Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://ejhgfuiujuytf.z28.web.core.windows.net/

Overview

General Information

Sample URL:https://ejhgfuiujuytf.z28.web.core.windows.net/
Analysis ID:1433036
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2932 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2264,i,9588583432764059645,12207997020657023467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:/// MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6548 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1076,i,5865716177844344068,6491379979185972027,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ejhgfuiujuytf.z28.web.core.windows.net/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtT5aGLyxu7EGIjBmRvg3k60CHA86WhAg8f_DzWZLnICjuMFNVpqItlNAyR0CiXsIFS6XqoN1viAjMgoyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-28-23; NID=513=STFtKW1cV9dgNrlOAgzKGe2Hk4xiyYURxhpXKvCslLCReZQAzP1S4dFtcA90IEl7sGApaeiQTcLiS5a4OxL06VcsG0fssnJsYzE-OWGjjYRTkFn1xDknTUSZdPCzohdAhfplHLUx5T2pRugi6UDjLpd2ZxMQjARh9SwsOnGFr5c
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtT5aGLyxu7EGIjDnZTj4xwn7ol3UU-E0Z-F62zxHP09Qw5jvZu3xhYhTxYirDVBo3joR5tht7VYvWaIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-28-23; NID=513=d_-y9fQ7OqvxAe7fb8aFFkWmdVVdgv0aNY0tb5HEnLH_rGOGV6R1ztL9UowQ51PDjwRpHxiNaziaP4hkCY9kstufEVD2KNae0-bLu6yoqqcY-_rVkgzr-vB5uhfFI5BvAg0Qi3sA2C3zYZ06Bq3UkOhxU2uG9FelYw8qJyAB0w4
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtT5aGLyxu7EGIjB_7TCxg5sVrRokyHpB8zqsv3IEcYNBnYFnKuXNEICQkFW9PKW7eSZnD00RdKpXeigyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-28-23; NID=513=StgM3MlSRXP7Lc3J2_VxQpiPG_Iom18ssucediBWequolHoAi1SOAtfSKaGrpalCk3UjI_R4bhy1eiL7OOBSk2IDCbsL79l0t8KEQUci-OHCuaWl6mBBvM8r0erEn-vlCmebs-NFRJqDP-tr4yXVd6vhIDJXt8gMfLkWnrRsoK4
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@26/2@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2264,i,9588583432764059645,12207997020657023467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1076,i,5865716177844344068,6491379979185972027,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ejhgfuiujuytf.z28.web.core.windows.net/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2264,i,9588583432764059645,12207997020657023467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1076,i,5865716177844344068,6491379979185972027,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1433036 URL: https://ejhgfuiujuytf.z28.w... Startdate: 29/04/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 2->5         started        8 chrome.exe 2->8         started        10 chrome.exe 2->10         started        dnsIp3 17 192.168.2.4, 138, 443, 49423 unknown unknown 5->17 19 239.255.255.250 unknown Reserved 5->19 12 chrome.exe 5->12         started        15 chrome.exe 8->15         started        process4 dnsIp5 21 www.google.com 142.250.191.132, 443, 49735, 49736 GOOGLEUS United States 12->21 23 google.com 12->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://ejhgfuiujuytf.z28.web.core.windows.net/0%Avira URL Cloudsafe
https://ejhgfuiujuytf.z28.web.core.windows.net/2%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.190.142
truefalse
    high
    www.google.com
    142.250.191.132
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtT5aGLyxu7EGIjBmRvg3k60CHA86WhAg8f_DzWZLnICjuMFNVpqItlNAyR0CiXsIFS6XqoN1viAjMgoyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
          high
          https://www.google.com/async/ddljson?async=ntp:2false
            high
            https://www.google.com/async/newtab_promosfalse
              high
              https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
                high
                https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0false
                  high
                  https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtT5aGLyxu7EGIjDnZTj4xwn7ol3UU-E0Z-F62zxHP09Qw5jvZu3xhYhTxYirDVBo3joR5tht7VYvWaIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
                    high
                    https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtT5aGLyxu7EGIjB_7TCxg5sVrRokyHpB8zqsv3IEcYNBnYFnKuXNEICQkFW9PKW7eSZnD00RdKpXeigyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      142.250.191.132
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.2.4
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1433036
                      Start date and time:2024-04-29 01:15:19 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 2m 4s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:https://ejhgfuiujuytf.z28.web.core.windows.net/
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:7
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:UNKNOWN
                      Classification:unknown0.win@26/2@4/3
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • URL browsing timeout or error
                      • URL not reachable
                      • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 172.217.2.35, 142.250.191.206, 142.250.112.84, 34.104.35.123, 23.11.208.106, 40.127.169.103, 72.21.81.240, 192.229.211.108, 13.95.31.18
                      • Excluded domains from analysis (whitelisted): ejhgfuiujuytf.z28.web.core.windows.net, slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtSetInformationFile calls found.
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (3238)
                      Category:downloaded
                      Size (bytes):3243
                      Entropy (8bit):5.819056280673524
                      Encrypted:false
                      SSDEEP:96:3vdjliAUIN6666VUBOGXeKKO+g8+hbzFl9nf8nXCfQfffo:FZTN6666VWXeKagPhbxXnEM
                      MD5:F111BAACB030F3D50593978A649B1544
                      SHA1:921B473A77FDA3FFE93AE475463DEBB694E3C0B4
                      SHA-256:DC5613569AA869CF0528D0D424592F05ADEA163D6CAE4935C401722936D1656A
                      SHA-512:F86CF77104C502ED70E3C97978EB4C5A57E7EBD6BEAA26986F5393C88CD9A03187C4E7F0763BED1AD49A9C4A74C37ED0C4966082F2E3E22ED56151B67B9266C5
                      Malicious:false
                      Reputation:low
                      URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                      Preview:)]}'.["",["wordle today answer april 28","troy franklin nfl draft","bob bakish","baseball","stardew valley 1.6 console update","horoscope today aries","prime energy drink","household cavalry horses london"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"google:entityinfo":"CgovbS8wYm1jNnhnEh1QcmVzaWRlbnQgb2YgUGFyYW1vdW50IEdsb2JhbDK7DWRhdGE6aW1hZ2UvanBlZztiYXNlNjQsLzlqLzRBQVFTa1pKUmdBQkFRQUFBUUFCQUFELzJ3Q0VBQWtHQndnSEJna0lCd2dLQ2drTERSWVBEUXdNRFJzVUZSQVdJQjBpSWlBZEh4OGtLRFFzSkNZeEp4OGZMVDB0TVRVM09qbzZJeXMvUkQ4NFF6UTVPamNCQ2dvS0RRd05HZzhQR2pjbEh5VTNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTi8vQUFCRUlBRUFBUUFNQklnQUNFUUVERVFIL3hBQWNBQUFDQXdFQkFRRUFBQUFBQUFBQUFBQUZCZ01FQndnQ0FRRC94QUEwRUFBQkFnVUJCUVlGQXdVQUFBQUFBQUFCQWdNQUJBVVJFaUVHRXlJeFFWRmhjWUdoc1FjVUl6S1IwZUh4RlVKeXNzSC94QUFaQVFBQ0F3RUFBQUFBQUFBQUFBQ
                      No static file info
                      TimestampSource PortDest PortSource IPDest IP
                      Apr 29, 2024 01:16:02.246979952 CEST49678443192.168.2.4104.46.162.224
                      Apr 29, 2024 01:16:02.371959925 CEST49675443192.168.2.4173.222.162.32
                      Apr 29, 2024 01:16:11.592140913 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.592190027 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.592267990 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.593436003 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.593453884 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.647857904 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.647907019 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.648046017 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.648314953 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.648359060 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.772597075 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.772651911 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.772718906 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.773217916 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.773298025 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.773454905 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.773472071 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.773492098 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.773694992 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.773727894 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.834176064 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.834464073 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.834480047 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.835907936 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.835968971 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.837141991 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.837224007 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.837321043 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.880121946 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.885910988 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.886364937 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.886390924 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.887285948 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.887382984 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.888231039 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.888289928 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.888571024 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:11.888583899 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:11.960532904 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.008328915 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.008708954 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.008759975 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.008765936 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.008971930 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.009016991 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.009644985 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.009716988 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.009892941 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.010118961 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.010440111 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.010499954 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.010768890 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.010838985 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.011179924 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.011195898 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.011238098 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.011254072 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.048126936 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.049740076 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.070035934 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.070041895 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.081931114 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.081991911 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.082030058 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.082145929 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.082169056 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.083559990 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.086339951 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.086431026 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.086458921 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.086471081 CEST44349735142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.086489916 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.086520910 CEST49735443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.151748896 CEST49675443192.168.2.4173.222.162.32
                      Apr 29, 2024 01:16:12.457926989 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.457993984 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.458022118 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.458035946 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.458085060 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.461018085 CEST49737443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.461035967 CEST44349737142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.467639923 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.467722893 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.467750072 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.468230963 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.468286037 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.475014925 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.475047112 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.475105047 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.476629972 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.476644039 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.477210999 CEST49736443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.477233887 CEST44349736142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.486797094 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.486833096 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.486892939 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.487349987 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.487365007 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.593065977 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.593141079 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.593175888 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.594233036 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.594275951 CEST44349738142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.594331026 CEST49738443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.599126101 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.599199057 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.599282026 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.600039005 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.600087881 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.711179018 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.711703062 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.711714029 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.712173939 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.713417053 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.713499069 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.713588953 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.719615936 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.719969988 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.719984055 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.720277071 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.720822096 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.720877886 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.721138954 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.760148048 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.768116951 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.832019091 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.867954016 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.868024111 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.868902922 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.868978977 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.869492054 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.869554996 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.869663954 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.869680882 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.948694944 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.948757887 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.948796988 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.948801041 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.948812008 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.948851109 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.949115038 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.949176073 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.949218988 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.950328112 CEST49739443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.950335026 CEST44349739142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.950442076 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.956756115 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.956799030 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.956830978 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.956841946 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.956892967 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:12.956933022 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.958811998 CEST49740443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:12.958823919 CEST44349740142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:13.069166899 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:13.069202900 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:13.069243908 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:13.069274902 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:13.069288969 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:13.069340944 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:13.086647034 CEST49741443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:13.086682081 CEST44349741142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.390543938 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:15.390625954 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.390710115 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:15.391097069 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:15.391128063 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.631166935 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.631623030 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:15.631666899 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.632797956 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.633797884 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:15.633977890 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:15.720439911 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:25.636120081 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:25.636195898 CEST44349743142.250.191.132192.168.2.4
                      Apr 29, 2024 01:16:25.636240959 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:26.060715914 CEST49743443192.168.2.4142.250.191.132
                      Apr 29, 2024 01:16:26.060740948 CEST44349743142.250.191.132192.168.2.4
                      TimestampSource PortDest PortSource IPDest IP
                      Apr 29, 2024 01:16:10.760320902 CEST53595091.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:10.766427994 CEST53621871.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:11.477683067 CEST5693453192.168.2.41.1.1.1
                      Apr 29, 2024 01:16:11.477884054 CEST4993253192.168.2.41.1.1.1
                      Apr 29, 2024 01:16:11.588649988 CEST53569341.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:11.588695049 CEST53499321.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:11.945437908 CEST53653191.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:12.556509972 CEST53543571.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:12.571345091 CEST53582691.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:12.715998888 CEST53553531.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:12.866884947 CEST5621853192.168.2.48.8.8.8
                      Apr 29, 2024 01:16:12.867419004 CEST5168953192.168.2.41.1.1.1
                      Apr 29, 2024 01:16:12.978828907 CEST53516891.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:12.987428904 CEST53562188.8.8.8192.168.2.4
                      Apr 29, 2024 01:16:15.532464027 CEST53603381.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:15.541471958 CEST53555101.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:22.474668026 CEST53577981.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:22.479619026 CEST53609491.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:22.629483938 CEST53494231.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:30.437107086 CEST53541451.1.1.1192.168.2.4
                      Apr 29, 2024 01:16:32.767848969 CEST138138192.168.2.4192.168.2.255
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Apr 29, 2024 01:16:11.477683067 CEST192.168.2.41.1.1.10xc704Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Apr 29, 2024 01:16:11.477884054 CEST192.168.2.41.1.1.10xa54dStandard query (0)www.google.com65IN (0x0001)false
                      Apr 29, 2024 01:16:12.866884947 CEST192.168.2.48.8.8.80x14beStandard query (0)google.comA (IP address)IN (0x0001)false
                      Apr 29, 2024 01:16:12.867419004 CEST192.168.2.41.1.1.10x6a91Standard query (0)google.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Apr 29, 2024 01:16:11.588649988 CEST1.1.1.1192.168.2.40xc704No error (0)www.google.com142.250.191.132A (IP address)IN (0x0001)false
                      Apr 29, 2024 01:16:11.588695049 CEST1.1.1.1192.168.2.40xa54dNo error (0)www.google.com65IN (0x0001)false
                      Apr 29, 2024 01:16:12.978828907 CEST1.1.1.1192.168.2.40x6a91No error (0)google.com142.250.190.142A (IP address)IN (0x0001)false
                      Apr 29, 2024 01:16:12.987428904 CEST8.8.8.8192.168.2.40x14beNo error (0)google.com142.250.190.46A (IP address)IN (0x0001)false
                      Apr 29, 2024 01:16:25.694837093 CEST1.1.1.1192.168.2.40x8a14No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Apr 29, 2024 01:16:25.694837093 CEST1.1.1.1192.168.2.40x8a14No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                      • www.google.com
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.449735142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:11 UTC615OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-04-28 23:16:12 UTC1703INHTTP/1.1 200 OK
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Pragma: no-cache
                      Expires: -1
                      Cache-Control: no-cache, must-revalidate
                      Content-Type: text/javascript; charset=UTF-8
                      Strict-Transport-Security: max-age=31536000
                      Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-JrYrZoui6MIrjBCPchRbLA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                      Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                      Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                      Accept-CH: Sec-CH-UA-Platform
                      Accept-CH: Sec-CH-UA-Platform-Version
                      Accept-CH: Sec-CH-UA-Full-Version
                      Accept-CH: Sec-CH-UA-Arch
                      Accept-CH: Sec-CH-UA-Model
                      Accept-CH: Sec-CH-UA-Bitness
                      Accept-CH: Sec-CH-UA-Full-Version-List
                      Accept-CH: Sec-CH-UA-WoW64
                      Permissions-Policy: unload=()
                      Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                      Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                      Content-Disposition: attachment; filename="f.txt"
                      Server: gws
                      X-XSS-Protection: 0
                      X-Frame-Options: SAMEORIGIN
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2024-04-28 23:16:12 UTC1703INData Raw: 63 61 62 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 77 6f 72 64 6c 65 20 74 6f 64 61 79 20 61 6e 73 77 65 72 20 61 70 72 69 6c 20 32 38 22 2c 22 74 72 6f 79 20 66 72 61 6e 6b 6c 69 6e 20 6e 66 6c 20 64 72 61 66 74 22 2c 22 62 6f 62 20 62 61 6b 69 73 68 22 2c 22 62 61 73 65 62 61 6c 6c 22 2c 22 73 74 61 72 64 65 77 20 76 61 6c 6c 65 79 20 31 2e 36 20 63 6f 6e 73 6f 6c 65 20 75 70 64 61 74 65 22 2c 22 68 6f 72 6f 73 63 6f 70 65 20 74 6f 64 61 79 20 61 72 69 65 73 22 2c 22 70 72 69 6d 65 20 65 6e 65 72 67 79 20 64 72 69 6e 6b 22 2c 22 68 6f 75 73 65 68 6f 6c 64 20 63 61 76 61 6c 72 79 20 68 6f 72 73 65 73 20 6c 6f 6e 64 6f 6e 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e
                      Data Ascii: cab)]}'["",["wordle today answer april 28","troy franklin nfl draft","bob bakish","baseball","stardew valley 1.6 console update","horoscope today aries","prime energy drink","household cavalry horses london"],["","","","","","","",""],[],{"google:clien
                      2024-04-28 23:16:12 UTC1547INData Raw: 4d 64 44 64 55 52 31 42 57 5a 6d 52 4e 4d 6a 5a 4f 53 6e 64 68 4f 57 63 33 59 58 56 76 64 45 64 57 62 54 4a 35 4d 6d 39 43 64 54 5a 57 52 57 63 34 4c 30 6c 49 4d 58 52 42 52 46 6c 34 56 47 4a 47 55 47 5a 44 4c 33 5a 6a 62 6b 5a 46 57 44 5a 45 52 6b 31 47 52 46 68 47 55 46 52 7a 4b 7a 41 76 53 6b 70 44 55 32 35 6c 54 6d 39 36 51 33 70 6a 52 46 55 32 55 55 73 79 5a 46 46 30 4d 6c 59 7a 4d 6b 4a 50 56 54 42 77 56 32 63 34 53 55 78 54 63 6a 56 46 4d 58 5a 47 59 55 64 34 5a 7a 4a 74 55 56 42 69 64 32 64 77 54 48 56 7a 57 6b 78 52 51 56 4e 56 4f 56 4e 5a 62 33 6b 33 53 55 74 75 57 45 5a 77 54 6d 68 69 52 54 6b 34 55 55 31 51 53 55 52 36 62 6a 46 52 51 32 38 79 51 57 70 68 4b 31 52 74 63 6b 74 46 55 31 68 79 59 6a 67 76 53 6a 46 4f 51 31 70 6b 62 30 39 71 52 6e
                      Data Ascii: MdDdUR1BWZmRNMjZOSndhOWc3YXVvdEdWbTJ5Mm9CdTZWRWc4L0lIMXRBRFl4VGJGUGZDL3ZjbkZFWDZERk1GRFhGUFRzKzAvSkpDU25lTm96Q3pjRFU2UUsyZFF0MlYzMkJPVTBwV2c4SUxTcjVFMXZGYUd4ZzJtUVBid2dwTHVzWkxRQVNVOVNZb3k3SUtuWEZwTmhiRTk4UU1QSUR6bjFRQ28yQWphK1RtcktFU1hyYjgvSjFOQ1pkb09qRn
                      2024-04-28 23:16:12 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.449736142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:11 UTC353OUTGET /async/ddljson?async=ntp:2 HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-04-28 23:16:12 UTC1816INHTTP/1.1 302 Found
                      Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtT5aGLyxu7EGIjDnZTj4xwn7ol3UU-E0Z-F62zxHP09Qw5jvZu3xhYhTxYirDVBo3joR5tht7VYvWaIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                      x-hallmonitor-challenge: CgwIvLG7sQYQiNH9wAESBFG1Plo
                      Content-Type: text/html; charset=UTF-8
                      Strict-Transport-Security: max-age=31536000
                      Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                      Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                      Permissions-Policy: unload=()
                      Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                      Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                      P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Server: gws
                      Content-Length: 427
                      X-XSS-Protection: 0
                      X-Frame-Options: SAMEORIGIN
                      Set-Cookie: 1P_JAR=2024-04-28-23; expires=Tue, 28-May-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; SameSite=none
                      Set-Cookie: NID=513=d_-y9fQ7OqvxAe7fb8aFFkWmdVVdgv0aNY0tb5HEnLH_rGOGV6R1ztL9UowQ51PDjwRpHxiNaziaP4hkCY9kstufEVD2KNae0-bLu6yoqqcY-_rVkgzr-vB5uhfFI5BvAg0Qi3sA2C3zYZ06Bq3UkOhxU2uG9FelYw8qJyAB0w4; expires=Mon, 28-Oct-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:12 UTC427INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 64 64 6c 6a 73 6f 6e 25 33 46 61 73 79 6e
                      Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasyn


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.449738142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:12 UTC518OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                      Sec-Fetch-Site: cross-site
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-04-28 23:16:12 UTC1843INHTTP/1.1 302 Found
                      Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtT5aGLyxu7EGIjB_7TCxg5sVrRokyHpB8zqsv3IEcYNBnYFnKuXNEICQkFW9PKW7eSZnD00RdKpXeigyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                      x-hallmonitor-challenge: CgwIvLG7sQYQ3LaO-QESBFG1Plo
                      Content-Type: text/html; charset=UTF-8
                      Strict-Transport-Security: max-age=31536000
                      Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                      Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                      Permissions-Policy: unload=()
                      Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                      Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                      P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Server: gws
                      Content-Length: 458
                      X-XSS-Protection: 0
                      X-Frame-Options: SAMEORIGIN
                      Set-Cookie: 1P_JAR=2024-04-28-23; expires=Tue, 28-May-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; SameSite=none
                      Set-Cookie: NID=513=StgM3MlSRXP7Lc3J2_VxQpiPG_Iom18ssucediBWequolHoAi1SOAtfSKaGrpalCk3UjI_R4bhy1eiL7OOBSk2IDCbsL79l0t8KEQUci-OHCuaWl6mBBvM8r0erEn-vlCmebs-NFRJqDP-tr4yXVd6vhIDJXt8gMfLkWnrRsoK4; expires=Mon, 28-Oct-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:12 UTC458INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 25 33 46 68
                      Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fh


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.449737142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:12 UTC353OUTGET /async/newtab_promos HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      Sec-Fetch-Site: cross-site
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-04-28 23:16:12 UTC1761INHTTP/1.1 302 Found
                      Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtT5aGLyxu7EGIjBmRvg3k60CHA86WhAg8f_DzWZLnICjuMFNVpqItlNAyR0CiXsIFS6XqoN1viAjMgoyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                      x-hallmonitor-challenge: CgwIvLG7sQYQm_mqvAESBFG1Plo
                      Content-Type: text/html; charset=UTF-8
                      Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                      Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                      Permissions-Policy: unload=()
                      Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                      Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                      P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Server: gws
                      Content-Length: 417
                      X-XSS-Protection: 0
                      X-Frame-Options: SAMEORIGIN
                      Set-Cookie: 1P_JAR=2024-04-28-23; expires=Tue, 28-May-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; SameSite=none
                      Set-Cookie: NID=513=STFtKW1cV9dgNrlOAgzKGe2Hk4xiyYURxhpXKvCslLCReZQAzP1S4dFtcA90IEl7sGApaeiQTcLiS5a4OxL06VcsG0fssnJsYzE-OWGjjYRTkFn1xDknTUSZdPCzohdAhfplHLUx5T2pRugi6UDjLpd2ZxMQjARh9SwsOnGFr5c; expires=Mon, 28-Oct-2024 23:16:12 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:12 UTC417INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 26
                      Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.449739142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:12 UTC738OUTGET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtT5aGLyxu7EGIjBmRvg3k60CHA86WhAg8f_DzWZLnICjuMFNVpqItlNAyR0CiXsIFS6XqoN1viAjMgoyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      Sec-Fetch-Site: cross-site
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: 1P_JAR=2024-04-28-23; NID=513=STFtKW1cV9dgNrlOAgzKGe2Hk4xiyYURxhpXKvCslLCReZQAzP1S4dFtcA90IEl7sGApaeiQTcLiS5a4OxL06VcsG0fssnJsYzE-OWGjjYRTkFn1xDknTUSZdPCzohdAhfplHLUx5T2pRugi6UDjLpd2ZxMQjARh9SwsOnGFr5c
                      2024-04-28 23:16:12 UTC356INHTTP/1.1 429 Too Many Requests
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Pragma: no-cache
                      Expires: Fri, 01 Jan 1990 00:00:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate
                      Content-Type: text/html
                      Server: HTTP server (unknown)
                      Content-Length: 3111
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:12 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64
                      Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_promos</title></head
                      2024-04-28 23:16:12 UTC1255INData Raw: 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 7a 68 52 4c 2d 52 65 6f 41 75 66 4a 77 4d 4c 69 43 30 68 34 64 4e 52 4c 73 78 43 44 38 67 5f 57 36
                      Data Ascii: ack = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="zhRL-ReoAufJwMLiC0h4dNRLsxCD8g_W6
                      2024-04-28 23:16:12 UTC957INData Raw: 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74 65 72 20 74 68 6f 73 65 20 72 65 71 75 65 73 74 73 20 73 74 6f 70 2e 20 20 49 6e 20 74 68 65 20 6d 65 61 6e 74 69 6d 65 2c 20 73 6f 6c 76 69 6e
                      Data Ascii: ogle automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly after those requests stop. In the meantime, solvin


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.449740142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:12 UTC742OUTGET /sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtT5aGLyxu7EGIjDnZTj4xwn7ol3UU-E0Z-F62zxHP09Qw5jvZu3xhYhTxYirDVBo3joR5tht7VYvWaIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: 1P_JAR=2024-04-28-23; NID=513=d_-y9fQ7OqvxAe7fb8aFFkWmdVVdgv0aNY0tb5HEnLH_rGOGV6R1ztL9UowQ51PDjwRpHxiNaziaP4hkCY9kstufEVD2KNae0-bLu6yoqqcY-_rVkgzr-vB5uhfFI5BvAg0Qi3sA2C3zYZ06Bq3UkOhxU2uG9FelYw8qJyAB0w4
                      2024-04-28 23:16:12 UTC356INHTTP/1.1 429 Too Many Requests
                      Date: Sun, 28 Apr 2024 23:16:12 GMT
                      Pragma: no-cache
                      Expires: Fri, 01 Jan 1990 00:00:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate
                      Content-Type: text/html
                      Server: HTTP server (unknown)
                      Content-Length: 3129
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:12 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 64 64 6c 6a 73 6f 6e 3f 61 73 79 6e 63 3d 6e 74 70 3a 32 3c 2f 74 69 74 6c 65 3e
                      Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/ddljson?async=ntp:2</title>
                      2024-04-28 23:16:12 UTC1255INData Raw: 74 43 61 6c 6c 62 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 57 76 57 79 32 59 61 55 76 48 4d 47 65 72 75 6d 35 30 79 5a 57 42 69 61 2d 52 4a
                      Data Ascii: tCallback = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="WvWy2YaUvHMGerum50yZWBia-RJ
                      2024-04-28 23:16:12 UTC975INData Raw: 65 61 72 73 20 77 68 65 6e 20 47 6f 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74 65 72 20 74 68 6f 73 65 20 72 65 71 75 65 73 74 73 20 73 74 6f 70 2e 20 20 49 6e 20 74 68 65 20 6d 65 61 6e
                      Data Ascii: ears when Google automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly after those requests stop. In the mean


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      6192.168.2.449741142.250.191.1324432932C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-04-28 23:16:12 UTC920OUTGET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtT5aGLyxu7EGIjB_7TCxg5sVrRokyHpB8zqsv3IEcYNBnYFnKuXNEICQkFW9PKW7eSZnD00RdKpXeigyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                      Host: www.google.com
                      Connection: keep-alive
                      X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiVocsBCJz+zAEIhaDNAQjcvc0BCJDKzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                      Sec-Fetch-Site: cross-site
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: 1P_JAR=2024-04-28-23; NID=513=StgM3MlSRXP7Lc3J2_VxQpiPG_Iom18ssucediBWequolHoAi1SOAtfSKaGrpalCk3UjI_R4bhy1eiL7OOBSk2IDCbsL79l0t8KEQUci-OHCuaWl6mBBvM8r0erEn-vlCmebs-NFRJqDP-tr4yXVd6vhIDJXt8gMfLkWnrRsoK4
                      2024-04-28 23:16:13 UTC356INHTTP/1.1 429 Too Many Requests
                      Date: Sun, 28 Apr 2024 23:16:13 GMT
                      Pragma: no-cache
                      Expires: Fri, 01 Jan 1990 00:00:00 GMT
                      Cache-Control: no-store, no-cache, must-revalidate
                      Content-Type: text/html
                      Server: HTTP server (unknown)
                      Content-Length: 3183
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Connection: close
                      2024-04-28 23:16:13 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 3f 68 6c 3d 65 6e 2d 55 53 26 61 6d 70 3b 61 73 79
                      Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_ogb?hl=en-US&amp;asy
                      2024-04-28 23:16:13 UTC1255INData Raw: 0a 3c 73 63 72 69 70 74 3e 76 61 72 20 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 36 54 67 77 4a 31 45 55 70
                      Data Ascii: <script>var submitCallback = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="6TgwJ1EUp
                      2024-04-28 23:16:13 UTC1029INData Raw: 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 2e 34 65 6d 3b 22 3e 0a 54 68 69 73 20 70 61 67 65 20 61 70 70 65 61 72 73 20 77 68 65 6e 20 47 6f 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74
                      Data Ascii: ; line-height:1.4em;">This page appears when Google automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly aft


                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:01:16:04
                      Start date:29/04/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:1
                      Start time:01:16:08
                      Start date:29/04/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2264,i,9588583432764059645,12207997020657023467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:3
                      Start time:01:16:09
                      Start date:29/04/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      Target ID:4
                      Start time:01:16:10
                      Start date:29/04/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1076,i,5865716177844344068,6491379979185972027,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      Target ID:5
                      Start time:01:16:11
                      Start date:29/04/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ejhgfuiujuytf.z28.web.core.windows.net/"
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      No disassembly