Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b

Overview

General Information

Sample URL:https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has
Analysis ID:1524245
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 5816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2108 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1848,i,18377573424113018610,13651296300715311508,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:58071 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f HTTP/1.1Host: busb.co.inConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: busb.co.inConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8fAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: busb.co.in
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.24.0Date: Wed, 02 Oct 2024 14:35:42 GMTContent-Type: text/htmlContent-Length: 555Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 58076 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58076
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/2@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1848,i,18377573424113018610,13651296300715311508,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1848,i,18377573424113018610,13651296300715311508,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
busb.co.in
5.45.127.145
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://busb.co.in/favicon.icofalse
          unknown
          https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8ffalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            5.45.127.145
            busb.co.inEstonia
            198068PAGM-ASEEfalse
            IP
            192.168.2.16
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1524245
            Start date and time:2024-10-02 16:34:44 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 9s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@21/2@4/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.131, 74.125.133.84, 142.250.185.206, 34.104.35.123, 13.85.23.86, 2.16.100.168, 88.221.110.91, 192.229.221.95, 13.95.31.18, 52.165.164.15, 142.250.184.227, 131.107.255.255
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, dns.msftncsi.com, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):555
            Entropy (8bit):4.734589619218495
            Encrypted:false
            SSDEEP:12:TjeRHVIdtklI5rvy1INGlTF5TF5TF5TF5TF5TFK:neRH68pTPTPTPTPTPTc
            MD5:7D34D86E35ADE3769B332E032633EBD9
            SHA1:CBD7FB5217C686A8C5CDB8E9C9C71B611B4F526A
            SHA-256:338E171ECD2E7B7B1D89C2BED70F9A33477B1345BE879B35A211925B67476DCF
            SHA-512:73BF84CA367F4221F33294D9C408B97CFC29BDC23843D12EDDDB20D7072A3A0EB0E874E6198E7AD083A65B6F829B6E11F754BB2F6C074EB4D5184F0D7EC34E17
            Malicious:false
            Reputation:low
            URL:https://busb.co.in/favicon.ico
            Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.24.0</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 16:35:39.269193888 CEST49675443192.168.2.4173.222.162.32
            Oct 2, 2024 16:35:41.480643988 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.480700016 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:41.480768919 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.481093884 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.481117010 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:41.481175900 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.481345892 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.481363058 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:41.481642008 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:41.481656075 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.383462906 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.383894920 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.383935928 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.384871960 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.384941101 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.386244059 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.386308908 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.386529922 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.386544943 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.387919903 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.388137102 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.388159990 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.391510963 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.391581059 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.392050028 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.392112017 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.442559958 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.442584991 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.456815004 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.490451097 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.710489988 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.710591078 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.710716009 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.711910009 CEST49735443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.711982012 CEST443497355.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.759336948 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.803397894 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.968712091 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.968796015 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:42.968858004 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.974509001 CEST49736443192.168.2.45.45.127.145
            Oct 2, 2024 16:35:42.974528074 CEST443497365.45.127.145192.168.2.4
            Oct 2, 2024 16:35:44.830015898 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:44.830073118 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:44.830189943 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:44.830818892 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:44.830837011 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.092853069 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.092906952 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:45.093106031 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.095580101 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.095597982 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:45.510138988 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.510958910 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:45.511001110 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.512036085 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.512110949 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:45.515048027 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:45.515114069 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.565525055 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:45.565561056 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:45.612427950 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:45.774821043 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:45.774914980 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.778671026 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.778700113 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:45.779015064 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:45.819756031 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:45.867408037 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.379703999 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.379856110 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.379920006 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.380115986 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.380146027 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.380177021 CEST49741443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.380184889 CEST44349741184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.480295897 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.480345011 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:46.480422020 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.480828047 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:46.480848074 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.131329060 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.131453991 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.133245945 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.133259058 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.133493900 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.134772062 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.179414034 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.407743931 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.407830000 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.407886028 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.408727884 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.408751965 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:47.408763885 CEST49742443192.168.2.4184.28.90.27
            Oct 2, 2024 16:35:47.408780098 CEST44349742184.28.90.27192.168.2.4
            Oct 2, 2024 16:35:55.417834044 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:55.417901993 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:55.417952061 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:56.511476994 CEST49739443192.168.2.4142.250.186.100
            Oct 2, 2024 16:35:56.511516094 CEST44349739142.250.186.100192.168.2.4
            Oct 2, 2024 16:35:56.624594927 CEST8049723217.20.57.34192.168.2.4
            Oct 2, 2024 16:35:56.624814034 CEST4972380192.168.2.4217.20.57.34
            Oct 2, 2024 16:35:56.626605034 CEST4972380192.168.2.4217.20.57.34
            Oct 2, 2024 16:35:56.631576061 CEST8049723217.20.57.34192.168.2.4
            Oct 2, 2024 16:36:03.339843035 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:03.344780922 CEST53580711.1.1.1192.168.2.4
            Oct 2, 2024 16:36:03.344835997 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:03.344940901 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:03.351471901 CEST53580711.1.1.1192.168.2.4
            Oct 2, 2024 16:36:04.051595926 CEST53580711.1.1.1192.168.2.4
            Oct 2, 2024 16:36:04.056093931 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:04.057296991 CEST53580711.1.1.1192.168.2.4
            Oct 2, 2024 16:36:04.057713032 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:04.061557055 CEST53580711.1.1.1192.168.2.4
            Oct 2, 2024 16:36:04.061775923 CEST5807153192.168.2.41.1.1.1
            Oct 2, 2024 16:36:11.514738083 CEST8049724217.20.57.34192.168.2.4
            Oct 2, 2024 16:36:11.514873028 CEST4972480192.168.2.4217.20.57.34
            Oct 2, 2024 16:36:11.514873028 CEST4972480192.168.2.4217.20.57.34
            Oct 2, 2024 16:36:11.519829035 CEST8049724217.20.57.34192.168.2.4
            Oct 2, 2024 16:36:44.981643915 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:44.981687069 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:44.981746912 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:44.982079983 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:44.982098103 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:45.631081104 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:45.631725073 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:45.631732941 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:45.632097006 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:45.633012056 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:45.633095026 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:45.674531937 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:55.569797039 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:55.569869041 CEST44358076142.250.186.100192.168.2.4
            Oct 2, 2024 16:36:55.569928885 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:56.348467112 CEST58076443192.168.2.4142.250.186.100
            Oct 2, 2024 16:36:56.348494053 CEST44358076142.250.186.100192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 2, 2024 16:35:39.898658037 CEST53587001.1.1.1192.168.2.4
            Oct 2, 2024 16:35:39.955847025 CEST53633671.1.1.1192.168.2.4
            Oct 2, 2024 16:35:41.445034027 CEST53535181.1.1.1192.168.2.4
            Oct 2, 2024 16:35:41.466964960 CEST5288453192.168.2.41.1.1.1
            Oct 2, 2024 16:35:41.467300892 CEST5017953192.168.2.41.1.1.1
            Oct 2, 2024 16:35:41.479341030 CEST53528841.1.1.1192.168.2.4
            Oct 2, 2024 16:35:41.480036020 CEST53501791.1.1.1192.168.2.4
            Oct 2, 2024 16:35:44.665999889 CEST5605753192.168.2.41.1.1.1
            Oct 2, 2024 16:35:44.666271925 CEST5016953192.168.2.41.1.1.1
            Oct 2, 2024 16:35:44.673208952 CEST53560571.1.1.1192.168.2.4
            Oct 2, 2024 16:35:44.673250914 CEST53501691.1.1.1192.168.2.4
            Oct 2, 2024 16:35:57.428426981 CEST138138192.168.2.4192.168.2.255
            Oct 2, 2024 16:35:58.278383017 CEST53519511.1.1.1192.168.2.4
            Oct 2, 2024 16:36:03.339369059 CEST53613081.1.1.1192.168.2.4
            Oct 2, 2024 16:36:39.811058998 CEST53550121.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 2, 2024 16:35:41.466964960 CEST192.168.2.41.1.1.10x6f71Standard query (0)busb.co.inA (IP address)IN (0x0001)false
            Oct 2, 2024 16:35:41.467300892 CEST192.168.2.41.1.1.10xc79bStandard query (0)busb.co.in65IN (0x0001)false
            Oct 2, 2024 16:35:44.665999889 CEST192.168.2.41.1.1.10x1998Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 2, 2024 16:35:44.666271925 CEST192.168.2.41.1.1.10xb959Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 2, 2024 16:35:41.479341030 CEST1.1.1.1192.168.2.40x6f71No error (0)busb.co.in5.45.127.145A (IP address)IN (0x0001)false
            Oct 2, 2024 16:35:44.673208952 CEST1.1.1.1192.168.2.40x1998No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
            Oct 2, 2024 16:35:44.673250914 CEST1.1.1.1192.168.2.40xb959No error (0)www.google.com65IN (0x0001)false
            Oct 2, 2024 16:35:55.816173077 CEST1.1.1.1192.168.2.40x3d99No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 2, 2024 16:35:55.816173077 CEST1.1.1.1192.168.2.40x3d99No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • busb.co.in
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.4497355.45.127.1454432108C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-02 14:35:42 UTC1032OUTGET /oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f HTTP/1.1
            Host: busb.co.in
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-02 14:35:42 UTC210INHTTP/1.1 200 OK
            Server: nginx/1.24.0
            Date: Wed, 02 Oct 2024 14:35:42 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Strict-Transport-Security: max-age=31536000
            2024-10-02 14:35:42 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.4497365.45.127.1454432108C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-02 14:35:42 UTC955OUTGET /favicon.ico HTTP/1.1
            Host: busb.co.in
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-02 14:35:42 UTC150INHTTP/1.1 404 Not Found
            Server: nginx/1.24.0
            Date: Wed, 02 Oct 2024 14:35:42 GMT
            Content-Type: text/html
            Content-Length: 555
            Connection: close
            2024-10-02 14:35:42 UTC555INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 34 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20
            Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.24.0</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449741184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 14:35:45 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 14:35:46 UTC466INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-neu-z1
            Cache-Control: public, max-age=94205
            Date: Wed, 02 Oct 2024 14:35:45 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449742184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-02 14:35:47 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-02 14:35:47 UTC514INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=94147
            Date: Wed, 02 Oct 2024 14:35:47 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-02 14:35:47 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:10:35:35
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:10:35:38
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1848,i,18377573424113018610,13651296300715311508,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:10:35:40
            Start date:02/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://busb.co.in/oldmega/z/?clickid=b888eq57sa17s0685&t1=november-his-vyyqe24dy4&t2=gamboge-scorpion&t3=the,and,for,wrexham,pub,been,horse,have,who,changes,with,new,its,you,about,and%C2%A0jockey,has,get,street,centre,city,jockey,completely,contact,wrexham:,reopens,after,refurbishment,lea&lpkey=17b827a280f5452268&uclick=q57sa17s0&uclickhash=q57sa17s0-q57sa17s0-7si4-dv0-2tg5-fnsy8n-fnsywj-b5de8f"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly