Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome

Overview

General Information

Sample URL:http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%
Analysis ID:1523414
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 996 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 4424 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2036,i,11928365704172145029,5500621587362827193,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 7128 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://mc.yandex.com/watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1OD...HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5 HTTP/1.1Host: mc.yandex.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE%3D%3Aadb%3A1%3Arqnl%3A1%3Ast%3A1727725998%3At%3AMy%20tabs%20%40%20Ultimate-Guitar.Com&t=gdpr%2814%29clc%280-0-0%29rqnt%281%29aw%281%29cdl%28na%29eco%283178884%29ti%283%29&wmode=5&redirnss=1 HTTP/1.1Host: mc.yandex.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-full-version: "117.0.5938.134"sec-ch-ua-arch: "x86"sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-model: ""sec-ch-ua-bitness: "64"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: yabs-sid=1878560681727789838; i=IlFdxYK55eCnSvvYyqhPHpzvctSIUnrbCamnXpw+wWdbsabRkVHkNbiW2vglr9r19amg72hopIfxwq92D8++j18B164=; yandexuid=1804440101727789838; yuidss=1804440101727789838; ymex=1759325838.yrts.1727789838#1759325838.yrtsi.1727789838; receive-cookie-deprecation=1; bh=Ej8iR29vZ2xlIENocm9tZSI7dj0iMTI1IiwiQ2hyb21pdW0iO3Y9IjEyNSIsIk5vdC5BL0JyYW5kIjt2PSIyNCIaBSJ4ODYiIhAiMTI1LjAuNjQyMi4xMTMiKgI/MDoJIldpbmRvd3MiQggiMTAuMC4wIkoEIjY0IlJcIkdvb2dsZSBDaHJvbWUiO3Y9IjEyNS4wLjY0MjIuMTEzIiwiQ2hyb21pdW0iO3Y9IjEyNS4wLjY0MjIuMTEzIiwiTm90LkEvQnJhbmQiO3Y9IjI0LjAuMC4wIiI=
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mc.yandex.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "117.0.5938.134"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mc.yandex.com/watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE%3D%3Aadb%3A1%3Arqnl%3A1%3Ast%3A1727725998%3At%3AMy%20tabs%20%40%20Ultimate-Guitar.Com&t=gdpr%2814%29clc%280-0-0%29rqnt%281%29aw%281%29cdl%28na%29eco%283178884%29ti%283%29&wmode=5&redirnss=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: yabs-sid=1878560681727789838; i=IlFdxYK55eCnSvvYyqhPHpzvctSIUnrbCamnXpw+wWdbsabRkVHkNbiW2vglr9r19amg72hopIfxwq92D8++j18B164=; yandexuid=1804440101727789838; yuidss=1804440101727789838; ymex=1759325838.yrts.1727789838#1759325838.yrtsi.1727789838; receive-cookie-deprecation=1; bh=Ej8iR29vZ2xlIENocm9tZSI7dj0iMTI1IiwiQ2hyb21pdW0iO3Y9IjEyNSIsIk5vdC5BL0JyYW5kIjt2PSIyNCIaBSJ4ODYiIhAiMTI1LjAuNjQyMi4xMTMiKgI/MDoJIldpbmRvd3MiQggiMTAuMC4wIkoEIjY0IlJcIkdvb2dsZSBDaHJvbWUiO3Y9IjEyNS4wLjY0MjIuMTEzIiwiQ2hyb21pdW0iO3Y9IjEyNS4wLjY0MjIuMTEzIiwiTm90LkEvQnJhbmQiO3Y9IjI0LjAuMC4wIiI=
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5 HTTP/1.1Host: mc.yandex.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: mc.yandex.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not foundConnection: CloseContent-Length: 0Date: Tue, 01 Oct 2024 13:37:20 GMTSet-Cookie: _yasc=RGN87xBGxCjQgE6UYC7Cq73tVfyg5pyKJb50nrlPL/ybUbPdaA67HTfaqHU6bShynmjWGIM=; domain=.yandex.com; path=/; expires=Fri, 29 Sep 2034 13:37:20 GMT; secureStrict-Transport-Security: max-age=31536000X-XSS-Protection: 1; mode=block
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/0@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2036,i,11928365704172145029,5500621587362827193,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2036,i,11928365704172145029,5500621587362827193,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
mc.yandex.ru
77.88.21.119
truefalse
    unknown
    www.google.com
    142.250.186.164
    truefalse
      unknown
      default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
      84.201.210.34
      truefalse
        unknown
        mc.yandex.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5false
            unknown
            http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5false
              unknown
              https://mc.yandex.com/watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE%3D%3Aadb%3A1%3Arqnl%3A1%3Ast%3A1727725998%3At%3AMy%20tabs%20%40%20Ultimate-Guitar.Com&t=gdpr%2814%29clc%280-0-0%29rqnt%281%29aw%281%29cdl%28na%29eco%283178884%29ti%283%29&wmode=5&redirnss=1false
                unknown
                https://mc.yandex.com/favicon.icofalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  77.88.21.119
                  mc.yandex.ruRussian Federation
                  13238YANDEXRUfalse
                  142.250.186.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  87.250.250.119
                  unknownRussian Federation
                  13238YANDEXRUfalse
                  IP
                  192.168.2.7
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1523414
                  Start date and time:2024-10-01 15:36:18 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 12s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:16
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@17/0@6/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.184.227, 142.250.184.206, 66.102.1.84, 34.104.35.123, 13.85.23.86, 93.184.221.240, 52.165.164.15, 88.221.110.91, 88.221.110.121, 142.250.186.163
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, time.windows.com, a767.dspw65.akamai.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5
                  No simulations
                  InputOutput
                  URL: https://mc.yandex.com/watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224 Model: jbxai
                  {
                  "brand":[],
                  "contains_trigger_text":false,
                  "trigger_text":"",
                  "prominent_button_name":"unknown",
                  "text_input_field_labels":"unknown",
                  "pdf_icon_visible":false,
                  "has_visible_captcha":false,
                  "has_urgent_text":false,
                  "has_visible_qrcode":false}
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 1, 2024 15:37:06.838134050 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:07.150360107 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:07.759629011 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:08.744003057 CEST49674443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:08.744045019 CEST49675443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:08.790890932 CEST49672443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:08.962733030 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:11.369007111 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:15.385504007 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:15.822073936 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:16.243047953 CEST4970480192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:16.243463039 CEST4970580192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:16.247924089 CEST804970477.88.21.119192.168.2.7
                  Oct 1, 2024 15:37:16.247991085 CEST4970480192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:16.248229980 CEST4970480192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:16.248281002 CEST804970577.88.21.119192.168.2.7
                  Oct 1, 2024 15:37:16.248332024 CEST4970580192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:16.253045082 CEST804970477.88.21.119192.168.2.7
                  Oct 1, 2024 15:37:16.253271103 CEST804970477.88.21.119192.168.2.7
                  Oct 1, 2024 15:37:16.293338060 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:16.620600939 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:17.074949026 CEST804970477.88.21.119192.168.2.7
                  Oct 1, 2024 15:37:17.085762024 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.085802078 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.085880041 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.086087942 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.086102009 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.181528091 CEST4970480192.168.2.777.88.21.119
                  Oct 1, 2024 15:37:17.794466019 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.877547979 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.877583027 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.878793001 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.878808975 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.878863096 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.881464958 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.881547928 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.881937981 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:17.881948948 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:17.976675034 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:17.976703882 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:17.976850986 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:17.977390051 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:17.977406025 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:17.994313955 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.103686094 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.103761911 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.103784084 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.103847027 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.103981972 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.110188961 CEST49708443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.110215902 CEST4434970887.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.112552881 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.112606049 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.112685919 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.113662958 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.113679886 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.119874954 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:18.354521990 CEST49674443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:18.354545116 CEST49675443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:18.445363998 CEST49672443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:18.612564087 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:18.613632917 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:18.613643885 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:18.614667892 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:18.614734888 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:18.617789030 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:18.617858887 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:18.667181969 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:18.667191982 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:18.712333918 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:18.857431889 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.883775949 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.883807898 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.884376049 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.885417938 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.885510921 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:18.886101007 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:18.886133909 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.223474026 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.223587036 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.223648071 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:19.225481987 CEST49710443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:19.225505114 CEST4434971087.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.273338079 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:19.273395061 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:19.273505926 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:19.275279999 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:19.275304079 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:19.640866041 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:19.640907049 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.641025066 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:19.641499996 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:19.641520023 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:19.915971994 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:19.916053057 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:19.922384977 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:19.922401905 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:19.922677040 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:19.994594097 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.371462107 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.433410883 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:20.433440924 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.434088945 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.491955996 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:20.492274046 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.492547989 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:20.492588043 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.575942993 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.623409033 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.732280970 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.732359886 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.732404947 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:20.742408037 CEST49712443192.168.2.787.250.250.119
                  Oct 1, 2024 15:37:20.742443085 CEST4434971287.250.250.119192.168.2.7
                  Oct 1, 2024 15:37:20.760699987 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.760782957 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.760859013 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.763396978 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.763427019 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.763438940 CEST49711443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.763446093 CEST44349711184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.815953016 CEST44349698104.98.116.138192.168.2.7
                  Oct 1, 2024 15:37:20.816070080 CEST49698443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:20.840743065 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.840787888 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:20.840871096 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.843348026 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:20.843363047 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.100280046 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:21.477926016 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.478010893 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.514228106 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.514260054 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.514508009 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.557565928 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.576595068 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.619405985 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.762286901 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.762368917 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:21.762482882 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.916357040 CEST49713443192.168.2.7184.28.90.27
                  Oct 1, 2024 15:37:21.916388988 CEST44349713184.28.90.27192.168.2.7
                  Oct 1, 2024 15:37:25.899888992 CEST49671443192.168.2.7204.79.197.203
                  Oct 1, 2024 15:37:27.056287050 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:37:28.511415005 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:28.511590004 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:28.511663914 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:28.819717884 CEST49709443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:37:28.819756985 CEST44349709142.250.186.164192.168.2.7
                  Oct 1, 2024 15:37:29.372078896 CEST49698443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:29.380351067 CEST49715443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:29.380387068 CEST44349715104.98.116.138192.168.2.7
                  Oct 1, 2024 15:37:29.380672932 CEST49715443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:29.381297112 CEST49715443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:37:29.381309032 CEST44349715104.98.116.138192.168.2.7
                  Oct 1, 2024 15:37:29.451133966 CEST44349698104.98.116.138192.168.2.7
                  Oct 1, 2024 15:37:38.962882042 CEST49677443192.168.2.720.50.201.200
                  Oct 1, 2024 15:38:01.260294914 CEST4970580192.168.2.777.88.21.119
                  Oct 1, 2024 15:38:01.265244961 CEST804970577.88.21.119192.168.2.7
                  Oct 1, 2024 15:38:02.087974072 CEST4970480192.168.2.777.88.21.119
                  Oct 1, 2024 15:38:02.093168974 CEST804970477.88.21.119192.168.2.7
                  Oct 1, 2024 15:38:12.225495100 CEST44349715104.98.116.138192.168.2.7
                  Oct 1, 2024 15:38:12.225719929 CEST49715443192.168.2.7104.98.116.138
                  Oct 1, 2024 15:38:16.780776024 CEST4970580192.168.2.777.88.21.119
                  Oct 1, 2024 15:38:16.786017895 CEST804970577.88.21.119192.168.2.7
                  Oct 1, 2024 15:38:16.786073923 CEST4970580192.168.2.777.88.21.119
                  Oct 1, 2024 15:38:18.027359009 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.027415991 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.027739048 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.027951956 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.027971029 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.657416105 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.697802067 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.724138021 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.724158049 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.724700928 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.728831053 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:18.728907108 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:18.775917053 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:28.562935114 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:28.563009977 CEST44349721142.250.186.164192.168.2.7
                  Oct 1, 2024 15:38:28.563066006 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:29.279937029 CEST49721443192.168.2.7142.250.186.164
                  Oct 1, 2024 15:38:29.279982090 CEST44349721142.250.186.164192.168.2.7
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 1, 2024 15:37:14.589405060 CEST53525231.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:14.593647003 CEST53561351.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:15.553845882 CEST53611701.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:16.004033089 CEST5426653192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:16.004184008 CEST6324153192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:16.241987944 CEST53542661.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:16.242054939 CEST53632411.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:17.078242064 CEST5126053192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:17.078577995 CEST5127153192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:17.085078001 CEST53512601.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:17.085297108 CEST53512711.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:17.966973066 CEST5409153192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:17.967556000 CEST5563253192.168.2.71.1.1.1
                  Oct 1, 2024 15:37:17.974910021 CEST53540911.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:17.975517035 CEST53556321.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:20.669895887 CEST123123192.168.2.720.101.57.9
                  Oct 1, 2024 15:37:20.840949059 CEST12312320.101.57.9192.168.2.7
                  Oct 1, 2024 15:37:22.201412916 CEST123123192.168.2.720.101.57.9
                  Oct 1, 2024 15:37:22.370843887 CEST12312320.101.57.9192.168.2.7
                  Oct 1, 2024 15:37:32.549885988 CEST53512741.1.1.1192.168.2.7
                  Oct 1, 2024 15:37:51.440505981 CEST53521511.1.1.1192.168.2.7
                  Oct 1, 2024 15:38:14.219186068 CEST53632831.1.1.1192.168.2.7
                  Oct 1, 2024 15:38:14.472850084 CEST53549341.1.1.1192.168.2.7
                  Oct 1, 2024 15:38:15.890729904 CEST138138192.168.2.7192.168.2.255
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Oct 1, 2024 15:37:16.004033089 CEST192.168.2.71.1.1.10x6ce6Standard query (0)mc.yandex.comA (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:16.004184008 CEST192.168.2.71.1.1.10x7c6Standard query (0)mc.yandex.com65IN (0x0001)false
                  Oct 1, 2024 15:37:17.078242064 CEST192.168.2.71.1.1.10x2e5aStandard query (0)mc.yandex.comA (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.078577995 CEST192.168.2.71.1.1.10x85b4Standard query (0)mc.yandex.com65IN (0x0001)false
                  Oct 1, 2024 15:37:17.966973066 CEST192.168.2.71.1.1.10x74c3Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.967556000 CEST192.168.2.71.1.1.10x9430Standard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Oct 1, 2024 15:37:16.241987944 CEST1.1.1.1192.168.2.70x6ce6No error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                  Oct 1, 2024 15:37:16.241987944 CEST1.1.1.1192.168.2.70x6ce6No error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:16.241987944 CEST1.1.1.1192.168.2.70x6ce6No error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:16.241987944 CEST1.1.1.1192.168.2.70x6ce6No error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:16.241987944 CEST1.1.1.1192.168.2.70x6ce6No error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:16.242054939 CEST1.1.1.1192.168.2.70x7c6No error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085078001 CEST1.1.1.1192.168.2.70x2e5aNo error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085078001 CEST1.1.1.1192.168.2.70x2e5aNo error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085078001 CEST1.1.1.1192.168.2.70x2e5aNo error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085078001 CEST1.1.1.1192.168.2.70x2e5aNo error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085078001 CEST1.1.1.1192.168.2.70x2e5aNo error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.085297108 CEST1.1.1.1192.168.2.70x85b4No error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                  Oct 1, 2024 15:37:17.974910021 CEST1.1.1.1192.168.2.70x74c3No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:37:17.975517035 CEST1.1.1.1192.168.2.70x9430No error (0)www.google.com65IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.34A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.37A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.19A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.22A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.23A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.39A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.36A (IP address)IN (0x0001)false
                  Oct 1, 2024 15:38:27.941484928 CEST1.1.1.1192.168.2.70xec5eNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.26A (IP address)IN (0x0001)false
                  • mc.yandex.com
                  • https:
                  • fs.microsoft.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.74970477.88.21.119804424C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 1, 2024 15:37:16.248229980 CEST1402OUTGET /watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5 HTTP/1.1
                  Host: mc.yandex.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Oct 1, 2024 15:37:17.074949026 CEST1061INHTTP/1.1 302 Moved temporarily
                  Content-Length: 0
                  Location: https://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5
                  Oct 1, 2024 15:38:02.087974072 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.74970577.88.21.119804424C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 1, 2024 15:38:01.260294914 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.74970887.250.250.1194434424C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-01 13:37:17 UTC1630OUTGET /watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5 HTTP/1.1
                  Host: mc.yandex.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-10-01 13:37:18 UTC3145INHTTP/1.1 302 Moved temporarily
                  Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                  Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
                  Connection: Close
                  Date: Tue, 01 Oct 2024 13:37:18 GMT
                  Expires: Tue, 01-Oct-2024 13:37:18 GMT
                  Last-Modified: Tue, 01-Oct-2024 13:37:18 GMT
                  Location: /watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1ODkwMzkzLjE3M [TRUNCATED]
                  Pragma: no-cache
                  Set-Cookie: yabs-sid=1878560681727789838; Path=/; SameSite=None; Secure
                  Set-Cookie: i=IlFdxYK55eCnSvvYyqhPHpzvctSIUnrbCamnXpw+wWdbsabRkVHkNbiW2vglr9r19amg72hopIfxwq92D8++j18B164=; Expires=Fri, 29-Sep-2034 13:37:14 GMT; Domain=.yandex.com; Path=/; Secure; HttpOnly; SameSite=None
                  Set-Cookie: yandexuid=1804440101727789838; Expires=Fri, 29-Sep-2034 13:37:14 GMT; Domain=.yandex.com; Path=/; Secure; SameSite=None
                  Set-Cookie: yuidss=1804440101727789838; Expires=Wed, 01-Oct-2025 13:37:18 GMT; Domain=.yandex.com; Path=/; SameSite=None; Secure
                  Set-Cookie: ymex=1759325838.yrts.1727789838#1759325838.yrtsi.1727789838; Expires=Wed, 01-Oct-2025 13:37:18 GMT; Domain=.yandex.com; Path=/; SameSite=None; Secure
                  Set-Cookie: receive-cookie-deprecation=1; Expires=Wed, 01-Oct-2025 13:37:18 GMT; Domain=.yandex.com; Path=/; SameSite=None; Secure; HttpOnly; Partitioned
                  Set-Cookie: bh=Ej8iR29vZ2xlIENocm9tZSI7dj0iMTI1IiwiQ2hyb21pdW0iO3Y9IjEyNSIsIk5vdC5BL0JyYW5kIjt2PSIyNCIaBSJ4ODYiIhAiMTI1LjAuNjQyMi4xMTMiKgI/MDoJIldpbmRvd3MiQggiMTAuMC4wIkoEIjY0IlJcIkdvb2dsZSBDaHJvbWUiO3Y9IjEyNS4wLjY0MjIuMTEzIiwiQ2hyb21pdW0iO3Y9IjEyNS4wLjY0MjIuMTEzIiwiTm90LkEvQnJhbmQiO3Y9IjI0LjAuMC4wIiI=; Expires=Wed, 01-Oct-2025 13:37:18 GMT; Domain=.yandex.com; Path=/; SameSite=None; Secure
                  Strict-Transport-Security: max-age=31536000
                  Transfer-Encoding: chunked
                  X-XSS-Protection: 1; mode=block
                  2024-10-01 13:37:18 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.74971087.250.250.1194434424C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-01 13:37:18 UTC2718OUTGET /watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQ [TRUNCATED]
                  Host: mc.yandex.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-full-version: "117.0.5938.134"
                  sec-ch-ua-arch: "x86"
                  sec-ch-ua-platform: "Windows"
                  sec-ch-ua-platform-version: "10.0.0"
                  sec-ch-ua-model: ""
                  sec-ch-ua-bitness: "64"
                  sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: yabs-sid=1878560681727789838; i=IlFdxYK55eCnSvvYyqhPHpzvctSIUnrbCamnXpw+wWdbsabRkVHkNbiW2vglr9r19amg72hopIfxwq92D8++j18B164=; yandexuid=1804440101727789838; yuidss=1804440101727789838; ymex=1759325838.yrts.1727789838#1759325838.yrtsi.1727789838; receive-cookie-deprecation=1; bh=Ej8iR29vZ2xlIENocm9tZSI7dj0iMTI1IiwiQ2hyb21pdW0iO3Y9IjEyNSIsIk5vdC5BL0JyYW5kIjt2PSIyNCIaBSJ4ODYiIhAiMTI1LjAuNjQyMi4xMTMiKgI/MDoJIldpbmRvd3MiQggiMTAuMC4wIkoEIjY0IlJcIkdvb2dsZSBDaHJvbWUiO3Y9IjEyNS4wLjY0MjIuMTEzIiwiQ2hyb21pdW0iO3Y9IjEyNS4wLjY0MjIuMTEzIiwiTm90LkEvQnJhbmQiO3Y9IjI0LjAuMC4wIiI=
                  2024-10-01 13:37:19 UTC711INHTTP/1.1 200 Ok
                  Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                  Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
                  Connection: Close
                  Content-Length: 576
                  Content-Type: application/javascript
                  Date: Tue, 01 Oct 2024 13:37:19 GMT
                  Expires: Tue, 01-Oct-2024 13:37:19 GMT
                  Last-Modified: Tue, 01-Oct-2024 13:37:19 GMT
                  Pragma: no-cache
                  Strict-Transport-Security: max-age=31536000
                  X-Content-Type-Options: nosniff
                  X-XSS-Protection: 1; mode=block
                  2024-10-01 13:37:19 UTC576INData Raw: 2f 2a 2a 2f 74 72 79 7b 5f 79 6d 6a 73 70 32 30 34 38 34 38 30 30 30 28 7b 22 61 75 74 6f 5f 67 6f 61 6c 73 22 3a 30 2c 22 62 75 74 74 6f 6e 5f 67 6f 61 6c 73 22 3a 30 2c 22 63 5f 72 65 63 70 22 3a 22 31 2e 30 30 30 30 30 22 2c 22 66 6f 72 6d 5f 67 6f 61 6c 73 22 3a 30 2c 22 70 63 73 22 3a 22 31 22 2c 22 77 65 62 76 69 73 6f 72 22 3a 7b 22 61 72 63 68 5f 74 79 70 65 22 3a 22 68 74 6d 6c 22 2c 22 64 61 74 65 22 3a 22 32 30 32 34 2d 30 31 2d 31 38 20 31 31 3a 30 37 3a 33 31 22 2c 22 66 6f 72 6d 73 22 3a 31 2c 22 72 65 63 70 22 3a 22 30 2e 30 30 37 31 30 22 2c 22 75 72 6c 73 22 3a 22 2f 63 6f 6e 74 72 69 62 75 74 69 6f 6e 2f 22 7d 2c 22 73 62 70 22 3a 20 7b 22 61 22 3a 22 55 48 78 4f 4d 30 37 68 79 46 35 4f 71 4e 59 55 76 45 34 44 4f 35 65 7a 63 39 61 69 69
                  Data Ascii: /**/try{_ymjsp204848000({"auto_goals":0,"button_goals":0,"c_recp":"1.00000","form_goals":0,"pcs":"1","webvisor":{"arch_type":"html","date":"2024-01-18 11:07:31","forms":1,"recp":"0.00710","urls":"/contribution/"},"sbp": {"a":"UHxOM07hyF5OqNYUvE4DO5ezc9aii


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.74971287.250.250.1194434424C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-01 13:37:20 UTC2644OUTGET /favicon.ico HTTP/1.1
                  Host: mc.yandex.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-arch: "x86"
                  sec-ch-ua-full-version: "117.0.5938.134"
                  sec-ch-ua-platform-version: "10.0.0"
                  sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"
                  sec-ch-ua-bitness: "64"
                  sec-ch-ua-model: ""
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://mc.yandex.com/watch/18746557/1?callback=_ymjsp204848000&page-url=https%3A%2F%2Fwww.ultimate-guitar.com%2Fuser%2Fmytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22%3Bv%3D%22125%22%2C%22Chromium%22%3Bv%3D%22125%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22%3Bv%3D%22125.0.6422.113%22%2C%22Chromium%22%3Bv%3D%22125.0.6422.113%22%2C%22Not.A%2FBrand%22%3Bv%3D%2224.0.0.0%22%0Achm%0A%3F0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv%3A1%3Avf%3Alxzalitzueo8p9865yapkilbx7%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1461%3Acn%3A1%3Adp%3A0%3Als%3A1351292419062%3Ahid%3A798345388%3Az%3A-300%3Ai%3A20240930145317%3Aet%3A1727725997%3Ac%3A1%3Arn%3A63242771%3Arqn%3A1131%3Au%3A1615229803639781828%3Aw%3A1479x914%3As%3A1920x1080x24%3Ask%3A1%3Ads%3A0%2C109%2C452%2C18%2C9%2C0%2C%2C%2C%2C%2C%2C%2C%3Aco%3A0%3Acpf%3A1%3Ans%3A1727725996533%3Apani%3AMTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg%3D%3D%3Agi%3AR0ExL [TRUNCATED]
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: yabs-sid=1878560681727789838; i=IlFdxYK55eCnSvvYyqhPHpzvctSIUnrbCamnXpw+wWdbsabRkVHkNbiW2vglr9r19amg72hopIfxwq92D8++j18B164=; yandexuid=1804440101727789838; yuidss=1804440101727789838; ymex=1759325838.yrts.1727789838#1759325838.yrtsi.1727789838; receive-cookie-deprecation=1; bh=Ej8iR29vZ2xlIENocm9tZSI7dj0iMTI1IiwiQ2hyb21pdW0iO3Y9IjEyNSIsIk5vdC5BL0JyYW5kIjt2PSIyNCIaBSJ4ODYiIhAiMTI1LjAuNjQyMi4xMTMiKgI/MDoJIldpbmRvd3MiQggiMTAuMC4wIkoEIjY0IlJcIkdvb2dsZSBDaHJvbWUiO3Y9IjEyNS4wLjY0MjIuMTEzIiwiQ2hyb21pdW0iO3Y9IjEyNS4wLjY0MjIuMTEzIiwiTm90LkEvQnJhbmQiO3Y9IjI0LjAuMC4wIiI=
                  2024-10-01 13:37:20 UTC346INHTTP/1.1 404 Not found
                  Connection: Close
                  Content-Length: 0
                  Date: Tue, 01 Oct 2024 13:37:20 GMT
                  Set-Cookie: _yasc=RGN87xBGxCjQgE6UYC7Cq73tVfyg5pyKJb50nrlPL/ybUbPdaA67HTfaqHU6bShynmjWGIM=; domain=.yandex.com; path=/; expires=Fri, 29 Sep 2034 13:37:20 GMT; secure
                  Strict-Transport-Security: max-age=31536000
                  X-XSS-Protection: 1; mode=block


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.749711184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-10-01 13:37:20 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-10-01 13:37:20 UTC467INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-neu-z1
                  Cache-Control: public, max-age=184110
                  Date: Tue, 01 Oct 2024 13:37:20 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.749713184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-10-01 13:37:21 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-10-01 13:37:21 UTC515INHTTP/1.1 200 OK
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-weu-z1
                  Cache-Control: public, max-age=184053
                  Date: Tue, 01 Oct 2024 13:37:21 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-10-01 13:37:21 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:09:37:09
                  Start date:01/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff6c4390000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:09:37:12
                  Start date:01/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2036,i,11928365704172145029,5500621587362827193,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff6c4390000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:7
                  Start time:09:37:14
                  Start date:01/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/watch/18746557?callback=_ymjsp204848000&page-url=https://www.ultimate-guitar.com/user/mytabs&charset=utf-8&uah=chu%0A%22Google%20Chrome%22;v=%22125%22,%22Chromium%22;v=%22125%22,%22Not.A/Brand%22;v=%2224%22%0Acha%0Ax86%0Achb%0A64%0Achf%0A125.0.6422.113%0Achl%0A%22Google%20Chrome%22;v=%22125.0.6422.113%22,%22Chromium%22;v=%22125.0.6422.113%22,%22Not.A/Brand%22;v=%2224.0.0.0%22%0Achm%0A?0%0Achp%0AWindows%0Achv%0A10.0.0&browser-info=pv:1:vf:lxzalitzueo8p9865yapkilbx7:fu:0:en:utf-8:la:en-US:v:1461:cn:1:dp:0:ls:1351292419062:hid:798345388:z:-300:i:20240930145317:et:1727725997:c:1:rn:63242771:rqn:1131:u:1615229803639781828:w:1479x914:s:1920x1080x24:sk:1:ds:0,109,452,18,9,0,,,,,,,:co:0:cpf:1:ns:1727725996533:pani:MTVlNWE4NTJhZmNlOWMxMzdlNTY4YzNmMjg0NDE4NWNhMDJjMDZjOTE1MzY3NDhjZWQ3MDU1ZWE4NTgzNDllYg==:gi:R0ExLjEuNTg1ODkwMzkzLjE3MTgwNTQxMjE=:adb:1:rqnl:1:st:1727725998:t:My%20tabs%20@%20Ultimate-Guitar.Com&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)cdl(na)eco(3178884)ti(3)&wmode=5"
                  Imagebase:0x7ff6c4390000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly