 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.555629969 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.555656910 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.555681944 CEST44349737188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.555727005 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.555749893 CEST49737443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.555989981 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.556045055 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:41.556116104 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.556302071 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:41.556317091 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.336081028 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.379302979 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:42.726639986 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:42.726670027 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.727700949 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.727835894 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:42.729404926 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:42.729470968 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.729789972 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:42.729799032 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:42.739162922 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:42.739209890 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:42.739269018 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:42.740010023 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:42.740024090 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:42.772699118 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.084578991 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.084614038 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.084640980 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.084661961 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.084681034 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.084714890 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.084721088 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.084758997 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.089775085 CEST49740443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.089791059 CEST44349740188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.324225903 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.324275970 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.324510098 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.324821949 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.324836969 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.384901047 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:43.385235071 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:43.385253906 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:43.386878967 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:43.386950016 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:43.476105928 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:43.476160049 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:43.476229906 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:43.478068113 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:43.478099108 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:43.753971100 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:43.754446983 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:43.775692940 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.789163113 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.789190054 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.790168047 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.790249109 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.790683031 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.790704012 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.790743113 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.790750980 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.790924072 CEST44349743188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.790987015 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.791007996 CEST49743443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.791295052 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.791402102 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.791481972 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.791812897 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:43.791848898 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:43.797135115 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:43.797154903 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:43.843166113 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:44.135816097 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.135910034 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.150461912 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.150523901 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.150748014 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.193810940 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.259322882 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.269166946 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:44.269207001 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.269542933 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.318806887 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:44.335781097 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.340226889 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:44.340364933 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.349893093 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:44.383407116 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.395401001 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.525065899 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.525114059 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.525185108 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.534756899 CEST49744443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:44.534794092 CEST44349744184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:44.669207096 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.669255018 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.669358015 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:44.669400930 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.669491053 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:44.670582056 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:45.115814924 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.115855932 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.115928888 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.116676092 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.116689920 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.213099957 CEST49745443192.168.2.4188.114.97.3
                      Oct 1, 2024 11:34:45.213171005 CEST44349745188.114.97.3192.168.2.4
                      Oct 1, 2024 11:34:45.337640047 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:45.337660074 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:45.337752104 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:45.338383913 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:45.338396072 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:45.576793909 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.577066898 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.577086926 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.577949047 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.578013897 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.807966948 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.808135033 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.808159113 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.855429888 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.940645933 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.940722942 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.941149950 CEST49748443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.941165924 CEST4434974835.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.943240881 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.943327904 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.943438053 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.943892002 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:45.943928003 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:45.977816105 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:45.977885962 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:45.980715990 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:45.980721951 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:45.980968952 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:45.981972933 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:46.027431011 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:46.255112886 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:46.255175114 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:46.255321980 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:46.258697987 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:46.258711100 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:46.258719921 CEST49749443192.168.2.4184.28.90.27
                      Oct 1, 2024 11:34:46.258723974 CEST44349749184.28.90.27192.168.2.4
                      Oct 1, 2024 11:34:46.416407108 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.416909933 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:46.416958094 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.417303085 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.417782068 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:46.417850018 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.418275118 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:46.463406086 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.556807041 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.556869984 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:46.556963921 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:46.557327986 CEST49750443192.168.2.435.190.80.1
                      Oct 1, 2024 11:34:46.557367086 CEST4434975035.190.80.1192.168.2.4
                      Oct 1, 2024 11:34:52.453212023 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:52.453263044 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:52.453454971 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:52.455192089 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:52.455212116 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:53.065551996 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:53.065632105 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:53.072132111 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:53.072149038 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:53.072525024 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:53.115453959 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:53.278934002 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:53.279016018 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:53.279083014 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:53.390353918 CEST49741443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:34:53.390374899 CEST44349741172.217.18.4192.168.2.4
                      Oct 1, 2024 11:34:54.046273947 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.091403008 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250725031 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250780106 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250799894 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250843048 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.250859022 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250864029 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.250890970 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250905991 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.250910997 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.250937939 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.250962019 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.251096964 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.251163960 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:54.251179934 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.251274109 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:54.251367092 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:55.028029919 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:55.028057098 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:34:55.028110981 CEST49751443192.168.2.420.12.23.50
                      Oct 1, 2024 11:34:55.028119087 CEST4434975120.12.23.50192.168.2.4
                      Oct 1, 2024 11:35:20.654062986 CEST5597953192.168.2.41.1.1.1
                      Oct 1, 2024 11:35:20.658860922 CEST53559791.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:20.658927917 CEST5597953192.168.2.41.1.1.1
                      Oct 1, 2024 11:35:20.658946991 CEST5597953192.168.2.41.1.1.1
                      Oct 1, 2024 11:35:20.663713932 CEST53559791.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:21.103780031 CEST53559791.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:21.108949900 CEST5597953192.168.2.41.1.1.1
                      Oct 1, 2024 11:35:21.114347935 CEST53559791.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:21.114413023 CEST5597953192.168.2.41.1.1.1
                      Oct 1, 2024 11:35:26.091114998 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:35:26.091173887 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:35:31.606893063 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:31.606955051 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:31.607053041 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:31.607670069 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:31.607701063 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.410626888 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.410867929 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.520466089 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.520529032 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.521545887 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.559752941 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.603446960 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821130991 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821182013 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821202040 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821239948 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821264029 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.821278095 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821304083 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.821316004 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.821346998 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.821369886 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.822181940 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.822247982 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.822261095 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.822297096 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.822333097 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.822443962 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.822499990 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.832722902 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.832776070 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:32.832808971 CEST55981443192.168.2.44.175.87.197
                      Oct 1, 2024 11:35:32.832827091 CEST443559814.175.87.197192.168.2.4
                      Oct 1, 2024 11:35:41.264097929 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:35:41.264300108 CEST4434973667.199.248.10192.168.2.4
                      Oct 1, 2024 11:35:41.264475107 CEST49736443192.168.2.467.199.248.10
                      Oct 1, 2024 11:35:42.750504017 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:42.750538111 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:42.750600100 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:42.751081944 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:42.751096964 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:43.385802984 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:43.386542082 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:43.386558056 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:43.387656927 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:43.389264107 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:43.389440060 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:43.443533897 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:47.131180048 CEST4972380192.168.2.4199.232.210.172
                      Oct 1, 2024 11:35:47.131306887 CEST4972480192.168.2.4199.232.210.172
                      Oct 1, 2024 11:35:47.136548996 CEST8049723199.232.210.172192.168.2.4
                      Oct 1, 2024 11:35:47.136641026 CEST4972380192.168.2.4199.232.210.172
                      Oct 1, 2024 11:35:47.136931896 CEST8049724199.232.210.172192.168.2.4
                      Oct 1, 2024 11:35:47.136986971 CEST4972480192.168.2.4199.232.210.172
                      Oct 1, 2024 11:35:53.302908897 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:53.302989960 CEST44355983172.217.18.4192.168.2.4
                      Oct 1, 2024 11:35:53.303057909 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:55.227104902 CEST55983443192.168.2.4172.217.18.4
                      Oct 1, 2024 11:35:55.227148056 CEST44355983172.217.18.4192.168.2.4
                      TimestampSource PortDest PortSource IPDest IP
                      Oct 1, 2024 11:34:39.048937082 CEST53521671.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:39.051923990 CEST53615881.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:40.229794979 CEST53628431.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:40.420525074 CEST5254853192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:40.420799017 CEST5524653192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:40.427242994 CEST53525481.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:40.428006887 CEST53552461.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:41.015525103 CEST5271153192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:41.015656948 CEST5289953192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:41.029083014 CEST53528991.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:41.040112019 CEST53527111.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:42.727823973 CEST5040153192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:42.728111029 CEST4998253192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:42.734905958 CEST53504011.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:42.737196922 CEST53499821.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:43.272130966 CEST53644061.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:45.107480049 CEST6274853192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:45.108016014 CEST5272953192.168.2.41.1.1.1
                      Oct 1, 2024 11:34:45.114818096 CEST53627481.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:45.114856005 CEST53527291.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:57.530591011 CEST53562541.1.1.1192.168.2.4
                      Oct 1, 2024 11:34:58.699629068 CEST138138192.168.2.4192.168.2.255
                      Oct 1, 2024 11:35:16.608586073 CEST53577521.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:20.653593063 CEST53557121.1.1.1192.168.2.4
                      Oct 1, 2024 11:35:38.453789949 CEST53523711.1.1.1192.168.2.4
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Oct 1, 2024 11:34:40.420525074 CEST192.168.2.41.1.1.10x39cfStandard query (0)bit.lyA (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:40.420799017 CEST192.168.2.41.1.1.10x3e4aStandard query (0)bit.ly65IN (0x0001)false
                      Oct 1, 2024 11:34:41.015525103 CEST192.168.2.41.1.1.10xc16eStandard query (0)virtltra.usA (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:41.015656948 CEST192.168.2.41.1.1.10x875aStandard query (0)virtltra.us65IN (0x0001)false
                      Oct 1, 2024 11:34:42.727823973 CEST192.168.2.41.1.1.10x1aa0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:42.728111029 CEST192.168.2.41.1.1.10x73b5Standard query (0)www.google.com65IN (0x0001)false
                      Oct 1, 2024 11:34:45.107480049 CEST192.168.2.41.1.1.10x74cStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:45.108016014 CEST192.168.2.41.1.1.10x9426Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Oct 1, 2024 11:34:40.427242994 CEST1.1.1.1192.168.2.40x39cfNo error (0)bit.ly67.199.248.10A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:40.427242994 CEST1.1.1.1192.168.2.40x39cfNo error (0)bit.ly67.199.248.11A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:41.029083014 CEST1.1.1.1192.168.2.40x875aNo error (0)virtltra.us65IN (0x0001)false
                      Oct 1, 2024 11:34:41.040112019 CEST1.1.1.1192.168.2.40xc16eNo error (0)virtltra.us188.114.97.3A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:41.040112019 CEST1.1.1.1192.168.2.40xc16eNo error (0)virtltra.us188.114.96.3A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:42.734905958 CEST1.1.1.1192.168.2.40x1aa0No error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:42.737196922 CEST1.1.1.1192.168.2.40x73b5No error (0)www.google.com65IN (0x0001)false
                      Oct 1, 2024 11:34:45.114818096 CEST1.1.1.1192.168.2.40x74cNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:34:54.063791037 CEST1.1.1.1192.168.2.40x4e71No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Oct 1, 2024 11:34:54.063791037 CEST1.1.1.1192.168.2.40x4e71No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                      Oct 1, 2024 11:35:07.452122927 CEST1.1.1.1192.168.2.40x2fbeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Oct 1, 2024 11:35:07.452122927 CEST1.1.1.1192.168.2.40x2fbeNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                      • bit.ly
                      • virtltra.us
                      • https:
                      • fs.microsoft.com
                      • a.nel.cloudflare.com
                      • slscr.update.microsoft.com
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.44973567.199.248.104433004C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:40 UTC663OUTGET /INQUIRYNO03875 HTTP/1.1
                      Host: bit.ly
                      Connection: keep-alive
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-10-01 09:34:41 UTC493INHTTP/1.1 301 Moved Permanently
                      Server: nginx
                      Date: Tue, 01 Oct 2024 09:34:40 GMT
                      Content-Type: text/html; charset=utf-8
                      Content-Length: 118
                      Cache-Control: private, max-age=90
                      Content-Security-Policy: referrer always;
                      Location: https://virtltra.us/loading.php
                      Referrer-Policy: unsafe-url
                      Set-Cookie: _bit=o919yE-c6c9c187395a8ce2ea-00e; Domain=bit.ly; Expires=Sun, 30 Mar 2025 09:34:40 GMT
                      Via: 1.1 google
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-10-01 09:34:41 UTC118INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 42 69 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 76 69 72 74 6c 74 72 61 2e 75 73 2f 6c 6f 61 64 69 6e 67 2e 70 68 70 22 3e 6d 6f 76 65 64 20 68 65 72 65 3c 2f 61 3e 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                      Data Ascii: <html><head><title>Bitly</title></head><body><a href="https://virtltra.us/loading.php">moved here</a></body></html>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.449740188.114.97.34433004C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:42 UTC665OUTGET /loading.php HTTP/1.1
                      Host: virtltra.us
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-10-01 09:34:43 UTC606INHTTP/1.1 200 OK
                      Date: Tue, 01 Oct 2024 09:34:43 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Vary: Accept-Encoding
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=xy9r9swQGhAg7CnScBCi6OjkBQFdAZaWWSuIbGjXc7YY8igInWCkjw2JNbuRNcRL34AwTyIertxFIN4PLW7YIFKe7B2cJxHyAiXhP3aY%2BtMmkF9nrPpl2PX%2FivERGA%3D%3D"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Speculation-Rules: "/cdn-cgi/speculation"
                      Server: cloudflare
                      CF-RAY: 8cbb755d6d39440b-EWR
                      2024-10-01 09:34:43 UTC763INData Raw: 62 36 34 0d 0a 0a 20 20 20 20 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 74 6d 6c 20 6c 61 6e 67 3d 27 65 6e 27 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 27 55 54 46 2d 38 27 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 27 76 69 65 77 70 6f 72 74 27 20 63 6f 6e 74 65 6e 74 3d 27 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 27 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 27 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 27 20 63 6f 6e 74 65 6e 74 3d 27 69 65 3d 65 64 67 65 27 3e 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 42 72 6f 77 73 65 72 20 4e 6f
                      Data Ascii: b64 <!DOCTYPE html> <html lang='en'> <head> <meta charset='UTF-8'> <meta name='viewport' content='width=device-width, initial-scale=1.0'> <meta http-equiv='X-UA-Compatible' content='ie=edge'> <title>Browser No
                      2024-10-01 09:34:43 UTC1369INData Raw: 73 68 61 64 6f 77 3a 20 30 20 34 70 78 20 38 70 78 20 72 67 62 61 28 30 2c 20 30 2c 20 30 2c 20 30 2e 31 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 20 38 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 68 31 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 66 66 34 64 34 64 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 32 34 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 36 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a
                      Data Ascii: shadow: 0 4px 8px rgba(0, 0, 0, 0.1); border-radius: 8px; } h1 { color: #ff4d4d; font-size: 24px; } p { font-size: 16px; color:
                      2024-10-01 09:34:43 UTC791INData Raw: 20 20 20 2f 2f 20 47 65 74 20 74 68 65 20 74 65 78 74 20 66 69 65 6c 64 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 76 61 72 20 63 6f 70 79 54 65 78 74 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 64 6f 77 6e 6c 6f 61 64 4c 69 6e 6b 27 29 3b 0a 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 2f 2f 20 53 65 6c 65 63 74 20 74 68 65 20 74 65 78 74 20 66 69 65 6c 64 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 70 79 54 65 78 74 2e 73 65 6c 65 63 74 28 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 70 79 54 65 78 74 2e 73 65 74 53 65 6c 65 63 74 69 6f 6e 52 61 6e 67 65 28 30 2c 20 39 39 39 39 39 29 3b 20 2f 2f 20 46 6f 72 20 6d 6f 62 69 6c 65 20 64 65 76 69 63 65 73 0a 0a 20 20 20 20
                      Data Ascii: // Get the text field var copyText = document.getElementById('downloadLink'); // Select the text field copyText.select(); copyText.setSelectionRange(0, 99999); // For mobile devices
                      2024-10-01 09:34:43 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.449744184.28.90.27443
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:44 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      Accept-Encoding: identity
                      User-Agent: Microsoft BITS/7.8
                      Host: fs.microsoft.com
                      2024-10-01 09:34:44 UTC467INHTTP/1.1 200 OK
                      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                      Content-Type: application/octet-stream
                      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                      Server: ECAcc (lpl/EF06)
                      X-CID: 11
                      X-Ms-ApiVersion: Distribute 1.2
                      X-Ms-Region: prod-neu-z1
                      Cache-Control: public, max-age=198666
                      Date: Tue, 01 Oct 2024 09:34:44 GMT
                      Connection: close
                      X-CID: 2


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.449745188.114.97.34433004C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:44 UTC589OUTGET /favicon.ico HTTP/1.1
                      Host: virtltra.us
                      Connection: keep-alive
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      sec-ch-ua-platform: "Windows"
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: image
                      Referer: https://virtltra.us/loading.php
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-10-01 09:34:44 UTC690INHTTP/1.1 404 Not Found
                      Date: Tue, 01 Oct 2024 09:34:44 GMT
                      Content-Type: text/html; charset=utf-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Vary: Accept-Encoding
                      Last-Modified: Mon, 09 Sep 2024 07:56:19 GMT
                      Cache-Control: max-age=14400
                      CF-Cache-Status: MISS
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3D"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Speculation-Rules: "/cdn-cgi/speculation"
                      Server: cloudflare
                      CF-RAY: 8cbb75678b395e71-EWR
                      2024-10-01 09:34:44 UTC679INData Raw: 62 39 36 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 09 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 09 09 3c 74 69 74 6c 65 3e 50 61 67 65 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 09 09 3c 73 74 79 6c 65 3e 0a 09 09 09 62 6f 64 79 20 7b 0a 09 09 09 09 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 35 66 35 66 35 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 38 25 3b 0a 09 09 09 09 63 6f
                      Data Ascii: b96<!DOCTYPE html><html lang="en"><head><meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Page Not Found</title><style>body {background-color: #f5f5f5;margin-top: 8%;co
                      2024-10-01 09:34:44 UTC1369INData Raw: 6f 74 74 6f 6d 3a 20 33 30 70 78 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 33 30 70 78 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 63 6f 6e 74 61 69 6e 65 72 20 7b 0a 09 09 09 09 77 69 64 74 68 3a 20 31 30 30 25 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 72 69 67 68 74 3a 20 61 75 74 6f 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 61 75 74 6f 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 61 6e 69 6d 61 74 65 5f 5f 61 6e 69 6d 61 74 65 64 20 7b 0a 09 09 09 09 61 6e 69 6d 61 74 69 6f 6e 2d 64 75 72 61 74 69 6f 6e 3a 20 31 73 3b 0a 09 09 09 09 61 6e 69 6d 61 74 69 6f 6e 2d 66 69 6c 6c 2d 6d 6f 64 65 3a 20 62 6f 74 68 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 61 6e 69 6d 61 74 65 5f 5f 66 61 64 65 49 6e 20 7b 0a 09 09 09 09 61 6e 69 6d 61 74 69 6f 6e 2d 6e 61 6d
                      Data Ascii: ottom: 30px;margin-top: 30px;}.container {width: 100%;margin-right: auto;margin-left: auto;}.animate__animated {animation-duration: 1s;animation-fill-mode: both;}.animate__fadeIn {animation-nam
                      2024-10-01 09:34:44 UTC925INData Raw: 36 20 35 2e 32 38 36 2d 32 2e 33 35 33 20 31 32 2e 34 31 35 20 32 2e 37 31 35 20 31 36 2e 32 35 38 6c 33 34 2e 36 39 39 20 32 36 2e 33 31 63 35 2e 32 30 35 20 33 2e 39 34 37 20 31 32 2e 36 32 31 20 33 2e 30 30 38 20 31 36 2e 36 36 35 2d 32 2e 31 32 32 20 31 37 2e 38 36 34 2d 32 32 2e 36 35 38 20 33 30 2e 31 31 33 2d 33 35 2e 37 39 37 20 35 37 2e 33 30 33 2d 33 35 2e 37 39 37 20 32 30 2e 34 32 39 20 30 20 34 35 2e 36 39 38 20 31 33 2e 31 34 38 20 34 35 2e 36 39 38 20 33 32 2e 39 35 38 20 30 20 31 34 2e 39 37 36 2d 31 32 2e 33 36 33 20 32 32 2e 36 36 37 2d 33 32 2e 35 33 34 20 33 33 2e 39 37 36 43 32 34 37 2e 31 32 38 20 32 33 38 2e 35 32 38 20 32 31 36 20 32 35 34 2e 39 34 31 20 32 31 36 20 32 39 36 76 34 63 30 20 36 2e 36 32 37 20 35 2e 33 37 33 20 31 32
                      Data Ascii: 6 5.286-2.353 12.415 2.715 16.258l34.699 26.31c5.205 3.947 12.621 3.008 16.665-2.122 17.864-22.658 30.113-35.797 57.303-35.797 20.429 0 45.698 13.148 45.698 32.958 0 14.976-12.363 22.667-32.534 33.976C247.128 238.528 216 254.941 216 296v4c0 6.627 5.373 12
                      2024-10-01 09:34:44 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.44974835.190.80.14433004C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:45 UTC532OUTOPTIONS /report/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3D HTTP/1.1
                      Host: a.nel.cloudflare.com
                      Connection: keep-alive
                      Origin: https://virtltra.us
                      Access-Control-Request-Method: POST
                      Access-Control-Request-Headers: content-type
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-10-01 09:34:45 UTC336INHTTP/1.1 200 OK
                      Content-Length: 0
                      access-control-max-age: 86400
                      access-control-allow-methods: POST, OPTIONS
                      access-control-allow-origin: *
                      access-control-allow-headers: content-length, content-type
                      date: Tue, 01 Oct 2024 09:34:45 GMT
                      Via: 1.1 google
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.449749184.28.90.27443
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:45 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      Accept-Encoding: identity
                      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                      Range: bytes=0-2147483646
                      User-Agent: Microsoft BITS/7.8
                      Host: fs.microsoft.com
                      2024-10-01 09:34:46 UTC515INHTTP/1.1 200 OK
                      ApiVersion: Distribute 1.1
                      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                      Content-Type: application/octet-stream
                      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                      Server: ECAcc (lpl/EF06)
                      X-CID: 11
                      X-Ms-ApiVersion: Distribute 1.2
                      X-Ms-Region: prod-weu-z1
                      Cache-Control: public, max-age=198608
                      Date: Tue, 01 Oct 2024 09:34:46 GMT
                      Content-Length: 55
                      Connection: close
                      X-CID: 2
                      2024-10-01 09:34:46 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      6192.168.2.44975035.190.80.14433004C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:46 UTC478OUTPOST /report/v4?s=DV6%2BiCC%2BXCwEA6jQgkj7dZJonigM2%2BlahE6QBRqVbd3FxwvMaQzIRdAjTwa8u34dtQoEkpC9zTGdlxzAcyj9GOVyXQ0kbOdSBfos4eR0%2F54j1cNIzBpSgIeGU8jP7Q%3D%3D HTTP/1.1
                      Host: a.nel.cloudflare.com
                      Connection: keep-alive
                      Content-Length: 423
                      Content-Type: application/reports+json
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-10-01 09:34:46 UTC423OUTData Raw: 5b 7b 22 61 67 65 22 3a 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 37 38 30 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 76 69 72 74 6c 74 72 61 2e 75 73 2f 6c 6f 61 64 69 6e 67 2e 70 68 70 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 38 38 2e 31 31 34 2e 39 37 2e 33 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c
                      Data Ascii: [{"age":1,"body":{"elapsed_time":1780,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://virtltra.us/loading.php","sampling_fraction":1.0,"server_ip":"188.114.97.3","status_code":404,"type":"http.error"},"type":"network-error",
                      2024-10-01 09:34:46 UTC168INHTTP/1.1 200 OK
                      Content-Length: 0
                      date: Tue, 01 Oct 2024 09:34:46 GMT
                      Via: 1.1 google
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      7192.168.2.44975120.12.23.50443
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:34:54 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rUuBHBGwzs6Nykd&MD=8AydGKhD HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                      Host: slscr.update.microsoft.com
                      2024-10-01 09:34:54 UTC560INHTTP/1.1 200 OK
                      Cache-Control: no-cache
                      Pragma: no-cache
                      Content-Type: application/octet-stream
                      Expires: -1
                      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                      ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                      MS-CorrelationId: 3e7695af-df98-4592-bff1-5e452e5bed22
                      MS-RequestId: c8367a18-1a4c-4162-8829-2860bb614499
                      MS-CV: +IKv57KtzUeaDSKp.0
                      X-Microsoft-SLSClientCache: 2880
                      Content-Disposition: attachment; filename=environment.cab
                      X-Content-Type-Options: nosniff
                      Date: Tue, 01 Oct 2024 09:34:53 GMT
                      Connection: close
                      Content-Length: 24490
                      2024-10-01 09:34:54 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                      Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                      2024-10-01 09:34:54 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                      Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      8192.168.2.4559814.175.87.197443
                      TimestampBytes transferredDirectionData
                      2024-10-01 09:35:32 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rUuBHBGwzs6Nykd&MD=8AydGKhD HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                      Host: slscr.update.microsoft.com
                      2024-10-01 09:35:32 UTC560INHTTP/1.1 200 OK
                      Cache-Control: no-cache
                      Pragma: no-cache
                      Content-Type: application/octet-stream
                      Expires: -1
                      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                      ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                      MS-CorrelationId: 2c14da1c-b4ae-4080-aaec-fcb63a4de066
                      MS-RequestId: 6202912c-c57d-47e9-b97b-fc9cefd715ee
                      MS-CV: I8ABo99CtECBqRMW.0
                      X-Microsoft-SLSClientCache: 1440
                      Content-Disposition: attachment; filename=environment.cab
                      X-Content-Type-Options: nosniff
                      Date: Tue, 01 Oct 2024 09:35:32 GMT
                      Connection: close
                      Content-Length: 30005
                      2024-10-01 09:35:32 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                      Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                      2024-10-01 09:35:32 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                      Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:05:34:33
                      Start date:01/10/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:2
                      Start time:05:34:36
                      Start date:01/10/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2248,i,17017703825588552381,14886282017310328945,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:3
                      Start time:05:34:39
                      Start date:01/10/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/INQUIRYNO03875"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      No disassembly