Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...

Overview

General Information

Sample URL:https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...
Analysis ID:1523881
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2144 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,2615457566890070354,17357747598670132392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX..." MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:49752 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX... HTTP/1.1Host: kakaku-navi.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kakaku-navi.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kakaku-navi.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: kakaku-navi.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,2615457566890070354,17357747598670132392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX..."
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,2615457566890070354,17357747598670132392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kakaku-navi.net
138.91.0.30
truefalse
    unknown
    www.google.com
    142.250.186.68
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://kakaku-navi.net/favicon.icofalse
          unknown
          https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.186.68
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            138.91.0.30
            kakaku-navi.netUnited States
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1523881
            Start date and time:2024-10-02 06:51:30 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 3s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/5@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.18.3, 216.58.206.78, 74.125.71.84, 34.104.35.123, 4.175.87.197, 93.184.221.240, 192.229.221.95, 40.69.42.241, 20.3.187.198, 142.250.184.195
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            InputOutput
            URL: https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX... Model: jbxai
            {
            "brand":[],
            "contains_trigger_text":false,
            "trigger_text":"",
            "prominent_button_name":"unknown",
            "text_input_field_labels":"unknown",
            "pdf_icon_visible":false,
            "has_visible_captcha":false,
            "has_urgent_text":false,
            "has_visible_qrcode":false}
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with very long lines (379), with CRLF line terminators
            Category:downloaded
            Size (bytes):3490
            Entropy (8bit):4.728496519121105
            Encrypted:false
            SSDEEP:96:4+3sq2ixgj/BH61acPXBJHuXohGDHuWtkX:h3sqLxgj/txiko8HT6X
            MD5:504AE2E068B4F2F58F27804A5DB9B9BA
            SHA1:15B9C0C456B6A113D34BB53C0DF25423F6DB277C
            SHA-256:F69EC9C7D598B2859AC983EF6ADB3A865E7037B097CBC06D8F32582679309483
            SHA-512:A60DACAF04B099631AC93ECF508600F4F9079A0250B2426A9BE87629AB7FD3C17CB139545D815F99B2568D582E2EB8C6366F1496FDD67480DC141A3492DA455D
            Malicious:false
            Reputation:low
            URL:https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...
            Preview:<!DOCTYPE html>..<html>.. <head>.. <title>Runtime Error</title>.. <meta name="viewport" content="width=device-width" />.. <style>.. body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} .. p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}.. b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}.. H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }.. H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }.. pre {font-family:"Consolas","Lucida Console",Monospace;font-size:11pt;margin:0;padding:0.5em;line-height:14pt}.. .marker {font-weight: bold; color: black;text-decoration: none;}.. .version {color: gray;}.. .error {margin-bottom: 10px;}.. .expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:pointer; }.. @media screen and (max-width: 639px) {..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 16 x 16
            Category:downloaded
            Size (bytes):160
            Entropy (8bit):5.070532860876292
            Encrypted:false
            SSDEEP:3:Cse8oyWu88Vl/7ziE3sRERfvGtR7Zn6rrY5QEE:NnoyWql//7sS+dZANf
            MD5:2ECF5D981337B4F384994CBCCAA27FA5
            SHA1:D369F4835EC55E8B51F71504832301BF7404B33E
            SHA-256:7D198B2BA9971B3C2B3417298C657361EA3185CE9C3F07E78F2E82276AD9C106
            SHA-512:92AFDDF169AB07AF7FD0986F16F3578E4C482533EA01DE5FE6071CCB98EECCD73126940CAE02570F7AB0C02C525004D0F14091989D644CE01ADCC85BE376401E
            Malicious:false
            Reputation:low
            URL:https://kakaku-navi.net/favicon.ico
            Preview:GIF89a.................ff.33...ff.33........................!.......,..........M..I....3.<.@i. JG...*P.v.,.x.Q"F.M.@-30...#!....... ....W.......0S2.$.@}n.)..;
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:GIF image data, version 89a, 16 x 16
            Category:dropped
            Size (bytes):160
            Entropy (8bit):5.070532860876292
            Encrypted:false
            SSDEEP:3:Cse8oyWu88Vl/7ziE3sRERfvGtR7Zn6rrY5QEE:NnoyWql//7sS+dZANf
            MD5:2ECF5D981337B4F384994CBCCAA27FA5
            SHA1:D369F4835EC55E8B51F71504832301BF7404B33E
            SHA-256:7D198B2BA9971B3C2B3417298C657361EA3185CE9C3F07E78F2E82276AD9C106
            SHA-512:92AFDDF169AB07AF7FD0986F16F3578E4C482533EA01DE5FE6071CCB98EECCD73126940CAE02570F7AB0C02C525004D0F14091989D644CE01ADCC85BE376401E
            Malicious:false
            Reputation:low
            Preview:GIF89a.................ff.33...ff.33........................!.......,..........M..I....3.<.@i. JG...*P.v.,.x.Q"F.M.@-30...#!....... ....W.......0S2.$.@}n.)..;
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 06:52:14.701617956 CEST49675443192.168.2.4173.222.162.32
            Oct 2, 2024 06:52:24.388015032 CEST49675443192.168.2.4173.222.162.32
            Oct 2, 2024 06:52:25.469795942 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.469830990 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:25.469898939 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.470122099 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.470135927 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:25.470602989 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.470609903 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:25.470679045 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.470824003 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:25.470834970 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.525204897 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.526061058 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.576354027 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.576445103 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.845349073 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.845369101 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.845709085 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.845719099 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.846389055 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.846456051 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.846710920 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.846770048 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.862657070 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.862728119 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.864355087 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.864463091 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.865520954 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.865529060 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.903841019 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:26.903877974 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:26.903958082 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:26.904151917 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.904160023 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:26.904594898 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:26.904608965 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:26.918903112 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:26.949944973 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.145924091 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.145941019 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.145992994 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.146011114 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.146059036 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.146091938 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.146125078 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.146173000 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.282183886 CEST49738443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.282210112 CEST44349738138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.508395910 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.555396080 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.565224886 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:27.565764904 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:27.565778017 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:27.566827059 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:27.566953897 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:27.568330050 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:27.568408966 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:27.622366905 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:27.622375965 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:27.669471979 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:27.919734001 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:27.919759989 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:27.919899940 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:27.921513081 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:27.921525955 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:27.969299078 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.969376087 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:27.969430923 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.970130920 CEST49737443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:27.970139980 CEST44349737138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:28.578295946 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.578365088 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:28.585262060 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:28.585268021 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.585464954 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.638689041 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:28.714833975 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:28.759397030 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.804527044 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:28.804539919 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:28.804688931 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:28.805041075 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:28.805053949 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:28.921092987 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.921128988 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:28.921197891 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.144998074 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.145013094 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:29.145021915 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.145026922 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:29.344161034 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.344253063 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:29.344357014 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.344779015 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:29.344813108 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:29.869453907 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:29.869877100 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:29.869894028 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:29.870892048 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:29.870955944 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:29.871454954 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:29.871517897 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:29.871706963 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:29.871714115 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:29.919744968 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:30.455909967 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.456005096 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.467101097 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.467127085 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.467344046 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.469351053 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:30.469474077 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:30.469527960 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:30.469994068 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.515439034 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.602832079 CEST49743443192.168.2.4138.91.0.30
            Oct 2, 2024 06:52:30.602845907 CEST44349743138.91.0.30192.168.2.4
            Oct 2, 2024 06:52:30.737077951 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.737128019 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.737198114 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.755760908 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.755809069 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:30.755846977 CEST49744443192.168.2.4184.28.90.27
            Oct 2, 2024 06:52:30.755862951 CEST44349744184.28.90.27192.168.2.4
            Oct 2, 2024 06:52:37.463521957 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:37.463608980 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:52:37.467192888 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:37.485548019 CEST49741443192.168.2.4142.250.186.68
            Oct 2, 2024 06:52:37.485574007 CEST44349741142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:00.530546904 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:00.540395021 CEST53497521.1.1.1192.168.2.4
            Oct 2, 2024 06:53:00.540575027 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:00.540642977 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:00.540642977 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:00.554699898 CEST53497521.1.1.1192.168.2.4
            Oct 2, 2024 06:53:00.555670977 CEST53497521.1.1.1192.168.2.4
            Oct 2, 2024 06:53:01.087857008 CEST53497521.1.1.1192.168.2.4
            Oct 2, 2024 06:53:01.088321924 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:01.095489025 CEST53497521.1.1.1192.168.2.4
            Oct 2, 2024 06:53:01.095726013 CEST4975253192.168.2.41.1.1.1
            Oct 2, 2024 06:53:26.944418907 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:26.944458008 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:26.944581985 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:26.944952011 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:26.944967031 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:27.593952894 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:27.594198942 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:27.594213963 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:27.594505072 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:27.594805002 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:27.594860077 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:27.638062954 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:32.156111002 CEST4972580192.168.2.4199.232.214.172
            Oct 2, 2024 06:53:32.156172037 CEST4972680192.168.2.4199.232.214.172
            Oct 2, 2024 06:53:32.161818027 CEST8049725199.232.214.172192.168.2.4
            Oct 2, 2024 06:53:32.161879063 CEST4972580192.168.2.4199.232.214.172
            Oct 2, 2024 06:53:32.162249088 CEST8049726199.232.214.172192.168.2.4
            Oct 2, 2024 06:53:32.162298918 CEST4972680192.168.2.4199.232.214.172
            Oct 2, 2024 06:53:37.504044056 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:37.504113913 CEST44349755142.250.186.68192.168.2.4
            Oct 2, 2024 06:53:37.504172087 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:39.469008923 CEST49755443192.168.2.4142.250.186.68
            Oct 2, 2024 06:53:39.469028950 CEST44349755142.250.186.68192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 06:52:23.124226093 CEST53492571.1.1.1192.168.2.4
            Oct 2, 2024 06:52:23.238145113 CEST53626721.1.1.1192.168.2.4
            Oct 2, 2024 06:52:24.396306992 CEST53585321.1.1.1192.168.2.4
            Oct 2, 2024 06:52:24.966861010 CEST6036753192.168.2.41.1.1.1
            Oct 2, 2024 06:52:24.967003107 CEST6273653192.168.2.41.1.1.1
            Oct 2, 2024 06:52:25.465723038 CEST53627361.1.1.1192.168.2.4
            Oct 2, 2024 06:52:25.469238997 CEST53603671.1.1.1192.168.2.4
            Oct 2, 2024 06:52:26.895025015 CEST5655953192.168.2.41.1.1.1
            Oct 2, 2024 06:52:26.895725012 CEST6318753192.168.2.41.1.1.1
            Oct 2, 2024 06:52:26.901638985 CEST53565591.1.1.1192.168.2.4
            Oct 2, 2024 06:52:26.902484894 CEST53631871.1.1.1192.168.2.4
            Oct 2, 2024 06:52:28.306926966 CEST5679953192.168.2.41.1.1.1
            Oct 2, 2024 06:52:28.307718039 CEST5687653192.168.2.41.1.1.1
            Oct 2, 2024 06:52:28.788403034 CEST53568761.1.1.1192.168.2.4
            Oct 2, 2024 06:52:28.803260088 CEST53567991.1.1.1192.168.2.4
            Oct 2, 2024 06:52:41.585988045 CEST53612161.1.1.1192.168.2.4
            Oct 2, 2024 06:52:43.722238064 CEST138138192.168.2.4192.168.2.255
            Oct 2, 2024 06:53:00.529978037 CEST53502851.1.1.1192.168.2.4
            Oct 2, 2024 06:53:22.836729050 CEST53531951.1.1.1192.168.2.4
            Oct 2, 2024 06:53:23.381184101 CEST53497151.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 2, 2024 06:52:24.966861010 CEST192.168.2.41.1.1.10xcc53Standard query (0)kakaku-navi.netA (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:24.967003107 CEST192.168.2.41.1.1.10x4889Standard query (0)kakaku-navi.net65IN (0x0001)false
            Oct 2, 2024 06:52:26.895025015 CEST192.168.2.41.1.1.10x674fStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:26.895725012 CEST192.168.2.41.1.1.10x8d46Standard query (0)www.google.com65IN (0x0001)false
            Oct 2, 2024 06:52:28.306926966 CEST192.168.2.41.1.1.10xb70bStandard query (0)kakaku-navi.netA (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:28.307718039 CEST192.168.2.41.1.1.10x216Standard query (0)kakaku-navi.net65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 2, 2024 06:52:25.469238997 CEST1.1.1.1192.168.2.40xcc53No error (0)kakaku-navi.net138.91.0.30A (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:26.901638985 CEST1.1.1.1192.168.2.40x674fNo error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:26.902484894 CEST1.1.1.1192.168.2.40x8d46No error (0)www.google.com65IN (0x0001)false
            Oct 2, 2024 06:52:28.803260088 CEST1.1.1.1192.168.2.40xb70bNo error (0)kakaku-navi.net138.91.0.30A (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:38.806603909 CEST1.1.1.1192.168.2.40x8abfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 06:52:38.806603909 CEST1.1.1.1192.168.2.40x8abfNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Oct 2, 2024 06:52:53.230901957 CEST1.1.1.1192.168.2.40x3e66No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 06:52:53.230901957 CEST1.1.1.1192.168.2.40x3e66No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Oct 2, 2024 06:53:15.599638939 CEST1.1.1.1192.168.2.40xe3efNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 06:53:15.599638939 CEST1.1.1.1192.168.2.40xe3efNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            Oct 2, 2024 06:53:35.877625942 CEST1.1.1.1192.168.2.40x2ccfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 06:53:35.877625942 CEST1.1.1.1192.168.2.40x2ccfNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • kakaku-navi.net
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449738138.91.0.304436096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-02 04:52:26 UTC757OUTGET /items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX... HTTP/1.1
            Host: kakaku-navi.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-02 04:52:27 UTC250INHTTP/1.1 400 Bad Request
            Content-Length: 3490
            Connection: close
            Content-Type: text/html; charset=utf-8
            Date: Wed, 02 Oct 2024 04:52:26 GMT
            Server: Microsoft-IIS/10.0
            Cache-Control: private
            X-AspNet-Version: 4.0.30319
            X-Powered-By: ASP.NET
            2024-10-02 04:52:27 UTC3490INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 20 20 20 20 3c 68 65 61 64 3e 0d 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 52 75 6e 74 69 6d 65 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 56 65 72 64 61 6e 61 22 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 6e 6f 72 6d 61 6c 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 2e 37 65 6d 3b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 20 0d 0a 20 20 20 20 20 20 20 20 20 70 20 7b
            Data Ascii: <!DOCTYPE html><html> <head> <title>Runtime Error</title> <meta name="viewport" content="width=device-width" /> <style> body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} p {


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449737138.91.0.304436096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-02 04:52:27 UTC685OUTGET /favicon.ico HTTP/1.1
            Host: kakaku-navi.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX...
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-02 04:52:27 UTC269INHTTP/1.1 200 OK
            Content-Length: 160
            Connection: close
            Content-Type: image/x-icon
            Date: Wed, 02 Oct 2024 04:52:27 GMT
            Server: Microsoft-IIS/10.0
            Accept-Ranges: bytes
            ETag: "1952c432039d01:0"
            Last-Modified: Mon, 26 Jan 2015 00:37:00 GMT
            X-Powered-By: ASP.NET
            2024-10-02 04:52:27 UTC160INData Raw: 47 49 46 38 39 61 10 00 10 00 b3 00 00 ff ff ff ff cc cc ff 99 99 ff 66 66 ff 33 33 cc 99 99 cc 66 66 cc 33 33 cc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 f9 04 00 07 00 ff 00 2c 00 00 00 00 10 00 10 00 00 04 4d 10 c9 49 ab bd f6 08 33 ca 3c dd 40 69 00 20 4a 47 00 1c 96 2a 50 00 76 94 2c 12 78 98 51 22 46 80 4d ae 40 2d 33 30 e8 00 01 23 21 b3 11 94 0a 82 8e c5 20 80 96 92 82 57 e5 00 9a 01 04 07 c3 30 53 32 fc 24 d4 80 40 7d 6e bb 29 11 00 3b
            Data Ascii: GIF89aff33ff33!,MI3<@i JG*Pv,xQ"FM@-30#! W0S2$@}n);


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449742184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 04:52:28 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 04:52:28 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=129202
            Date: Wed, 02 Oct 2024 04:52:28 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449743138.91.0.304436096C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-02 04:52:29 UTC350OUTGET /favicon.ico HTTP/1.1
            Host: kakaku-navi.net
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-02 04:52:30 UTC269INHTTP/1.1 200 OK
            Content-Length: 160
            Connection: close
            Content-Type: image/x-icon
            Date: Wed, 02 Oct 2024 04:52:30 GMT
            Server: Microsoft-IIS/10.0
            Accept-Ranges: bytes
            ETag: "1952c432039d01:0"
            Last-Modified: Mon, 26 Jan 2015 00:37:00 GMT
            X-Powered-By: ASP.NET
            2024-10-02 04:52:30 UTC160INData Raw: 47 49 46 38 39 61 10 00 10 00 b3 00 00 ff ff ff ff cc cc ff 99 99 ff 66 66 ff 33 33 cc 99 99 cc 66 66 cc 33 33 cc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 f9 04 00 07 00 ff 00 2c 00 00 00 00 10 00 10 00 00 04 4d 10 c9 49 ab bd f6 08 33 ca 3c dd 40 69 00 20 4a 47 00 1c 96 2a 50 00 76 94 2c 12 78 98 51 22 46 80 4d ae 40 2d 33 30 e8 00 01 23 21 b3 11 94 0a 82 8e c5 20 80 96 92 82 57 e5 00 9a 01 04 07 c3 30 53 32 fc 24 d4 80 40 7d 6e bb 29 11 00 3b
            Data Ascii: GIF89aff33ff33!,MI3<@i JG*Pv,xQ"FM@-30#! W0S2$@}n);


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449744184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 04:52:30 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 04:52:30 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=129144
            Date: Wed, 02 Oct 2024 04:52:30 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-02 04:52:30 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:00:52:18
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:00:52:21
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,2615457566890070354,17357747598670132392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:00:52:24
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://kakaku-navi.net/items/**Ameatmsges.com__;Ly8!!CiF3mHgEawk!EJtFDR8FEEauLfGDHoxZUvF1js_YNRdoiAEPtRWlzygttSYGxFGRIX..."
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly