Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://zwgaleriamlodych.pl

Overview

General Information

Sample URL:http://zwgaleriamlodych.pl
Analysis ID:1395948
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Creates files inside the system directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3320 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: highperformancedformats.comVirustotal: Detection: 6%Perma Link
Source: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: zwgaleriamlodych.plConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3 HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"sec-ch-ua-model: ""sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: u_pl=15107318
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: u_pl=15107318
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /anonymous/ HTTP/1.1Host: highperformancedformats.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.21.6Date: Wed, 21 Feb 2024 08:24:57 GMTContent-Type: text/htmlContent-Length: 0Connection: keep-aliveP3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UA
Source: chromecache_41.1.drString found in binary or memory: http://highperformancedformats.com/anonymous/
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_3320_1322997098Jump to behavior
Source: classification engineClassification label: mal48.win@19/2@16/9
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://zwgaleriamlodych.pl0%Avira URL Cloudsafe
http://zwgaleriamlodych.pl0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
dilutegulpedshirt.com1%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
highperformancedformats.com7%VirustotalBrowse
zwgaleriamlodych.pl0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://zwgaleriamlodych.pl/0%Avira URL Cloudsafe
http://highperformancedformats.com/anonymous/0%Avira URL Cloudsafe
https://dilutegulpedshirt.com/favicon.ico0%Avira URL Cloudsafe
https://zwgaleriamlodych.pl/0%VirustotalBrowse
http://highperformancedformats.com/anonymous/3%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
dilutegulpedshirt.com
192.243.61.227
truefalseunknown
accounts.google.com
172.253.122.84
truefalse
    high
    highperformancedformats.com
    172.240.108.76
    truefalseunknown
    www.google.com
    142.251.35.164
    truefalse
      high
      clients.l.google.com
      142.250.65.174
      truefalse
        high
        zwgaleriamlodych.pl
        172.67.160.242
        truefalseunknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalseunknown
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://zwgaleriamlodych.pl/false
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://dilutegulpedshirt.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3false
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://highperformancedformats.com/anonymous/false
                • 3%, Virustotal, Browse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.240.108.76
                highperformancedformats.comUnited States
                7979SERVERS-COMUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.65.174
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                192.243.61.227
                dilutegulpedshirt.comDominica
                39572ADVANCEDHOSTERS-ASNLfalse
                172.240.108.84
                unknownUnited States
                7979SERVERS-COMUSfalse
                104.21.9.178
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                142.251.35.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                172.253.122.84
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1395948
                Start date and time:2024-02-21 09:23:48 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 8s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://zwgaleriamlodych.pl
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@19/2@16/9
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Browse: http://highperformancedformats.com/anonymous/
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.65.195, 34.104.35.123, 13.85.23.86, 104.102.251.17, 104.102.251.57, 192.229.211.108, 52.165.164.15, 20.3.187.198, 142.251.40.227
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):115
                Entropy (8bit):4.719823396275518
                Encrypted:false
                SSDEEP:3:uNXADiFCDRAWMO5h1KRWLRE+Vs2+ZJiNRDs7SGKy:uFAyTWLhgRW2+T+ZJas7Sdy
                MD5:16579CC322E9E105427ECFA57890EF69
                SHA1:8BB47EC30CF894AB49032D7271A45F0C778BAA05
                SHA-256:F28CE5BEFE08ED90A2E12B6B2A5E9FDAFAA6AD173503079155260AA480C66590
                SHA-512:FCF36F77D99F6594929BDED28F200BEE11FAB9B316A5E437567345B8877CFC6707BF8A116C03F07B03C0235B587E71DBD4843560564BAE07BAD2F5B6295CCE3F
                Malicious:false
                Reputation:low
                URL:https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3
                Preview:<a href = 'http://highperformancedformats.com/anonymous/' target='_blank'>Anonymous Proxy detected, click here.</a>
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 09:24:36.143358946 CET49675443192.168.2.4173.222.162.32
                Feb 21, 2024 09:24:42.209597111 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.209681988 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.209758043 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.210087061 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210109949 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.210161924 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210534096 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.210566998 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.210803032 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210815907 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.413261890 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414351940 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.414361954 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414804935 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414859056 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.415807962 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.415854931 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426202059 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426259995 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.426382065 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426388979 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.429553032 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.430176020 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.430231094 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.431695938 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.431768894 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.436444044 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.436537027 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.440104008 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.440120935 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.485451937 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.522351980 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.613079071 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.613236904 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.613291025 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.618107080 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.618122101 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.646348000 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.646761894 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.646841049 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.647708893 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.647747993 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:43.693319082 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693402052 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.693501949 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693700075 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693717957 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.897238970 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.897588015 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.897607088 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.899080992 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.899147987 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900043964 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900126934 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.900249004 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900257111 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.049365044 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.303739071 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.304162025 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.304239988 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.308173895 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.308196068 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.399168015 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399208069 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.399279118 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399602890 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399651051 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.707329035 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.707763910 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.707819939 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.709606886 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.709693909 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.710772991 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.710869074 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.710987091 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.711003065 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.766478062 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.809854031 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.810112000 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.810306072 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.811184883 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.811218977 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.887384892 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887479067 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.887559891 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887871981 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887904882 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.181703091 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.181988955 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.182018995 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.182740927 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.183116913 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.183151007 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.183213949 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.235363007 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.277672052 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.277854919 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.278012991 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.279342890 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.279373884 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.395627022 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.395721912 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.395803928 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.406122923 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.406155109 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.598539114 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.598598957 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.598680973 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.599139929 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.599173069 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.702404976 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.704034090 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.704070091 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.705535889 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.705620050 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.706634998 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.706727982 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.707139015 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.707154036 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.751132965 CET49675443192.168.2.4173.222.162.32
                Feb 21, 2024 09:24:45.751153946 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.799972057 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.801326036 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.801480055 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.801541090 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.814830065 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.814866066 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.818666935 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.818749905 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.846514940 CET49739443192.168.2.4172.240.108.84
                Feb 21, 2024 09:24:45.846550941 CET44349739172.240.108.84192.168.2.4
                Feb 21, 2024 09:24:45.853091002 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.853532076 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.907371044 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:45.907428026 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:45.954256058 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:46.865315914 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:46.865396976 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:46.865477085 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:46.886964083 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:46.887001038 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.088203907 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.088278055 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.094974041 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.094991922 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.095383883 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.141901970 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.191411018 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.237946987 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.280407906 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.280522108 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.280570984 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.280618906 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.280649900 CET49742443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.280667067 CET4434974223.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.338109016 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.338179111 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.338255882 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.338713884 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.338745117 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.532396078 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.532485008 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.534153938 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.534168959 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.534611940 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.537051916 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.581947088 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.707839012 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.708038092 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.708257914 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.709328890 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.709328890 CET49743443192.168.2.423.54.68.82
                Feb 21, 2024 09:24:47.709357977 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:47.709383965 CET4434974323.54.68.82192.168.2.4
                Feb 21, 2024 09:24:55.850434065 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:55.850589037 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:55.850725889 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:56.488506079 CET49740443192.168.2.4142.251.35.164
                Feb 21, 2024 09:24:56.488568068 CET44349740142.251.35.164192.168.2.4
                Feb 21, 2024 09:24:56.867474079 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:24:56.868704081 CET4974580192.168.2.4172.240.108.76
                Feb 21, 2024 09:24:56.961117029 CET8049744172.240.108.76192.168.2.4
                Feb 21, 2024 09:24:56.961358070 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:24:56.961513042 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:24:56.962565899 CET8049745172.240.108.76192.168.2.4
                Feb 21, 2024 09:24:56.962632895 CET4974580192.168.2.4172.240.108.76
                Feb 21, 2024 09:24:57.055145979 CET8049744172.240.108.76192.168.2.4
                Feb 21, 2024 09:24:57.055377960 CET8049744172.240.108.76192.168.2.4
                Feb 21, 2024 09:24:57.096818924 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:00.788743973 CET4972380192.168.2.472.21.81.240
                Feb 21, 2024 09:25:00.876044035 CET804972372.21.81.240192.168.2.4
                Feb 21, 2024 09:25:00.876302004 CET4972380192.168.2.472.21.81.240
                Feb 21, 2024 09:25:07.056005001 CET8049744172.240.108.76192.168.2.4
                Feb 21, 2024 09:25:07.056092024 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:08.504194021 CET4974480192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:08.597879887 CET8049744172.240.108.76192.168.2.4
                Feb 21, 2024 09:25:41.970057964 CET4974580192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:42.063657999 CET8049745172.240.108.76192.168.2.4
                Feb 21, 2024 09:25:45.545557022 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:45.545595884 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.545664072 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:45.546287060 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:45.546303988 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.741130114 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.741806030 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:45.741833925 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.742477894 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.743201017 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:45.743292093 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:45.798320055 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:50.360949039 CET4972480192.168.2.472.21.81.240
                Feb 21, 2024 09:25:50.448694944 CET804972472.21.81.240192.168.2.4
                Feb 21, 2024 09:25:50.448884964 CET4972480192.168.2.472.21.81.240
                Feb 21, 2024 09:25:55.786014080 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:55.786144018 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:55.786381960 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:56.729043961 CET49753443192.168.2.4142.251.35.164
                Feb 21, 2024 09:25:56.729137897 CET44349753142.251.35.164192.168.2.4
                Feb 21, 2024 09:25:57.055782080 CET8049745172.240.108.76192.168.2.4
                Feb 21, 2024 09:25:57.055867910 CET4974580192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:58.487685919 CET4974580192.168.2.4172.240.108.76
                Feb 21, 2024 09:25:58.581413984 CET8049745172.240.108.76192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 09:24:42.117466927 CET6194253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.117759943 CET5249853192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.118524075 CET5297353192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.118746042 CET5805653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.188942909 CET53508711.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.205507994 CET53619421.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206618071 CET53529731.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206737041 CET53524981.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206865072 CET53580561.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.752068043 CET53595461.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.500464916 CET5734253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.500746965 CET5695753192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.590240955 CET53573421.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.590987921 CET53569571.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.592792034 CET5159653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.593051910 CET6435853192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.681495905 CET53515961.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.692238092 CET53643581.1.1.1192.168.2.4
                Feb 21, 2024 09:24:44.309912920 CET5459053192.168.2.41.1.1.1
                Feb 21, 2024 09:24:44.310506105 CET5952653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:44.398276091 CET53545901.1.1.1192.168.2.4
                Feb 21, 2024 09:24:44.398387909 CET53595261.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.283561945 CET6094753192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.283848047 CET6409253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.372205973 CET53609471.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.494402885 CET5680053192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.495861053 CET5267553192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.582165003 CET53568001.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.584068060 CET53526751.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.631890059 CET53640921.1.1.1192.168.2.4
                Feb 21, 2024 09:24:56.515297890 CET5178553192.168.2.41.1.1.1
                Feb 21, 2024 09:24:56.518250942 CET6531153192.168.2.41.1.1.1
                Feb 21, 2024 09:24:56.864346027 CET53517851.1.1.1192.168.2.4
                Feb 21, 2024 09:24:56.866496086 CET53653111.1.1.1192.168.2.4
                Feb 21, 2024 09:24:59.809118032 CET53494361.1.1.1192.168.2.4
                Feb 21, 2024 09:25:01.943603039 CET138138192.168.2.4192.168.2.255
                Feb 21, 2024 09:25:18.606254101 CET53514861.1.1.1192.168.2.4
                Feb 21, 2024 09:25:41.358896971 CET53505711.1.1.1192.168.2.4
                Feb 21, 2024 09:25:41.386491060 CET53524211.1.1.1192.168.2.4
                TimestampSource IPDest IPChecksumCodeType
                Feb 21, 2024 09:24:45.631989002 CET192.168.2.41.1.1.1c22f(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Feb 21, 2024 09:24:42.117466927 CET192.168.2.41.1.1.10xb600Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.117759943 CET192.168.2.41.1.1.10x7397Standard query (0)clients2.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:42.118524075 CET192.168.2.41.1.1.10x7d25Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.118746042 CET192.168.2.41.1.1.10x3e5eStandard query (0)accounts.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:43.500464916 CET192.168.2.41.1.1.10xcf7aStandard query (0)zwgaleriamlodych.plA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.500746965 CET192.168.2.41.1.1.10x91deStandard query (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:43.592792034 CET192.168.2.41.1.1.10xed88Standard query (0)zwgaleriamlodych.plA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.593051910 CET192.168.2.41.1.1.10x9b2bStandard query (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:44.309912920 CET192.168.2.41.1.1.10x91f0Standard query (0)dilutegulpedshirt.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.310506105 CET192.168.2.41.1.1.10x5c0eStandard query (0)dilutegulpedshirt.com65IN (0x0001)false
                Feb 21, 2024 09:24:45.283561945 CET192.168.2.41.1.1.10x4be0Standard query (0)dilutegulpedshirt.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.283848047 CET192.168.2.41.1.1.10xe477Standard query (0)dilutegulpedshirt.com65IN (0x0001)false
                Feb 21, 2024 09:24:45.494402885 CET192.168.2.41.1.1.10x352bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.495861053 CET192.168.2.41.1.1.10x40eeStandard query (0)www.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:56.515297890 CET192.168.2.41.1.1.10x6d47Standard query (0)highperformancedformats.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.518250942 CET192.168.2.41.1.1.10x9b8eStandard query (0)highperformancedformats.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Feb 21, 2024 09:24:42.205507994 CET1.1.1.1192.168.2.40xb600No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:24:42.205507994 CET1.1.1.1192.168.2.40xb600No error (0)clients.l.google.com142.250.65.174A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.206618071 CET1.1.1.1192.168.2.40x7d25No error (0)accounts.google.com172.253.122.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.206737041 CET1.1.1.1192.168.2.40x7397No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:24:43.590240955 CET1.1.1.1192.168.2.40xcf7aNo error (0)zwgaleriamlodych.pl172.67.160.242A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.590240955 CET1.1.1.1192.168.2.40xcf7aNo error (0)zwgaleriamlodych.pl104.21.9.178A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.590987921 CET1.1.1.1192.168.2.40x91deNo error (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:43.681495905 CET1.1.1.1192.168.2.40xed88No error (0)zwgaleriamlodych.pl104.21.9.178A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.681495905 CET1.1.1.1192.168.2.40xed88No error (0)zwgaleriamlodych.pl172.67.160.242A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.692238092 CET1.1.1.1192.168.2.40x9b2bNo error (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.20A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.12A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.68A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.68A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.20A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.12A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.582165003 CET1.1.1.1192.168.2.40x352bNo error (0)www.google.com142.251.35.164A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.584068060 CET1.1.1.1192.168.2.40x40eeNo error (0)www.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:00.207549095 CET1.1.1.1192.168.2.40x62eeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:00.207549095 CET1.1.1.1192.168.2.40x62eeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:14.933439016 CET1.1.1.1192.168.2.40xea2eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:14.933439016 CET1.1.1.1192.168.2.40xea2eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:33.668837070 CET1.1.1.1192.168.2.40xeb0aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:33.668837070 CET1.1.1.1192.168.2.40xeb0aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:54.199307919 CET1.1.1.1192.168.2.40x2482No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:54.199307919 CET1.1.1.1192.168.2.40x2482No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • zwgaleriamlodych.pl
                • dilutegulpedshirt.com
                • https:
                • fs.microsoft.com
                • highperformancedformats.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449744172.240.108.76805228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Feb 21, 2024 09:24:56.961513042 CET452OUTGET /anonymous/ HTTP/1.1
                Host: highperformancedformats.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Feb 21, 2024 09:24:57.055377960 CET471INHTTP/1.1 403 Forbidden
                Server: nginx/1.21.6
                Date: Wed, 21 Feb 2024 08:24:57 GMT
                Content-Type: text/html
                Content-Length: 0
                Connection: keep-alive
                P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
                Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UA


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449745172.240.108.76805228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Feb 21, 2024 09:25:41.970057964 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449731142.250.65.1744435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:42 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-117.0.5938.132
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-02-21 08:24:42 UTC731INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-L1tiPDAFmrEGlcM4WIDXlg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Feb 2024 08:24:42 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6260
                X-Daystart: 1482
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-21 08:24:42 UTC521INData Raw: 32 63 38 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 36 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 34 38 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22 20
                Data Ascii: 2c8<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6260" elapsed_seconds="1482"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2024-02-21 08:24:42 UTC198INData Raw: 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 3f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2024-02-21 08:24:42 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449730172.253.122.844435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:42 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                2024-02-21 08:24:42 UTC1OUTData Raw: 20
                Data Ascii:
                2024-02-21 08:24:42 UTC1799INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Feb 2024 08:24:42 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Content-Security-Policy: script-src 'report-sample' 'nonce-dbAvIPs39Sf788FKvsBf4A' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Cross-Origin-Opener-Policy: same-origin
                reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQJiIR6OU8-urWMT2HBszxQmALnSF-E"
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-21 08:24:42 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2024-02-21 08:24:42 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449734104.21.9.1784435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:43 UTC662OUTGET / HTTP/1.1
                Host: zwgaleriamlodych.pl
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-02-21 08:24:44 UTC1142INHTTP/1.1 302 Found
                Date: Wed, 21 Feb 2024 08:24:44 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                Set-Cookie: PHPSESSID=nn8fvss2b7n1mdlunp441pn0gn; path=/
                Set-Cookie: _subid=23n0u3tmsl3; expires=Thu, 22 Feb 2024 08:24:44 GMT; Max-Age=86400; path=/; domain=.zwgaleriamlodych.pl
                Set-Cookie: f748d=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1wic3RyZWFtc1wiOntcIjRcIjoxNzA4NTAzODg0fSxcImNhbXBhaWduc1wiOntcIjFcIjoxNzA4NTAzODg0fSxcInRpbWVcIjoxNzA4NTAzODg0fSJ9.6NsjEuczM7LVZNLLI9-BrK5gIoQ1jWFDHSWwoQW00Bo; expires=Thu, 22 Feb 2024 08:24:44 GMT; Max-Age=86400; path=/; domain=.zwgaleriamlodych.pl
                Set-Cookie: _token=uuid_23n0u3tmsl3_23n0u3tmsl365d5b34c32e2a5.74555082; expires=Thu, 22 Feb 2024 08:24:44 GMT; Max-Age=86400; path=/; domain=.zwgaleriamlodych.pl
                Expires: Thu, 19 Nov 1981 08:52:00 GMT
                Cache-Control: no-store, no-cache, must-revalidate
                Pragma: no-cache
                Location: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                X-Content-Type-Options: nosniff
                CF-Cache-Status: DYNAMIC
                2024-02-21 08:24:44 UTC411INData Raw: 52 65 70 6f 72 74 2d 54 6f 3a 20 7b 22 65 6e 64 70 6f 69 6e 74 73 22 3a 5b 7b 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 61 2e 6e 65 6c 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 5c 2f 72 65 70 6f 72 74 5c 2f 76 33 3f 73 3d 72 59 32 25 32 46 54 48 30 61 55 4c 74 49 77 34 58 64 79 45 57 53 35 6f 72 42 76 30 4b 6c 67 37 70 71 38 73 79 68 4d 25 32 42 59 41 44 73 69 32 34 64 68 57 49 4c 6c 77 31 6d 61 6f 76 5a 78 55 4a 74 74 72 4e 49 5a 62 66 53 4e 43 35 4e 77 61 50 31 62 56 48 63 25 32 46 45 66 53 51 25 32 46 48 66 64 4d 62 78 47 56 34 56 6d 78 6b 62 73 73 43 50 51 76 61 70 41 61 48 6d 6d 31 6c 5a 4d 7a 70 65 66 58 6f 6a 35 4b 52 78 71 4d 36 56 7a 73 22 7d 5d 2c 22 67 72 6f 75 70 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a 36 30
                Data Ascii: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=rY2%2FTH0aULtIw4XdyEWS5orBv0Klg7pq8syhM%2BYADsi24dhWILlw1maovZxUJttrNIZbfSNC5NwaP1bVHc%2FEfSQ%2FHfdMbxGV4VmxkbssCPQvapAaHmm1lZMzpefXoj5KRxqM6Vzs"}],"group":"cf-nel","max_age":60
                2024-02-21 08:24:44 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.449735192.243.61.2274435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:44 UTC725OUTGET /t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3 HTTP/1.1
                Host: dilutegulpedshirt.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-02-21 08:24:44 UTC697INHTTP/1.1 200 OK
                Server: nginx/1.21.6
                Date: Wed, 21 Feb 2024 08:24:44 GMT
                Content-Type: text/html
                Content-Length: 115
                Connection: close
                P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
                Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UA
                Set-Cookie: u_pl=15107318; expires=Thu, 22 Feb 2024 08:24:44 GMT
                Expires: Thu, 01 Jan 1970 00:00:01 GMT
                Cache-Control: no-cache
                X-Request-ID: 3514ff8031ff95b4a3811d4442f3f5c0
                Strict-Transport-Security: max-age=0; includeSubdomains
                2024-02-21 08:24:44 UTC115INData Raw: 3c 61 20 68 72 65 66 20 3d 20 27 68 74 74 70 3a 2f 2f 68 69 67 68 70 65 72 66 6f 72 6d 61 6e 63 65 64 66 6f 72 6d 61 74 73 2e 63 6f 6d 2f 61 6e 6f 6e 79 6d 6f 75 73 2f 27 20 74 61 72 67 65 74 3d 27 5f 62 6c 61 6e 6b 27 3e 41 6e 6f 6e 79 6d 6f 75 73 20 50 72 6f 78 79 20 64 65 74 65 63 74 65 64 2c 20 63 6c 69 63 6b 20 68 65 72 65 2e 3c 2f 61 3e
                Data Ascii: <a href = 'http://highperformancedformats.com/anonymous/' target='_blank'>Anonymous Proxy detected, click here.</a>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.449738192.243.61.2274435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:45 UTC906OUTGET /favicon.ico HTTP/1.1
                Host: dilutegulpedshirt.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-full-version: "117.0.5938.132"
                sec-ch-ua-platform-version: "10.0.0"
                sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"
                sec-ch-ua-model: ""
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: u_pl=15107318
                2024-02-21 08:24:45 UTC314INHTTP/1.1 200 OK
                Server: nginx/1.21.6
                Date: Wed, 21 Feb 2024 08:24:45 GMT
                Content-Type: image/x-icon
                Content-Length: 0
                Connection: close
                Expires: Thu, 01 Jan 1970 00:00:01 GMT
                Cache-Control: no-cache
                X-Request-ID: 4a9767a1660f2fd512216dbe68019ac2
                Strict-Transport-Security: max-age=0; includeSubdomains


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.449739172.240.108.844435228C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:45 UTC379OUTGET /favicon.ico HTTP/1.1
                Host: dilutegulpedshirt.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: */*
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: cors
                Sec-Fetch-Dest: empty
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: u_pl=15107318
                2024-02-21 08:24:45 UTC314INHTTP/1.1 200 OK
                Server: nginx/1.21.6
                Date: Wed, 21 Feb 2024 08:24:45 GMT
                Content-Type: image/x-icon
                Content-Length: 0
                Connection: close
                Expires: Thu, 01 Jan 1970 00:00:01 GMT
                Cache-Control: no-cache
                X-Request-ID: ffab5d48c4eb81946ef6ee91110afdce
                Strict-Transport-Security: max-age=0; includeSubdomains


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.44974223.54.68.82443
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-21 08:24:47 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/079C)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=126018
                Date: Wed, 21 Feb 2024 08:24:47 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                7192.168.2.44974323.54.68.82443
                TimestampBytes transferredDirectionData
                2024-02-21 08:24:47 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-21 08:24:47 UTC531INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=126074
                Date: Wed, 21 Feb 2024 08:24:47 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-02-21 08:24:47 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:09:24:38
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:09:24:40
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:09:24:42
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly