Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.flysascomonlineclaimer.mywire.org/WELCOME/

Overview

General Information

Sample URL:https://www.flysascomonlineclaimer.mywire.org/WELCOME/
Analysis ID:1543678
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7028 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1944,i,14011880240507093823,14102741856608283169,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6524 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.flysascomonlineclaimer.mywire.org/WELCOME/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIkqHLAQj2mM0BCIWgzQEI3L3NAQiRys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lo6w+M7asWVYflR&MD=Fdb6nu5a HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lo6w+M7asWVYflR&MD=Fdb6nu5a HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.flysascomonlineclaimer.mywire.org
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: wwwflysascomonlineclaimer.mywire.org
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: classification engineClassification label: clean0.win@25/8@34/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1944,i,14011880240507093823,14102741856608283169,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.flysascomonlineclaimer.mywire.org/WELCOME/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1944,i,14011880240507093823,14102741856608283169,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.206
truefalse
    unknown
    www.google.com
    142.250.186.100
    truefalse
      unknown
      www.flysascomonlineclaimer.mywire.org
      unknown
      unknownfalse
        unknown
        wwwflysascomonlineclaimer.mywire.org
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.16
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1543678
            Start date and time:2024-10-28 08:59:51 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 19s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowsinteractivecookbook.jbs
            Sample URL:https://www.flysascomonlineclaimer.mywire.org/WELCOME/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:13
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@25/8@34/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.186.46, 74.125.71.84, 34.104.35.123, 199.232.210.172, 172.217.18.3, 172.217.16.142
            • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://www.flysascomonlineclaimer.mywire.org/WELCOME/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 07:00:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2673
            Entropy (8bit):3.9825823650942422
            Encrypted:false
            SSDEEP:48:8TOr0dbQT706b8HMTidAKZdA1FehwiZUklqehHMy+3:8yyQXjbJmMy
            MD5:3D9ED6BB0FC0EDD004F78D6307FBD4CD
            SHA1:ADDDE882DA6A9991450AE248824AC43B80D88DB7
            SHA-256:66BD2951558A204BDB6F0FF6D57FC27DF8BC2BF43A36C3880EBCD6F3C2D894E8
            SHA-512:12CF5663118036669E55DC9F69B96E269CE11073F588962A1BE2AC3C77288D73F9EAB2C97B1F07B82A9FF966596A017D2CFE08AEAF525D61BB1182EFE3440087
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.......p.)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V\Y.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 07:00:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2675
            Entropy (8bit):3.9986278669823676
            Encrypted:false
            SSDEEP:48:8Mi0dbQT706b8HMTidAKZdA1seh/iZUkAQkqehWMy+2:8SQXjb/9QBMy
            MD5:1FAA3A4105CCEDE9D787783D23AFF2C4
            SHA1:E28B4A74E6207EB7F16956180B500852502767CC
            SHA-256:A59207020DA00FB5A3AF289FA06C1AFAF52B471CD7EBB1FC28CD53C0D666C20A
            SHA-512:A24A50D27B3AB8B8E303BB000E5F6A4513585215CDBE9751D1C01DFC733B870A39551DF038C9B9948D443099F045270D2CD039BAD7182417828976516AC48A91
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.......p.)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V\Y.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2689
            Entropy (8bit):4.0071551438089905
            Encrypted:false
            SSDEEP:48:860dbQT706bAHMTidAKZdA14meh7sFiZUkmgqeh7sgMy+BX:89QXjb/nqMy
            MD5:41EB99561DCE4E4B0B7E83E7514DD758
            SHA1:FF3442357BEC8FDA780D5D4008EB69254BE20149
            SHA-256:8BFB3D998DE2FAB5E0696038EBE50DA8E7E4EA51D836FF491757AB1B77B224C8
            SHA-512:56F0761290EAD411E18DC5707F54FA6FBA827B31AAE7B09C448DFB1338CF37A8C87580CE2053D4FEA152711C627C77836A732CB4525DE1E62C4D42628CC6B4AC
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 07:00:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9970984852711964
            Encrypted:false
            SSDEEP:48:8P0dbQT706b8HMTidAKZdA1TehDiZUkwqehyMy+R:8+QXjbMIMy
            MD5:6CB1BB5DCEE5DCF6818FDEBC57865F2E
            SHA1:17EF519AC558C55524612E2E58087DED10A5EA34
            SHA-256:CD02B94D7FCEA95032E2EFDEBD0A610A66E5D9F90162DB42ADEA6FD4535FD1FD
            SHA-512:0A0180DF70A9D157AA96EA6F1B34D2E6C0FCEBD39D67FA627D4B221000B96BF61C74B5AAB78F2308636D0273669062BA066A5AE992CD217B6ED5EDA00D6A2D9D
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......p.)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V\Y.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 07:00:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.984273763410692
            Encrypted:false
            SSDEEP:48:8gr0dbQT706b8HMTidAKZdA1dehBiZUk1W1qeh0My+C:8gyQXjbc9UMy
            MD5:7988F48CB158921CCE023F00A7B6CB3F
            SHA1:E1A528B820DE200026C60A010B8F1DB974ED67AB
            SHA-256:C650E7CA766D392B35EF8417D3D287EB614DE7AF694EA28FC1D0E3468469E3B8
            SHA-512:28F9739D135951E5534F9A355219B150663471D4341635894E4654E4641DCEE0C3D6B418CFC4B633BA4FCA59CA7CF2E77196637753A51A26197C0EB96C4A0D73
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....Y.p.)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V\Y.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 07:00:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.9918047154628624
            Encrypted:false
            SSDEEP:48:820dbQT706b8HMTidAKZdA1duTeehOuTbbiZUk5OjqehOuTbqMy+yT+:8xQXjbuTfTbxWOvTbqMy7T
            MD5:D44854B3D01FE77A96241A902C684BF9
            SHA1:7AF9E4AB0C39A68A48822B9A58992B803A26C946
            SHA-256:DFFAD7F326186E9B6FFDE5433CCEC74AC3DB9386C1BFCE018FBCEB35A5004E3E
            SHA-512:2AB6FF3363B562ACE8F981AFE62888F768D1A29F62AB3CB1D1402A6FC9F8AFC235AF2AF8798FCFF70409BE215B602E770406A9394547CE7B9DDB498C0889AA2E
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....HO.p.)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I\Y.@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V\Y.@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V\Y.@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V\Y.@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V\Y.@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........t.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (794)
            Category:downloaded
            Size (bytes):799
            Entropy (8bit):5.128164791379477
            Encrypted:false
            SSDEEP:24:j4ZjwLdWGgCJBHslgT9lCuABurz7HHHHHHHYqmffffffo:EqLyCJKlgZ01Bu/Eqmffffffo
            MD5:272541DCD74719BEC5DDFAD2254EDD02
            SHA1:EA17DB2ADBD5A5AC35E6AE42444801B804549E67
            SHA-256:B523963848432C0BE5D7169FDDA7BFA12CC48FD3519CD6D4E2C8990727545E95
            SHA-512:42FB3EAC5B142C5095829170221539B296FAC2FBCCED6D6165D601C4FCE340C809CC33E9161F639835E794BDC12BF32C86528D8A754B70AAAF1F6036033BBC1A
            Malicious:false
            Reputation:low
            URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
            Preview:)]}'.["",["diwali dates","ohio high school football playoffs","full cast tracker season 2 episode 3","elf stanley lip oil holder","open beta monster hunter wilds","sunday catholic tv mass","aurora borealis forecast","dallas mavericks vs phoenix suns"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggestrelevance":[1256,1255,1254,1253,1252,1251,1250,600],"google:suggestsubtypes":[[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 09:00:21.539361000 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:21.846633911 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:22.451643944 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:23.666639090 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:25.457330942 CET4968980192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:26.075648069 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:26.324767113 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:26.324836969 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:26.324942112 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:26.325186014 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:26.325213909 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.218184948 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.218524933 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.218592882 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.220099926 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.220216036 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.221241951 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.221335888 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.273696899 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.273720026 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.321670055 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.627216101 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.671360016 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.832061052 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:27.832112074 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:27.832207918 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:27.834265947 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:27.834284067 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:27.918224096 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.975662947 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.975699902 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.976809025 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:27.976865053 CET44349705142.250.186.100192.168.2.16
            Oct 28, 2024 09:00:27.976953030 CET49705443192.168.2.16142.250.186.100
            Oct 28, 2024 09:00:29.185555935 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:29.185683012 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:29.190321922 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:29.190332890 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:29.190728903 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:29.228686094 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:29.275343895 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:29.689196110 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:29.992674112 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:30.598656893 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:30.700706959 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.700932980 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.700963974 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.700978041 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.701108932 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.701138973 CET44349706184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.701185942 CET49706443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.730659008 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.730725050 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.730806112 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.731097937 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:30.731116056 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:30.883660078 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:31.574726105 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.574816942 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.576539993 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.576554060 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.577157021 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.578578949 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.619348049 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.806673050 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:31.824188948 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.824273109 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.824438095 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.825277090 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.825303078 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:31.825315952 CET49707443192.168.2.16184.28.90.27
            Oct 28, 2024 09:00:31.825323105 CET44349707184.28.90.27192.168.2.16
            Oct 28, 2024 09:00:34.158929110 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:34.207973957 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:34.318789959 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:34.318818092 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:34.318939924 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:34.319994926 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:34.320004940 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:34.460686922 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:35.066732883 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:35.149313927 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.149405003 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.152414083 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.152420044 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.152679920 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.193686962 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.204425097 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.247375965 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475649118 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475672960 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475682020 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475691080 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475718021 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475771904 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.475781918 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.475847006 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.475915909 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.475966930 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.476042032 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.476048946 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.476716995 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.476774931 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.487770081 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.487783909 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:35.487824917 CET49708443192.168.2.1620.109.210.53
            Oct 28, 2024 09:00:35.487831116 CET4434970820.109.210.53192.168.2.16
            Oct 28, 2024 09:00:36.270703077 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:38.682674885 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:39.017359972 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:40.498688936 CET49673443192.168.2.16204.79.197.203
            Oct 28, 2024 09:00:43.482726097 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:00:48.624718904 CET49678443192.168.2.1620.189.173.10
            Oct 28, 2024 09:00:53.093805075 CET4968080192.168.2.16192.229.211.108
            Oct 28, 2024 09:01:11.920968056 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:11.921005011 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:11.921201944 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:11.921720028 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:11.921729088 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.729036093 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.729168892 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:12.730428934 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:12.730463028 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.730967999 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.732598066 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:12.775372982 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.996762037 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.996892929 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.996953011 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.997014999 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:12.997081041 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:12.997123957 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:12.997147083 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114064932 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:13.114137888 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:13.114217997 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114280939 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:13.114315033 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:13.114327908 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114373922 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114434004 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114487886 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:13.114522934 CET49709443192.168.2.1620.109.210.53
            Oct 28, 2024 09:01:13.114537954 CET4434970920.109.210.53192.168.2.16
            Oct 28, 2024 09:01:26.377511024 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:26.377595901 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:26.377687931 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:26.377958059 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:26.377993107 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.228471994 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.228781939 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:27.228843927 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.229882002 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.229962111 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:27.230238914 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:27.230308056 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.270889997 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:27.270947933 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:27.318811893 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:37.221177101 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:37.221270084 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:01:37.221349955 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:37.749581099 CET49711443192.168.2.16142.250.186.100
            Oct 28, 2024 09:01:37.749645948 CET44349711142.250.186.100192.168.2.16
            Oct 28, 2024 09:02:26.453262091 CET49713443192.168.2.16142.250.186.100
            Oct 28, 2024 09:02:26.453306913 CET44349713142.250.186.100192.168.2.16
            Oct 28, 2024 09:02:26.453406096 CET49713443192.168.2.16142.250.186.100
            Oct 28, 2024 09:02:26.453742027 CET49713443192.168.2.16142.250.186.100
            Oct 28, 2024 09:02:26.453758001 CET44349713142.250.186.100192.168.2.16
            Oct 28, 2024 09:02:27.302598000 CET44349713142.250.186.100192.168.2.16
            Oct 28, 2024 09:02:27.345944881 CET49713443192.168.2.16142.250.186.100
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 09:00:21.530689001 CET53536631.1.1.1192.168.2.16
            Oct 28, 2024 09:00:21.564311028 CET53649431.1.1.1192.168.2.16
            Oct 28, 2024 09:00:22.421080112 CET5867453192.168.2.161.1.1.1
            Oct 28, 2024 09:00:22.421206951 CET5675153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:22.713740110 CET53586741.1.1.1192.168.2.16
            Oct 28, 2024 09:00:22.723339081 CET53567511.1.1.1192.168.2.16
            Oct 28, 2024 09:00:22.724059105 CET5568453192.168.2.161.1.1.1
            Oct 28, 2024 09:00:22.794645071 CET53570751.1.1.1192.168.2.16
            Oct 28, 2024 09:00:22.920423985 CET53556841.1.1.1192.168.2.16
            Oct 28, 2024 09:00:22.942981005 CET5320153192.168.2.168.8.8.8
            Oct 28, 2024 09:00:22.943484068 CET4977153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:22.951565981 CET53497711.1.1.1192.168.2.16
            Oct 28, 2024 09:00:23.948965073 CET6080453192.168.2.161.1.1.1
            Oct 28, 2024 09:00:23.949227095 CET5066053192.168.2.161.1.1.1
            Oct 28, 2024 09:00:23.955934048 CET6370653192.168.2.168.8.4.4
            Oct 28, 2024 09:00:24.016283035 CET53637068.8.4.4192.168.2.16
            Oct 28, 2024 09:00:24.197120905 CET53506601.1.1.1192.168.2.16
            Oct 28, 2024 09:00:24.291615963 CET53608041.1.1.1192.168.2.16
            Oct 28, 2024 09:00:26.316431999 CET5200753192.168.2.161.1.1.1
            Oct 28, 2024 09:00:26.316579103 CET5699153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:26.323642969 CET53520071.1.1.1192.168.2.16
            Oct 28, 2024 09:00:26.324116945 CET53569911.1.1.1192.168.2.16
            Oct 28, 2024 09:00:27.285707951 CET53532018.8.8.8192.168.2.16
            Oct 28, 2024 09:00:29.311135054 CET5075653192.168.2.161.1.1.1
            Oct 28, 2024 09:00:29.311330080 CET5461953192.168.2.161.1.1.1
            Oct 28, 2024 09:00:30.328015089 CET6435953192.168.2.161.1.1.1
            Oct 28, 2024 09:00:30.328208923 CET5414753192.168.2.161.1.1.1
            Oct 28, 2024 09:00:30.638189077 CET53507561.1.1.1192.168.2.16
            Oct 28, 2024 09:00:30.695547104 CET4980853192.168.2.161.1.1.1
            Oct 28, 2024 09:00:30.710042953 CET53546191.1.1.1192.168.2.16
            Oct 28, 2024 09:00:30.729664087 CET53643591.1.1.1192.168.2.16
            Oct 28, 2024 09:00:30.741203070 CET53541471.1.1.1192.168.2.16
            Oct 28, 2024 09:00:30.885473967 CET53498081.1.1.1192.168.2.16
            Oct 28, 2024 09:00:39.836074114 CET53519071.1.1.1192.168.2.16
            Oct 28, 2024 09:00:42.495981932 CET5043853192.168.2.161.1.1.1
            Oct 28, 2024 09:00:42.496223927 CET5897153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:42.658885002 CET53504381.1.1.1192.168.2.16
            Oct 28, 2024 09:00:42.702560902 CET6358453192.168.2.161.1.1.1
            Oct 28, 2024 09:00:42.711282969 CET53589711.1.1.1192.168.2.16
            Oct 28, 2024 09:00:42.824265957 CET53635841.1.1.1192.168.2.16
            Oct 28, 2024 09:00:42.835661888 CET6123153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:42.836324930 CET5565753192.168.2.168.8.4.4
            Oct 28, 2024 09:00:42.843044996 CET53612311.1.1.1192.168.2.16
            Oct 28, 2024 09:00:42.844309092 CET53556578.8.4.4192.168.2.16
            Oct 28, 2024 09:00:43.843516111 CET5798053192.168.2.161.1.1.1
            Oct 28, 2024 09:00:43.843782902 CET4957153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:43.851130962 CET53579801.1.1.1192.168.2.16
            Oct 28, 2024 09:00:43.990318060 CET53495711.1.1.1192.168.2.16
            Oct 28, 2024 09:00:48.887280941 CET6366953192.168.2.161.1.1.1
            Oct 28, 2024 09:00:48.887454033 CET6308953192.168.2.161.1.1.1
            Oct 28, 2024 09:00:49.008980989 CET53636691.1.1.1192.168.2.16
            Oct 28, 2024 09:00:49.034132004 CET53630891.1.1.1192.168.2.16
            Oct 28, 2024 09:00:49.034908056 CET6278153192.168.2.161.1.1.1
            Oct 28, 2024 09:00:49.136464119 CET53627811.1.1.1192.168.2.16
            Oct 28, 2024 09:00:58.719397068 CET53554951.1.1.1192.168.2.16
            Oct 28, 2024 09:01:13.799653053 CET5480453192.168.2.161.1.1.1
            Oct 28, 2024 09:01:13.947074890 CET53548041.1.1.1192.168.2.16
            Oct 28, 2024 09:01:19.151273966 CET5434453192.168.2.161.1.1.1
            Oct 28, 2024 09:01:19.151432991 CET6459753192.168.2.161.1.1.1
            Oct 28, 2024 09:01:19.274029970 CET53543441.1.1.1192.168.2.16
            Oct 28, 2024 09:01:19.303524017 CET5284353192.168.2.161.1.1.1
            Oct 28, 2024 09:01:19.558324099 CET53645971.1.1.1192.168.2.16
            Oct 28, 2024 09:01:19.558363914 CET53528431.1.1.1192.168.2.16
            Oct 28, 2024 09:01:21.727267027 CET53573791.1.1.1192.168.2.16
            Oct 28, 2024 09:01:21.756120920 CET53569941.1.1.1192.168.2.16
            Oct 28, 2024 09:01:25.872262955 CET138138192.168.2.16192.168.2.255
            Oct 28, 2024 09:01:35.131412029 CET6111953192.168.2.161.1.1.1
            Oct 28, 2024 09:01:35.278776884 CET53611191.1.1.1192.168.2.16
            Oct 28, 2024 09:01:50.506102085 CET53610061.1.1.1192.168.2.16
            Oct 28, 2024 09:02:05.584486008 CET6132853192.168.2.161.1.1.1
            Oct 28, 2024 09:02:05.731600046 CET53613281.1.1.1192.168.2.16
            Oct 28, 2024 09:02:19.582314014 CET6441453192.168.2.161.1.1.1
            Oct 28, 2024 09:02:19.582429886 CET5314953192.168.2.161.1.1.1
            Oct 28, 2024 09:02:19.685486078 CET53531491.1.1.1192.168.2.16
            Oct 28, 2024 09:02:19.729954958 CET53644141.1.1.1192.168.2.16
            Oct 28, 2024 09:02:19.730818033 CET5957253192.168.2.161.1.1.1
            Oct 28, 2024 09:02:19.739615917 CET53595721.1.1.1192.168.2.16
            TimestampSource IPDest IPChecksumCodeType
            Oct 28, 2024 09:00:27.285794973 CET192.168.2.168.8.8.8d00a(Port unreachable)Destination Unreachable
            Oct 28, 2024 09:00:30.710140944 CET192.168.2.161.1.1.1c245(Port unreachable)Destination Unreachable
            Oct 28, 2024 09:00:42.711389065 CET192.168.2.161.1.1.1c244(Port unreachable)Destination Unreachable
            Oct 28, 2024 09:00:43.990437031 CET192.168.2.161.1.1.1c244(Port unreachable)Destination Unreachable
            Oct 28, 2024 09:01:19.558528900 CET192.168.2.161.1.1.1c244(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 28, 2024 09:00:22.421080112 CET192.168.2.161.1.1.10xea5fStandard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:22.421206951 CET192.168.2.161.1.1.10xcf4cStandard query (0)www.flysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:22.724059105 CET192.168.2.161.1.1.10x8f4Standard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:22.942981005 CET192.168.2.168.8.8.80xb55dStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:22.943484068 CET192.168.2.161.1.1.10x7a9fStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:23.948965073 CET192.168.2.161.1.1.10x5b9aStandard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:23.949227095 CET192.168.2.161.1.1.10xc104Standard query (0)www.flysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:23.955934048 CET192.168.2.168.8.4.40xafaeStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:26.316431999 CET192.168.2.161.1.1.10x954cStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:26.316579103 CET192.168.2.161.1.1.10x1ef1Standard query (0)www.google.com65IN (0x0001)false
            Oct 28, 2024 09:00:29.311135054 CET192.168.2.161.1.1.10xca4fStandard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:29.311330080 CET192.168.2.161.1.1.10xe2e7Standard query (0)www.flysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:30.328015089 CET192.168.2.161.1.1.10x9cc4Standard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:30.328208923 CET192.168.2.161.1.1.10x9b1Standard query (0)www.flysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:30.695547104 CET192.168.2.161.1.1.10xe6cStandard query (0)www.flysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.495981932 CET192.168.2.161.1.1.10x2665Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.496223927 CET192.168.2.161.1.1.10xdb0Standard query (0)wwwflysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:42.702560902 CET192.168.2.161.1.1.10x502bStandard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.835661888 CET192.168.2.161.1.1.10x1974Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.836324930 CET192.168.2.168.8.4.40xa589Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:43.843516111 CET192.168.2.161.1.1.10xf0bbStandard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:43.843782902 CET192.168.2.161.1.1.10x3824Standard query (0)wwwflysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:48.887280941 CET192.168.2.161.1.1.10xea9aStandard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:48.887454033 CET192.168.2.161.1.1.10xc8afStandard query (0)wwwflysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:00:49.034908056 CET192.168.2.161.1.1.10x8554Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:13.799653053 CET192.168.2.161.1.1.10xd623Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:19.151273966 CET192.168.2.161.1.1.10x78c2Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:19.151432991 CET192.168.2.161.1.1.10x3681Standard query (0)wwwflysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:01:19.303524017 CET192.168.2.161.1.1.10x7508Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:35.131412029 CET192.168.2.161.1.1.10xc892Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:05.584486008 CET192.168.2.161.1.1.10x5a0cStandard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:19.582314014 CET192.168.2.161.1.1.10xf24Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:19.582429886 CET192.168.2.161.1.1.10x35b8Standard query (0)wwwflysascomonlineclaimer.mywire.org65IN (0x0001)false
            Oct 28, 2024 09:02:19.730818033 CET192.168.2.161.1.1.10xd204Standard query (0)wwwflysascomonlineclaimer.mywire.orgA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 28, 2024 09:00:22.713740110 CET1.1.1.1192.168.2.160xea5fName error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:22.723339081 CET1.1.1.1192.168.2.160xcf4cName error (3)www.flysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:22.920423985 CET1.1.1.1192.168.2.160x8f4Name error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:22.951565981 CET1.1.1.1192.168.2.160x7a9fNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:24.016283035 CET8.8.4.4192.168.2.160xafaeNo error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:24.197120905 CET1.1.1.1192.168.2.160xc104Name error (3)www.flysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:24.291615963 CET1.1.1.1192.168.2.160x5b9aName error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:26.323642969 CET1.1.1.1192.168.2.160x954cNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:26.324116945 CET1.1.1.1192.168.2.160x1ef1No error (0)www.google.com65IN (0x0001)false
            Oct 28, 2024 09:00:27.285707951 CET8.8.8.8192.168.2.160xb55dNo error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:30.638189077 CET1.1.1.1192.168.2.160xca4fName error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:30.710042953 CET1.1.1.1192.168.2.160xe2e7Name error (3)www.flysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:30.729664087 CET1.1.1.1192.168.2.160x9cc4Name error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:30.741203070 CET1.1.1.1192.168.2.160x9b1Name error (3)www.flysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:30.885473967 CET1.1.1.1192.168.2.160xe6cName error (3)www.flysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.658885002 CET1.1.1.1192.168.2.160x2665Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.711282969 CET1.1.1.1192.168.2.160xdb0Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:42.824265957 CET1.1.1.1192.168.2.160x502bName error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.843044996 CET1.1.1.1192.168.2.160x1974No error (0)google.com172.217.18.14A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:42.844309092 CET8.8.4.4192.168.2.160xa589No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:43.851130962 CET1.1.1.1192.168.2.160xf0bbName error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:43.990318060 CET1.1.1.1192.168.2.160x3824Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:49.008980989 CET1.1.1.1192.168.2.160xea9aName error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:00:49.034132004 CET1.1.1.1192.168.2.160xc8afName error (3)wwwflysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:00:49.136464119 CET1.1.1.1192.168.2.160x8554Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:13.947074890 CET1.1.1.1192.168.2.160xd623Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:19.274029970 CET1.1.1.1192.168.2.160x78c2Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:19.558324099 CET1.1.1.1192.168.2.160x3681Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:01:19.558363914 CET1.1.1.1192.168.2.160x7508Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:01:35.278776884 CET1.1.1.1192.168.2.160xc892Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:05.731600046 CET1.1.1.1192.168.2.160x5a0cName error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:19.685486078 CET1.1.1.1192.168.2.160x35b8Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenone65IN (0x0001)false
            Oct 28, 2024 09:02:19.729954958 CET1.1.1.1192.168.2.160xf24Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 09:02:19.739615917 CET1.1.1.1192.168.2.160xd204Name error (3)wwwflysascomonlineclaimer.mywire.orgnonenoneA (IP address)IN (0x0001)false
            • www.google.com
            • fs.microsoft.com
            • slscr.update.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.1649705142.250.186.1004437028C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-28 08:00:27 UTC613OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
            Host: www.google.com
            Connection: keep-alive
            X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIkqHLAQj2mM0BCIWgzQEI3L3NAQiRys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUX
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: empty
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-28 08:00:27 UTC1266INHTTP/1.1 200 OK
            Date: Mon, 28 Oct 2024 08:00:27 GMT
            Pragma: no-cache
            Expires: -1
            Cache-Control: no-cache, must-revalidate
            Content-Type: text/javascript; charset=UTF-8
            Strict-Transport-Security: max-age=31536000
            Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-ZN53ak6Aif68tRGLdkkqKg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
            Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
            Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
            Accept-CH: Sec-CH-Prefers-Color-Scheme
            Accept-CH: Sec-CH-UA-Form-Factors
            Accept-CH: Sec-CH-UA-Platform
            Accept-CH: Sec-CH-UA-Platform-Version
            Accept-CH: Sec-CH-UA-Full-Version
            Accept-CH: Sec-CH-UA-Arch
            Accept-CH: Sec-CH-UA-Model
            Accept-CH: Sec-CH-UA-Bitness
            Accept-CH: Sec-CH-UA-Full-Version-List
            Accept-CH: Sec-CH-UA-WoW64
            Permissions-Policy: unload=()
            Content-Disposition: attachment; filename="f.txt"
            Server: gws
            X-XSS-Protection: 0
            X-Frame-Options: SAMEORIGIN
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Accept-Ranges: none
            Vary: Accept-Encoding
            Connection: close
            Transfer-Encoding: chunked
            2024-10-28 08:00:27 UTC112INData Raw: 33 31 66 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 64 69 77 61 6c 69 20 64 61 74 65 73 22 2c 22 6f 68 69 6f 20 68 69 67 68 20 73 63 68 6f 6f 6c 20 66 6f 6f 74 62 61 6c 6c 20 70 6c 61 79 6f 66 66 73 22 2c 22 66 75 6c 6c 20 63 61 73 74 20 74 72 61 63 6b 65 72 20 73 65 61 73 6f 6e 20 32 20 65 70 69 73 6f 64 65 20 33 22 2c 22 65 6c 66 20 73
            Data Ascii: 31f)]}'["",["diwali dates","ohio high school football playoffs","full cast tracker season 2 episode 3","elf s
            2024-10-28 08:00:27 UTC694INData Raw: 74 61 6e 6c 65 79 20 6c 69 70 20 6f 69 6c 20 68 6f 6c 64 65 72 22 2c 22 6f 70 65 6e 20 62 65 74 61 20 6d 6f 6e 73 74 65 72 20 68 75 6e 74 65 72 20 77 69 6c 64 73 22 2c 22 73 75 6e 64 61 79 20 63 61 74 68 6f 6c 69 63 20 74 76 20 6d 61 73 73 22 2c 22 61 75 72 6f 72 61 20 62 6f 72 65 61 6c 69 73 20 66 6f 72 65 63 61 73 74 22 2c 22 64 61 6c 6c 61 73 20 6d 61 76 65 72 69 63 6b 73 20 76 73 20 70 68 6f 65 6e 69 78 20 73 75 6e 73 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70 73 69 6e 66 6f 22 3a 22 43 68 67 49 6b 6b 34 53 45 77 6f 52 56
            Data Ascii: tanley lip oil holder","open beta monster hunter wilds","sunday catholic tv mass","aurora borealis forecast","dallas mavericks vs phoenix suns"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRV
            2024-10-28 08:00:27 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.1649706184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-28 08:00:29 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-28 08:00:30 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=190458
            Date: Mon, 28 Oct 2024 08:00:30 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.1649707184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-28 08:00:31 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-28 08:00:31 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=190511
            Date: Mon, 28 Oct 2024 08:00:31 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-28 08:00:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.164970820.109.210.53443
            TimestampBytes transferredDirectionData
            2024-10-28 08:00:35 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lo6w+M7asWVYflR&MD=Fdb6nu5a HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-10-28 08:00:35 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
            MS-CorrelationId: 7f4cd992-b5cd-45ce-aaff-e44ecd610fcf
            MS-RequestId: 24c6065e-0b1b-4753-a8d2-665134dba0fe
            MS-CV: YDlEu/QO/0i+dedj.0
            X-Microsoft-SLSClientCache: 2880
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Mon, 28 Oct 2024 08:00:34 GMT
            Connection: close
            Content-Length: 24490
            2024-10-28 08:00:35 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
            Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
            2024-10-28 08:00:35 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
            Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.164970920.109.210.53443
            TimestampBytes transferredDirectionData
            2024-10-28 08:01:12 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=lo6w+M7asWVYflR&MD=Fdb6nu5a HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-10-28 08:01:12 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
            MS-CorrelationId: c7feb3b0-16e7-4ba2-8dda-cd744c79fb54
            MS-RequestId: e472e1c4-016d-4ac0-b6b0-1cd31e657a6c
            MS-CV: 7Oc+ctqoOk+zPLKH.0
            X-Microsoft-SLSClientCache: 1440
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Mon, 28 Oct 2024 08:01:12 GMT
            Connection: close
            Content-Length: 30005
            2024-10-28 08:01:12 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
            Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
            2024-10-28 08:01:13 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
            Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:04:00:19
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff7f9810000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:1
            Start time:04:00:20
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1944,i,14011880240507093823,14102741856608283169,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff7f9810000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:04:00:21
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.flysascomonlineclaimer.mywire.org/WELCOME/"
            Imagebase:0x7ff7f9810000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly