Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://dhl.link66820.site/order/ZxWKPP2i/

Overview

General Information

Sample URL:https://dhl.link66820.site/order/ZxWKPP2i/
Analysis ID:1427109
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1892 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1900,i,8584048215130342334,13196278809595615715,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhl.link66820.site/order/ZxWKPP2i/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /order/ZxWKPP2i/ HTTP/1.1Host: dhl.link66820.siteConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /static/errors/404/favicon.png HTTP/1.1Host: dhl.link66820.siteConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dhl.link66820.site/order/ZxWKPP2i/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /static/errors/404/favicon.png HTTP/1.1Host: dhl.link66820.siteConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: dhl.link66820.site
Source: unknownHTTP traffic detected: POST /report/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 401Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 16 Apr 2024 23:57:45 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: AcceptAllow: GET, HEAD, OPTIONSX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffReferrer-Policy: same-originCross-Origin-Opener-Policy: same-originCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 87581e93cf3f53fa-ATLalt-svc: h3=":443"; ma=86400
Source: chromecache_47.2.drString found in binary or memory: https://fonts.googleapis.com/css?family=Open
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWSw
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWT4
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWV0
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWV4
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWV8
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVA
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVI
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVM
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVQ
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVw
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS2mu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSCmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSGmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSKmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSOmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSumu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSymu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTUGmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTVOmu1aB.woff2)
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/7@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1900,i,8584048215130342334,13196278809595615715,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhl.link66820.site/order/ZxWKPP2i/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1900,i,8584048215130342334,13196278809595615715,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
dhl.link66820.site
104.21.7.20
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      www.google.com
      142.250.9.103
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://dhl.link66820.site/order/ZxWKPP2i/false
            unknown
            https://dhl.link66820.site/static/errors/404/favicon.pngfalse
              unknown
              https://a.nel.cloudflare.com/report/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3Dfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                104.21.7.20
                dhl.link66820.siteUnited States
                13335CLOUDFLARENETUSfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                142.250.9.103
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1427109
                Start date and time:2024-04-17 01:56:51 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 16s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://dhl.link66820.site/order/ZxWKPP2i/
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:9
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/7@8/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.105.94, 173.194.219.102, 173.194.219.138, 173.194.219.100, 173.194.219.113, 173.194.219.139, 173.194.219.101, 108.177.122.84, 34.104.35.123, 172.253.124.95, 172.253.124.94, 20.12.23.50, 23.45.13.145, 23.45.13.171, 192.229.211.108, 13.85.23.206, 20.166.126.56, 74.125.138.94
                • Excluded domains from analysis (whitelisted): fonts.googleapis.com, fs.microsoft.com, accounts.google.com, fonts.gstatic.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://dhl.link66820.site/order/ZxWKPP2i/
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
                Category:downloaded
                Size (bytes):2188
                Entropy (8bit):7.748209827877405
                Encrypted:false
                SSDEEP:48:c7/6wPYNtzltA8n/RXYmoy2TTjLRusDwee9CiS1s:2Sm8l+y/J12TTj0sDwt9Cbs
                MD5:A5923B088A4AE67CB0F5D281EBCFA791
                SHA1:D771BDA4314A2148ED0234E23987A01608A47085
                SHA-256:DF405A3640A308E1FB215923E6DBF92F9A325F1E9F74615CE2E920B26F11B02A
                SHA-512:69E054B09E0431E883606D7FDD5644FF1CFCABE8ECFF2EE3309614C73A19BA5EA006D48283FAA38301D95F6B40C618F42A84BF2ABDBEB7B80380BB5591476BC8
                Malicious:false
                Reputation:low
                URL:https://dhl.link66820.site/static/errors/404/favicon.png
                Preview:.PNG........IHDR..............X......sBIT....|.d.....pHYs.................IDATx...].\W....$m.F.6...ZA...."R..b..][. ...o..x.W...U.".......b."H#..R..Q....%M...1.pf.^{..f....g..9g...=... I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.Y.n`.5.Z`;p..mG................gH..7.g....P%.....>....A....D'......T....._G5....(....T.G..Q.E....\_..=G..r&....z.D..Xp}./.......|OD....T....h. ..&4...n.n..2..1...Mh.n.n`./....Dj`@...Dj..7...OE7......4....F..p.X...U..s4: {..|WE......|.G...Ht}./.2<..=.\_..=G...xp}..........*.3...s.u...&4.W./.n.dC./"6..M.7`.........%..H......H......H......H......\............!;.#.|/..x;.W..V........'= .8.%......Hc......,..Y..h7....|O....u<...F......I......X..H...:...t. =.u.....1c.....8....[3......V...)<}.L.S.X.hC...m..4......pv......8..u..)...G=.>.R.0.......M86....o.m...=..I.pl...o...E.aO.:Y.{..[.t.2)$......uM.}..v7.;..09$.H?....../o...X...L....p.b.......I!...X5S.W= ...f..aHr....}gu..^.....K8~.3<.f.|.A.na.NM.$...=...!.....H..s.\..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (1572)
                Category:downloaded
                Size (bytes):16991
                Entropy (8bit):5.384785512031636
                Encrypted:false
                SSDEEP:192:+oTOoHogoL5oHo5uy8oe0bqGIwY9oYoRooQ/A85q1H6uy2rbqGIwYRe1qh/ZFgq8:+SOK96oFZtoq99fzLUhq915Cq9C
                MD5:F3D6A2E29013598E08E29CE785386815
                SHA1:E1383F40EC1C5DBF37E92AFF0EE911ABFB97E17A
                SHA-256:5B7FE828DECC07F24AB19C7E017DA0DEDB2C71E1647594F3DDEB6072D743147F
                SHA-512:A5534956536325C166934414B40D3309D4EDABD32DA3A8698E874B729DF8E5F3FE1FE3C009C93345085760F88FD98D41D57B1035B6A982C3754A3218D295169D
                Malicious:false
                Reputation:low
                URL:"https://fonts.googleapis.com/css?family=Open+Sans:400italic,400,700&subset=latin,cyrillic"
                Preview:/* cyrillic-ext */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWV0ewJER.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVQewJER.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVwewJER.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek */.@f
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
                Category:dropped
                Size (bytes):2188
                Entropy (8bit):7.748209827877405
                Encrypted:false
                SSDEEP:48:c7/6wPYNtzltA8n/RXYmoy2TTjLRusDwee9CiS1s:2Sm8l+y/J12TTj0sDwt9Cbs
                MD5:A5923B088A4AE67CB0F5D281EBCFA791
                SHA1:D771BDA4314A2148ED0234E23987A01608A47085
                SHA-256:DF405A3640A308E1FB215923E6DBF92F9A325F1E9F74615CE2E920B26F11B02A
                SHA-512:69E054B09E0431E883606D7FDD5644FF1CFCABE8ECFF2EE3309614C73A19BA5EA006D48283FAA38301D95F6B40C618F42A84BF2ABDBEB7B80380BB5591476BC8
                Malicious:false
                Reputation:low
                Preview:.PNG........IHDR..............X......sBIT....|.d.....pHYs.................IDATx...].\W....$m.F.6...ZA...."R..b..][. ...o..x.W...U.".......b."H#..R..Q....%M...1.pf.^{..f....g..9g...=... I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.$I.Y.n`.5.Z`;p..mG................gH..7.g....P%.....>....A....D'......T....._G5....(....T.G..Q.E....\_..=G..r&....z.D..Xp}./.......|OD....T....h. ..&4...n.n..2..1...Mh.n.n`./....Dj`@...Dj..7...OE7......4....F..p.X...U..s4: {..|WE......|.G...Ht}./.2<..=.\_..=G...xp}..........*.3...s.u...&4.W./.n.dC./"6..M.7`.........%..H......H......H......H......\............!;.#.|/..x;.W..V........'= .8.%......Hc......,..Y..h7....|O....u<...F......I......X..H...:...t. =.u.....1c.....8....[3......V...)<}.L.S.X.hC...m..4......pv......8..u..)...G=.>.R.0.......M86....o.m...=..I.pl...o...E.aO.:Y.{..[.t.2)$......uM.}..v7.;..09$.H?....../o...X...L....p.b.......I!...X5S.W= ...f..aHr....}gu..^.....K8~.3<.f.|.A.na.NM.$...=...!.....H..s.\..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with very long lines (41114)
                Category:downloaded
                Size (bytes):42795
                Entropy (8bit):6.041026543202778
                Encrypted:false
                SSDEEP:768:svrowObBNtgIYqXPUBal5CBUk9/qjyY2EK/3Lk9ehFYBNfeOIQIckIyQ0DGf0eVz:sz+BNtWtcl5KUE/qyYzKvLkAhivfrFhT
                MD5:80D159469C692F41824195186DA28E97
                SHA1:DAFDA5BB8DCD51CEA410AC86198F12A9BFEF7895
                SHA-256:36D918D62D793E624564BA501F53411E641FA011BBB42D319B5B89B4EE43EA24
                SHA-512:4D670CC1DAC1B9C514731673AC8913051F1D58FA2CAC52C150CE74C981163767BF39D90FD2936CB269A1D3373BB1953CBD4D4E45C569677C66DD61C21A3D0594
                Malicious:false
                Reputation:low
                URL:https://dhl.link66820.site/order/ZxWKPP2i/
                Preview:.<!DOCTYPE html>.<html>..<head>. <title>404</title>. <meta charset="utf-8">. <link rel="shortcut icon" href="/static/errors/404/favicon.png" type="image/x-icon" />. <link href="https://fonts.googleapis.com/css?family=Open+Sans:400italic,400,700&subset=latin,cyrillic" rel='stylesheet' type='text/css'>. <style type="text/css">. html,. body {. width: 100%;. height: 100%;. overflow: hidden;. margin: 0px;. padding: 0px;. font-family: 'Open Sans', sans-serif;. font-size: 16px. }.. body {. background: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAyAAAAIQCAIAAAD2H50mAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAIGNIUk0AAHolAACAgwAA+f8AAIDoAABSCAABFVgAADqXAAAXb9daH5AAAHe9SURBVHja7N13fBz1nT/+z/Ttq15cJMuW5IZtuRe5gGmhXLjQnEDI5S4Q4BIgkAJJcBKSXCB39wuXkITwTYM7ArGppiSAwcZxt5F7keUqN9myZEkrbd+Z+f3xgWW9q5VXq5nZ2d3X8w8eQtbO7n52duY1n/Iepr6+ngAAAACAdlg0AQAAAAACFgAAAAACFgAAAAACFgAAAAAgYA
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 17, 2024 01:57:34.584100008 CEST49678443192.168.2.4104.46.162.224
                Apr 17, 2024 01:57:36.068336964 CEST49675443192.168.2.4173.222.162.32
                Apr 17, 2024 01:57:44.511010885 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511038065 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.511122942 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511394024 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511461973 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.511534929 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511629105 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511645079 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.511857986 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.511889935 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.741993904 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.742227077 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.742273092 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.742289066 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.742412090 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.742439985 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.743957043 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.744031906 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.744075060 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.744168043 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.745414019 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.745501995 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.745570898 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.745578051 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.745652914 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.745737076 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.787961960 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.788083076 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:44.788114071 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:44.835757971 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.331753969 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.331911087 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.331975937 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.331990004 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332123995 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332178116 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332182884 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332283020 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332329988 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332334995 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332443953 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332488060 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332492113 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332622051 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332665920 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332670927 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332768917 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332822084 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332825899 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332912922 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.332958937 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.332962990 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.378532887 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.446338892 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.446433067 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.446527004 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.446811914 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.446855068 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.458420038 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.458559990 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.458647966 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.458658934 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.458933115 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.458983898 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.458988905 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459059000 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459106922 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.459112883 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459530115 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459579945 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.459583998 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459666014 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.459712029 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.459717989 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460381031 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460433006 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.460437059 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460529089 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460575104 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.460580111 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460676908 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.460721970 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.460726976 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.461272001 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.461323023 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.461328030 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.461505890 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.461559057 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.466703892 CEST49735443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:45.466717005 CEST44349735104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:45.548999071 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.549022913 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.549108982 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.549489021 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.549496889 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.665592909 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.679873943 CEST49675443192.168.2.4173.222.162.32
                Apr 17, 2024 01:57:45.688771009 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.688849926 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.689774990 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.689871073 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.731774092 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.731887102 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.735162973 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.735207081 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.789123058 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.807228088 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.807729959 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.807739973 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.809154034 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.809218884 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.811239958 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.811314106 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.872106075 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:45.872112036 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:45.901487112 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.901527882 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.901701927 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.902949095 CEST49739443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.902992964 CEST4434973935.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.903762102 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.903831005 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.903906107 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.904247046 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:45.904279947 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:45.925951004 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:46.117657900 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.118068933 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:46.118352890 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:46.118382931 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.118716955 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.119148016 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:46.119210005 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.119342089 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:46.164115906 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.164120913 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:46.354904890 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.355031013 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.355087042 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:46.378177881 CEST49742443192.168.2.435.190.80.1
                Apr 17, 2024 01:57:46.378201008 CEST4434974235.190.80.1192.168.2.4
                Apr 17, 2024 01:57:46.531550884 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:46.531605005 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:46.531651020 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:46.531672001 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:46.531693935 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:46.531754017 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:46.535249949 CEST49736443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:46.535279036 CEST44349736104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.062127113 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.062165976 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.062532902 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.069900036 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.069933891 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.134295940 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.134320021 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.134598017 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.134715080 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.134723902 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.290077925 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.290174007 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.297071934 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.297094107 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.297497988 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.348354101 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.354789972 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.375274897 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.375294924 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.376725912 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.376802921 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.378396034 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.378474951 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.380312920 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.380326033 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.425407887 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.426479101 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.468152046 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.530941010 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.531013012 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.531076908 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.558079958 CEST49744443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.558121920 CEST44349744104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.615276098 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.615344048 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.615396023 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.615425110 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.615453959 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.615499020 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.621870041 CEST49745443192.168.2.4104.21.7.20
                Apr 17, 2024 01:57:47.621895075 CEST44349745104.21.7.20192.168.2.4
                Apr 17, 2024 01:57:47.646373034 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.646415949 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.646482944 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.647126913 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.647145987 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.864075899 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.864176035 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.881719112 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.881750107 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.882675886 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:47.887814045 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:47.932122946 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:48.070956945 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:48.071114063 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:48.071182966 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:48.075329065 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:48.075350046 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:48.075360060 CEST49746443192.168.2.4104.123.200.136
                Apr 17, 2024 01:57:48.075366020 CEST44349746104.123.200.136192.168.2.4
                Apr 17, 2024 01:57:55.800329924 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:55.800388098 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:57:55.800542116 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:56.810359001 CEST49741443192.168.2.4142.250.9.103
                Apr 17, 2024 01:57:56.810384035 CEST44349741142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.485116959 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:45.485162973 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.485215902 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:45.485955000 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:45.485965967 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.725814104 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.726100922 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:45.726109028 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.726655960 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.727057934 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:45.727123022 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:45.770045996 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:53.551597118 CEST4972480192.168.2.4199.232.210.172
                Apr 17, 2024 01:58:53.655834913 CEST8049724199.232.210.172192.168.2.4
                Apr 17, 2024 01:58:53.655900955 CEST8049724199.232.210.172192.168.2.4
                Apr 17, 2024 01:58:53.658998966 CEST4972480192.168.2.4199.232.210.172
                Apr 17, 2024 01:58:55.728001118 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:55.728055000 CEST44349755142.250.9.103192.168.2.4
                Apr 17, 2024 01:58:55.731070995 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:56.647069931 CEST49755443192.168.2.4142.250.9.103
                Apr 17, 2024 01:58:56.647097111 CEST44349755142.250.9.103192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 17, 2024 01:57:42.501693010 CEST53539461.1.1.1192.168.2.4
                Apr 17, 2024 01:57:42.551177025 CEST53649771.1.1.1192.168.2.4
                Apr 17, 2024 01:57:43.157480955 CEST53530631.1.1.1192.168.2.4
                Apr 17, 2024 01:57:44.364129066 CEST5723353192.168.2.41.1.1.1
                Apr 17, 2024 01:57:44.364660025 CEST5825753192.168.2.41.1.1.1
                Apr 17, 2024 01:57:44.506875992 CEST53572331.1.1.1192.168.2.4
                Apr 17, 2024 01:57:44.510329962 CEST53582571.1.1.1192.168.2.4
                Apr 17, 2024 01:57:45.340732098 CEST5006653192.168.2.41.1.1.1
                Apr 17, 2024 01:57:45.341070890 CEST5656553192.168.2.41.1.1.1
                Apr 17, 2024 01:57:45.442827940 CEST5827753192.168.2.41.1.1.1
                Apr 17, 2024 01:57:45.443216085 CEST5049153192.168.2.41.1.1.1
                Apr 17, 2024 01:57:45.445476055 CEST53565651.1.1.1192.168.2.4
                Apr 17, 2024 01:57:45.445806980 CEST53500661.1.1.1192.168.2.4
                Apr 17, 2024 01:57:45.470398903 CEST53638281.1.1.1192.168.2.4
                Apr 17, 2024 01:57:45.547394037 CEST53582771.1.1.1192.168.2.4
                Apr 17, 2024 01:57:45.548053026 CEST53504911.1.1.1192.168.2.4
                Apr 17, 2024 01:57:46.216869116 CEST53593281.1.1.1192.168.2.4
                Apr 17, 2024 01:57:46.981564045 CEST5593253192.168.2.41.1.1.1
                Apr 17, 2024 01:57:46.981936932 CEST5935653192.168.2.41.1.1.1
                Apr 17, 2024 01:57:47.123785973 CEST53559321.1.1.1192.168.2.4
                Apr 17, 2024 01:57:47.127964020 CEST53593561.1.1.1192.168.2.4
                Apr 17, 2024 01:58:00.424071074 CEST53639301.1.1.1192.168.2.4
                Apr 17, 2024 01:58:05.107155085 CEST138138192.168.2.4192.168.2.255
                Apr 17, 2024 01:58:19.339328051 CEST53649341.1.1.1192.168.2.4
                Apr 17, 2024 01:58:41.816239119 CEST53495221.1.1.1192.168.2.4
                Apr 17, 2024 01:58:42.158324957 CEST53499631.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 17, 2024 01:57:44.364129066 CEST192.168.2.41.1.1.10x48b3Standard query (0)dhl.link66820.siteA (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:44.364660025 CEST192.168.2.41.1.1.10xa74cStandard query (0)dhl.link66820.site65IN (0x0001)false
                Apr 17, 2024 01:57:45.340732098 CEST192.168.2.41.1.1.10x1fd5Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.341070890 CEST192.168.2.41.1.1.10x3812Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                Apr 17, 2024 01:57:45.442827940 CEST192.168.2.41.1.1.10xc7fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.443216085 CEST192.168.2.41.1.1.10xcbecStandard query (0)www.google.com65IN (0x0001)false
                Apr 17, 2024 01:57:46.981564045 CEST192.168.2.41.1.1.10x325eStandard query (0)dhl.link66820.siteA (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:46.981936932 CEST192.168.2.41.1.1.10x2757Standard query (0)dhl.link66820.site65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 17, 2024 01:57:44.506875992 CEST1.1.1.1192.168.2.40x48b3No error (0)dhl.link66820.site104.21.7.20A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:44.506875992 CEST1.1.1.1192.168.2.40x48b3No error (0)dhl.link66820.site172.67.155.100A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:44.510329962 CEST1.1.1.1192.168.2.40xa74cNo error (0)dhl.link66820.site65IN (0x0001)false
                Apr 17, 2024 01:57:45.445806980 CEST1.1.1.1192.168.2.40x1fd5No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.103A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.147A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.99A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.105A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.104A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.547394037 CEST1.1.1.1192.168.2.40xc7fNo error (0)www.google.com142.250.9.106A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:45.548053026 CEST1.1.1.1192.168.2.40xcbecNo error (0)www.google.com65IN (0x0001)false
                Apr 17, 2024 01:57:47.123785973 CEST1.1.1.1192.168.2.40x325eNo error (0)dhl.link66820.site104.21.7.20A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:47.123785973 CEST1.1.1.1192.168.2.40x325eNo error (0)dhl.link66820.site172.67.155.100A (IP address)IN (0x0001)false
                Apr 17, 2024 01:57:47.127964020 CEST1.1.1.1192.168.2.40x2757No error (0)dhl.link66820.site65IN (0x0001)false
                Apr 17, 2024 01:57:58.876441956 CEST1.1.1.1192.168.2.40x569fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 17, 2024 01:57:58.876441956 CEST1.1.1.1192.168.2.40x569fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 17, 2024 01:58:11.629020929 CEST1.1.1.1192.168.2.40x7c69No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 17, 2024 01:58:11.629020929 CEST1.1.1.1192.168.2.40x7c69No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 17, 2024 01:58:34.440023899 CEST1.1.1.1192.168.2.40x84ecNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 17, 2024 01:58:34.440023899 CEST1.1.1.1192.168.2.40x84ecNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 17, 2024 01:58:54.591960907 CEST1.1.1.1192.168.2.40x1ddeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 17, 2024 01:58:54.591960907 CEST1.1.1.1192.168.2.40x1ddeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • dhl.link66820.site
                • https:
                • a.nel.cloudflare.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449735104.21.7.204433744C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:44 UTC676OUTGET /order/ZxWKPP2i/ HTTP/1.1
                Host: dhl.link66820.site
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 23:57:45 UTC761INHTTP/1.1 404 Not Found
                Date: Tue, 16 Apr 2024 23:57:45 GMT
                Content-Type: text/html; charset=utf-8
                Transfer-Encoding: chunked
                Connection: close
                Vary: Accept
                Allow: GET, HEAD, OPTIONS
                X-Frame-Options: SAMEORIGIN
                X-Content-Type-Options: nosniff
                Referrer-Policy: same-origin
                Cross-Origin-Opener-Policy: same-origin
                CF-Cache-Status: DYNAMIC
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 87581e93cf3f53fa-ATL
                alt-svc: h3=":443"; ma=86400
                2024-04-16 23:57:45 UTC608INData Raw: 63 65 30 0d 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 22 20 68 72 65 66 3d 22 2f 73 74 61 74 69 63 2f 65 72 72 6f 72 73 2f 34 30 34 2f 66 61 76 69 63 6f 6e 2e 70 6e 67 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 78 2d 69 63 6f 6e 22 20 2f 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 4f 70 65 6e 2b 53 61 6e 73 3a 34 30 30 69 74 61 6c 69 63 2c 34
                Data Ascii: ce0<!DOCTYPE html><html><head> <title>404</title> <meta charset="utf-8"> <link rel="shortcut icon" href="/static/errors/404/favicon.png" type="image/x-icon" /> <link href="https://fonts.googleapis.com/css?family=Open+Sans:400italic,4
                2024-04-16 23:57:45 UTC1369INData Raw: 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 64 61 74 61 3a 69 6d 61 67 65 2f 70 6e 67 3b 62 61 73 65 36 34 2c 69 56 42 4f 52 77 30 4b 47 67 6f 41 41 41 41 4e 53 55 68 45 55 67 41 41 41 79 41 41 41 41 49 51 43 41 49 41 41 41 44 32 48 35 30 6d 41 41 41 41 43 58 42 49 57 58 4d 41 41 41 73 54 41 41 41 4c 45 77 45 41 6d 70 77 59 41 41 41 41 49 47 4e 49 55 6b 30 41 41 48 6f 6c 41 41 43 41 67 77 41 41 2b 66 38 41 41 49 44 6f 41 41 42 53 43 41 41 42 46 56 67 41 41 44 71 58 41 41 41 58 62 39 64 61 48 35 41 41 41 48 65 39 53 55 52 42 56 48 6a 61 37 4e 31 33 66 42 7a 31 6e 54 2f 2b 7a 2f 54 74 71 31 35 63 4a 4d 75 57 35 49 5a 74 75 52 65 35 67 47 6d 68 58 4c 6a 51 6e 45 44 49 35 53 34 51 34 42 49 67 6b 41 4a 4a
                Data Ascii: y { background: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAyAAAAIQCAIAAAD2H50mAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAIGNIUk0AAHolAACAgwAA+f8AAIDoAABSCAABFVgAADqXAAAXb9daH5AAAHe9SURBVHja7N13fBz1nT/+z/Ttq15cJMuW5IZtuRe5gGmhXLjQnEDI5S4Q4BIgkAJJ
                2024-04-16 23:57:45 UTC1326INData Raw: 58 6c 35 54 7a 50 42 77 4b 42 5a 63 75 57 74 62 65 33 44 78 79 65 61 46 65 57 49 41 67 63 78 39 48 61 44 51 68 62 41 41 68 59 41 41 43 35 54 46 47 55 78 45 34 73 4f 6e 32 71 70 36 65 6e 70 36 65 6e 75 4c 69 59 39 6b 4b 4a 6f 75 68 77 4f 45 70 4c 53 31 30 75 46 38 75 79 54 55 31 4e 37 37 7a 7a 54 6b 64 48 52 37 2f 6a 6a 4d 6e 43 48 4d 64 78 50 4d 2f 7a 50 45 39 54 48 5a 49 57 51 50 70 58 52 2f 58 31 39 57 67 46 41 41 44 54 45 6b 55 78 57 73 34 71 71 71 53 6b 78 4f 46 77 4d 41 7a 54 32 39 74 72 74 56 6f 72 4b 69 6f 4b 43 77 73 46 51 66 44 35 66 47 66 50 6e 75 33 73 37 41 77 45 41 6e 31 39 66 61 6d 6e 71 33 36 70 71 71 6f 6f 69 69 7a 4c 73 69 77 6a 62 41 45 4d 43 6f 38 6d 41 41 44 49 76 6d 4d 33 7a 77 38 62 4e 6d 7a 6b 79 4a 45 64 48 52 31 39 66 58 33 74 37
                Data Ascii: Xl5TzPBwKBZcuWtbe3DxyeaFeWIAgcx9HaDQhbAAhYAAC5TFGUxE4sOn2qp6enp6enuLiY9kKJouhwOEpLS10uF8uyTU1N77zzTkdHR7/jjMnCHMdxPM/zPE9THZIWQPpXR/X19WgFAADTEkUxWs4qqqSkxOFwMAzT29trtVorKioKCwsFQfD5fGfPnu3s7AwEAn19famnq36pqqooiizLsiwjbAEMCo8mAADIvmM3zw8bNmzkyJEdHR19fX3t7
                2024-04-16 23:57:45 UTC1369INData Raw: 33 39 64 65 0d 0a 4f 2f 73 6c 34 52 4a 4b 47 33 6b 77 30 48 6a 48 7a 37 47 45 41 45 42 43 77 59 74 49 71 4b 69 76 76 76 76 37 2f 66 66 35 49 6b 36 62 72 72 72 75 76 72 36 39 75 35 63 79 63 61 43 69 43 66 4a 55 37 41 59 68 6a 47 61 72 57 4f 47 54 50 47 5a 72 4d 78 44 4c 4f 78 62 4d 5a 52 78 71 58 72 61 31 41 35 49 56 42 61 33 54 4e 75 2f 72 6d 35 74 2f 61 4f 6d 53 6e 62 33 4a 79 2f 6c 2f 63 5a 4f 70 4d 42 74 52 34 41 41 51 74 53 4e 58 2f 2b 2f 47 75 75 75 53 62 5a 76 37 49 73 75 32 44 42 67 6f 71 4b 69 72 56 72 31 36 4a 76 48 43 42 76 69 61 49 59 64 77 74 43 68 38 4e 68 73 56 6a 47 6a 52 76 48 4d 49 7a 4e 37 6e 6a 52 50 53 4e 67 32 42 77 50 68 67 6d 37 79 33 70 48 7a 2b 69 59 2b 63 39 64 6b 36 34 4d 46 56 53 77 63 6c 6a 77 6e 47 4d 4d 37 46 56 43 72 51 66
                Data Ascii: 39deO/sl4RJKG3kw0HjHz7GEAEBCwYtIqKivvvv7/ff5Ik6brrruvr69u5cycaCiCfJU7AYhjGarWOGTPGZrMxDLOxbMZRxqXra1A5IVBa3TNu/rm5t/aOmSnb3Jy/l/cZOpMBtR4AAQtSNX/+/GuuuSbZv7Isu2DBgoqKirVr16JvHCBviaIYdwtCh8NhsVjGjRvHMIzN7njRPSNg2BwPhgm7y3pHz+iY+c9dk64MFVSwcljwnGMM7FVCrQf
                2024-04-16 23:57:45 UTC1369INData Raw: 58 67 57 4c 46 69 41 43 56 67 41 57 58 6b 34 5a 70 6a 45 4a 63 50 6c 35 65 56 6a 78 6f 79 70 71 71 6f 69 68 50 52 56 4e 2f 78 55 6d 71 31 68 75 6e 70 75 76 73 50 47 66 7a 72 67 36 49 75 6f 6d 38 36 45 56 37 61 46 6e 7a 67 5a 4e 6b 58 63 39 50 65 36 44 6d 31 79 48 39 6a 67 50 4c 7a 56 34 47 4c 78 55 52 68 41 68 4c 53 68 42 30 74 66 59 38 65 4f 2f 63 6c 50 66 6a 4a 6c 79 68 52 6a 6e 67 37 54 32 77 47 79 2b 48 43 63 55 4d 42 64 45 41 52 5a 6c 75 6b 45 4c 45 45 51 64 67 71 61 6a 51 38 2b 58 69 50 65 66 34 6b 31 4e 6c 30 52 51 6d 77 38 73 33 69 45 75 48 69 45 2b 50 68 4d 73 75 56 73 65 46 56 62 2b 4a 33 32 79 42 70 76 78 6f 4b 46 62 48 56 32 54 62 71 79 61 39 4b 56 6a 42 78 78 74 4f 35 77 74 57 78 30 74 32 77 51 75 38 38 59 66 49 55 63 48 55 43 4d 52 43 4a 49
                Data Ascii: XgWLFiACVgAWXk4ZpjEJcPl5eVjxoypqqoihPRVN/xUmq1hunpuvsPGfzrg6Iuom86EV7aFnzgZNkXc9Pe6Dm1yH9jgPLzV4GLxURhAhLShB0tfY8eO/clPfjJlyhRjng7T2wGy+HCcUMBdEARZlukELEEQdgqajQ8+XiPef4k1Nl0RQmw8s3iEuHiE+PhMsuVseFVb+J32yBpvxoKFbHV2Tbqya9KVjBxxtO5wtWx0t2wQu88YfIUcHUCMRCJI
                2024-04-16 23:57:45 UTC1369INData Raw: 6f 38 36 57 35 5a 37 7a 36 77 77 58 5a 69 6a 7a 48 46 34 6d 56 5a 52 72 72 4b 75 2b 39 31 63 58 45 78 57 69 45 39 58 71 2f 33 70 5a 64 65 69 6b 51 69 55 36 5a 4d 4d 62 4c 59 56 53 4b 72 31 58 72 38 2b 50 48 39 2b 2f 66 6a 51 77 48 49 4f 6e 52 79 64 4e 78 76 4a 45 6d 71 71 36 75 7a 57 43 77 73 79 35 34 70 72 56 2f 4e 44 6e 6f 4a 34 57 2f 72 70 51 63 6e 4a 30 31 58 2b 38 37 32 58 66 76 47 6f 55 4d 42 2b 62 45 5a 46 54 56 46 31 6e 37 2f 35 76 39 32 74 6e 2f 51 2f 6b 6b 46 4c 4b 75 39 31 75 56 49 62 79 4c 58 35 47 4a 2b 6f 5a 50 39 58 7a 4f 74 52 70 52 74 4c 75 2f 49 53 38 34 33 58 4e 4d 35 36 33 4f 42 73 68 71 56 35 51 56 50 4f 79 76 72 39 51 6f 56 52 55 47 36 51 73 43 43 77 59 6c 45 49 6c 75 32 62 48 6e 72 72 62 64 47 6a 42 67 78 65 76 54 6f 44 4c 36 53 59
                Data Ascii: o86W5Z7z6wwXZijzHF4mVZRrrKu+91cXExWiE9Xq/3pZdeikQiU6ZMMbLYVSKr1Xr8+PH9+/fjQwHIOnRydNxvJEmqq6uzWCwsy54prV/NDnoJ4W/rpQcnJ01X+872XfvGoUMB+bEZFTVF1n7/5v92tn/Q/kkFLKu91uVIbyLX5GJ+oZP9XzOtRpRtLu/IS843XNM563OBshqV5QVPOyvr9QoVRUG6QsCCwYlEIlu2bHnrrbdGjBgxevToDL6SY
                2024-04-16 23:57:45 UTC1369INData Raw: 2b 37 66 54 79 6d 38 73 2f 58 56 65 34 5a 45 4a 6c 73 72 39 66 33 2f 70 70 4c 39 54 39 73 35 49 75 59 4f 7a 77 68 75 37 2b 78 34 6e 45 33 31 2f 2b 33 72 45 4f 62 2f 2b 4c 35 75 59 4d 64 78 4a 50 42 37 6e 59 71 46 6c 73 50 59 67 4a 52 66 79 39 45 36 30 66 58 75 55 36 39 78 6e 58 36 77 33 57 75 38 75 4d 57 4c 4c 4e 42 62 33 56 72 2f 34 30 37 51 6f 4f 4b 4d 6f 41 42 44 31 59 75 6c 49 55 70 61 6d 70 36 63 30 33 33 36 79 73 72 4b 79 74 72 54 58 67 47 61 31 57 61 32 74 72 61 33 4e 7a 4d 78 6f 66 4e 49 39 54 30 55 51 6c 69 6d 4b 30 53 79 6e 61 6d 5a 54 5a 56 78 6a 4e 59 62 45 68 54 42 41 45 38 37 7a 43 5a 4f 6b 71 72 73 4b 4c 7a 57 61 7a 57 43 7a 6a 78 34 39 6e 47 4d 5a 6d 73 2b 31 79 31 7a 65 6c 66 41 76 43 2f 37 7a 45 57 6d 70 4e 65 73 31 63 59 42 56 6d 6a 6e
                Data Ascii: +7fTym8s/XVe4ZEJlsr9f3/ppL9T9s5IuYOzwhu7+x4nE31/+3rEOb/+L5uYMdxJPB7nYqFlsPYgJRfy9E60fXuU69xnX6w3Wu8uMWLLNBb3Vr/407QoOKMoABD1YulIUpamp6c0336ysrKytrTXgGa1Wa2tra3NzMxofNI9T0UQlimK0SynamZTZVxjNYbEhTBAE87zCZOkqrsKLzWazWCzjx49nGMZms+1y1zelfAvC/7zEWmpNes1cYBVmjn
                2024-04-16 23:57:45 UTC1369INData Raw: 72 57 7a 44 58 39 4f 2b 66 6b 5a 52 42 6b 44 41 79 71 52 4e 6d 7a 59 5a 38 30 53 33 33 48 49 4c 36 6a 56 41 58 47 64 56 31 6b 31 52 4e 30 38 62 53 70 4a 6b 73 39 6b 6b 53 64 4b 71 44 52 4d 4c 75 45 75 53 70 4b 70 71 53 55 6b 4a 2f 66 6d 59 55 4e 52 44 78 48 51 32 48 66 51 52 51 70 34 34 32 48 33 35 65 38 64 4b 6e 39 74 7a 79 79 76 4e 7a 32 38 2f 30 39 72 6c 31 37 5a 5a 59 73 75 51 45 6e 73 2f 4f 53 7a 5a 44 50 70 6a 35 7a 39 35 4a 59 70 43 55 69 67 39 76 2b 39 73 58 39 4c 44 61 63 78 63 4d 53 4a 49 5a 47 6a 58 44 4c 79 76 70 2b 71 31 6e 35 47 30 70 6b 38 70 69 6f 4a 6c 67 34 43 41 6c 57 48 4e 7a 63 30 65 6a 32 65 77 6a 7a 70 38 2b 48 42 72 61 2b 76 35 38 2b 64 54 48 39 30 76 4c 53 32 39 37 72 72 72 30 4f 44 35 69 57 45 59 6d 71 76 51 57 61 55 74 6a 75 4e
                Data Ascii: rWzDX9O+fkZRBkDAyqRNmzYZ80S33HIL6jVAXGdV1k1RN08bSpJks9kkSdKqDRMLuEuSpKpqSUkJ/fmYUNRDxHQ2HfQRQp442H35e8dKn9tzyyvNz28/09rl17ZZYsuQEns/OSzZDPpj5z95JYpCUig9v+9sX9LDacxcMSJIZGjXDLyvp+q1n5G0pk8pioJlg4CAlWHNzc0ej2ewjzp8+HBra+v58+dTH90vLS297rrr0OD5iWEYmqvQWaUtjuN
                2024-04-16 23:57:45 UTC1369INData Raw: 49 45 75 43 55 53 36 4d 6e 6b 43 70 6f 73 4d 2b 70 30 4c 48 7a 63 2b 79 50 4f 38 4c 4d 75 30 64 70 30 67 43 42 48 52 74 6f 38 70 31 4f 6d 46 44 56 44 77 6e 53 37 4b 4f 78 53 51 76 37 75 6e 34 2f 4c 33 6a 68 46 43 50 6d 68 50 65 71 50 36 48 30 34 74 4a 34 51 51 49 54 35 4c 2f 57 57 47 62 59 41 36 37 4e 4f 48 4f 51 5a 49 56 36 73 4f 6e 5a 2f 39 35 75 46 6f 75 72 71 35 33 46 5a 69 37 33 2f 67 6a 2f 61 45 66 66 72 2f 36 63 35 77 64 78 2f 59 55 50 4c 52 47 32 6b 38 45 50 64 79 42 67 51 73 6b 39 71 34 63 57 4f 79 66 31 71 2f 66 76 30 58 76 76 43 46 4d 32 66 4f 6f 4a 55 67 72 73 2b 44 72 6c 38 54 42 41 45 44 67 6c 6e 30 71 64 46 69 57 72 47 66 57 6d 49 42 64 35 66 4c 35 58 41 34 62 44 59 62 49 63 52 6d 73 2b 31 67 53 6d 53 69 31 30 63 38 71 79 54 70 71 4d 55 46
                Data Ascii: IEuCUS6MnkCposM+p0LHzc+yPO8LMu0dp0gCBHRto8p1OmFDVDwnS7KOxSQv7un4/L3jhFCPmhPeqP6H04tJ4QQIT5L/WWGbYA67NOHOQZIV6sOnZ/95uFourq53FZi73/gj/aEffr/6c5wdx/YUPLRG2k8EPdyBgQsk9q4cWOyf1q/fv0XvvCFM2fOoJUgrs+Drl8TBAEDgln0qdFiWrGfWmIBd5fL5XA4bDYbIcRms+1gSmSi10c8qyTpqMUF
                2024-04-16 23:57:45 UTC1369INData Raw: 39 57 79 45 7a 54 4d 77 77 6d 53 36 49 44 41 78 57 74 38 6c 6c 46 52 55 56 6c 5a 65 58 59 73 57 50 70 7a 2b 38 35 4a 72 7a 41 31 6d 58 34 4e 63 6d 52 70 4c 4f 61 2f 48 32 50 6c 49 61 2b 4f 57 39 45 73 76 4a 55 73 56 62 73 4f 2f 65 74 54 61 63 2f 6e 54 68 50 79 43 4b 33 74 4b 53 2b 65 4e 47 6f 77 67 6d 6c 30 74 42 66 5a 6f 63 33 39 4f 69 47 63 38 2f 30 44 61 49 48 53 2b 78 75 47 2f 76 4d 6e 56 7a 51 4e 36 67 6e 55 6c 55 31 45 41 6a 67 57 41 33 70 58 4d 4c 45 72 6d 55 44 41 4d 50 69 74 53 52 4a 36 4c 58 4b 38 33 33 41 59 72 48 55 31 74 5a 61 72 56 61 57 5a 55 74 4b 53 68 69 47 36 54 37 66 32 61 6e 77 69 6d 6a 4c 32 4d 73 61 49 4f 34 4c 34 72 71 7a 6e 76 39 71 4f 6d 58 78 68 30 57 57 44 48 66 33 4d 30 33 4b 46 35 62 58 48 75 33 2b 31 37 38 66 2b 66 6d 42 38
                Data Ascii: 9WyEzTMwwmS6IDAxWt8llFRUVlZeXYsWPpz+85JrzA1mX4NcmRpLOa/H2PlIa+OW9EsvJUsVbsO/etTac/nThPyCK3tKS+eNGowgml0tBfZoc39OiGc8/0DaIHS+xuG/vMnVzQN6gnUlU1EAjgWA3pXMLErmUDAMPitSRJ6LXK833AYrHU1tZarVaWZUtKShiG6T7f2anwimjL2MsaIO4L4rqznv9qOmXxh0WWDHf3M03KF5bXHu3+178f+fmB8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44973935.190.80.14433744C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:45 UTC545OUTOPTIONS /report/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://dhl.link66820.site
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 23:57:45 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: POST, OPTIONS
                access-control-allow-origin: *
                access-control-allow-headers: content-length, content-type
                date: Tue, 16 Apr 2024 23:57:45 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449736104.21.7.204433744C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:46 UTC625OUTGET /static/errors/404/favicon.png HTTP/1.1
                Host: dhl.link66820.site
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://dhl.link66820.site/order/ZxWKPP2i/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 23:57:46 UTC674INHTTP/1.1 200 OK
                Date: Tue, 16 Apr 2024 23:57:46 GMT
                Content-Type: image/png
                Content-Length: 2188
                Connection: close
                Last-Modified: Sun, 14 Apr 2024 22:51:20 GMT
                ETag: "661c5de8-88c"
                Cache-Control: max-age=14400
                CF-Cache-Status: MISS
                Accept-Ranges: bytes
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=84W4pnfCDgWAzT105bofUpVZBS3%2BE5Bpb95rOWWBbz4hxL6OQkHzMUydeoNNP%2BiL82hFQyImwdhbT8iTy9zdaxWVIrpyr7KkM0M7m%2B1fgmocN4TN3niETCTsyUaTxIiOWqJtvA0%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 87581e9b8912674d-ATL
                alt-svc: h3=":443"; ma=86400
                2024-04-16 23:57:46 UTC695INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 c8 08 06 00 00 00 ad 58 ae 9e 00 00 00 04 73 42 49 54 08 08 08 08 7c 08 64 88 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 08 2e 49 44 41 54 78 9c ed dd 5d a8 5c 57 19 87 f1 e7 24 6d aa 46 db 9a 36 98 fa d1 5a 41 a2 a6 b4 a9 22 52 c5 cf 62 8b e2 5d 5b 89 20 bd 10 04 6f 04 e9 85 78 a7 57 de e8 85 17 55 b0 22 8c a8 f5 13 15 15 94 62 ec 80 22 48 23 d5 da 98 52 95 f8 51 ac da d4 a6 c9 89 25 4d 93 e3 c5 9a 31 87 70 66 cf 5e 7b f6 cc bb 66 d6 f3 83 cd b9 d9 67 bf ef 39 67 ff cf ec 3d b3 d6 da 20 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 d2 aa 59 8b 6e 60 93
                Data Ascii: PNGIHDRXsBIT|dpHYs.IDATx]\W$mF6ZA"Rb][ oxWU"b"H#RQ%M1pf^{fg9g= I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$IYn`
                2024-04-16 23:57:46 UTC1369INData Raw: f3 e8 eb f7 49 e1 d3 02 0d 99 ff 58 ac 9b 48 a3 86 b7 3a f6 11 f2 a7 74 1e 20 3d 89 75 ab e3 fd 02 d8 31 63 bf b9 ae 04 fe 38 a1 9f 93 c0 5b 33 8f b7 8f b4 ea fe 56 c7 fb 17 29 3c 7d 19 4c a8 53 cc 58 ac 68 43 e6 1b 90 6d a4 10 34 1d ff 11 da 87 e4 00 70 76 ca f1 ee 9a a1 df 2e be 38 a5 9f 75 da 87 a4 29 1c e3 ed 47 3d f6 3e 98 52 cb 80 30 df 80 bc a1 c5 f1 db 86 a4 4d 38 36 80 df cc d0 6f ae 6d c0 89 16 3d b5 09 49 9b 70 6c 00 e7 e8 6f 9e f8 a0 45 bd 61 4f b5 3a 59 f5 7b 90 ab 5b ee b7 97 74 8f 32 29 24 07 80 af d3 ee f7 75 4d cb 9a 7d b8 8c 76 37 e4 3b 81 9f 30 39 24 fb 48 3f 7f 9b e7 01 ae 01 2f 6f d5 dd 0a 58 f5 80 e4 4c e9 9d 14 92 9c 70 c0 62 a7 88 9e a0 fd ac cc 49 21 c9 09 c7 58 35 53 a5 57 3d 20 87 80 bf 66 ec 7f 61 48 72 c3 01 f0 ed 8c 7d 67 75
                Data Ascii: IXH:t =u1c8[3V)<}LSXhCm4pv.8u)G=>R0M86om=IploEaO:Y{[t2)$uM}v7;09$H?/oXLpbI!X5SW= faHr}gu
                2024-04-16 23:57:46 UTC124INData Raw: cf 30 d1 af 20 00 fb 49 cb 7f 9e 8d 6e 44 c5 38 0b 7c 13 b8 31 ba 91 12 5e 41 c6 b6 01 d7 01 db 81 a7 82 7b 51 8c 5d a4 67 bd 1f a6 e2 85 22 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 9a af ff 01 de fe a0 40 55 2d af 35 00 00 00 00 49 45 4e 44 ae 42 60 82
                Data Ascii: 0 InD8|1^A{Q]g"$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I@U-5IENDB`


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974235.190.80.14433744C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:46 UTC484OUTPOST /report/v4?s=DvXX0AARqmtNchAnu6YvIvwECNSGB%2F3629WX76Dl5ZkMSWf2FnQDgg3J%2B05X2rq5Ae2tyVh4zGmLi7OwPwDVgKIWia2m4N1cCuH5GBHLKO1U%2F5IQ6UFNVIn4MTorIjeUCiV%2Bo3w%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 401
                Content-Type: application/reports+json
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 23:57:46 UTC401OUTData Raw: 5b 7b 22 61 67 65 22 3a 37 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 39 36 31 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 37 2e 32 30 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 64 68 6c 2e 6c 69 6e 6b 36 36 38 32 30 2e 73 69 74 65
                Data Ascii: [{"age":7,"body":{"elapsed_time":961,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.7.20","status_code":404,"type":"http.error"},"type":"network-error","url":"https://dhl.link66820.site
                2024-04-16 23:57:46 UTC168INHTTP/1.1 200 OK
                Content-Length: 0
                date: Tue, 16 Apr 2024 23:57:45 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.449745104.21.7.204433744C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:47 UTC371OUTGET /static/errors/404/favicon.png HTTP/1.1
                Host: dhl.link66820.site
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: */*
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: cors
                Sec-Fetch-Dest: empty
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 23:57:47 UTC685INHTTP/1.1 200 OK
                Date: Tue, 16 Apr 2024 23:57:47 GMT
                Content-Type: image/png
                Content-Length: 2188
                Connection: close
                Last-Modified: Sun, 14 Apr 2024 22:51:20 GMT
                ETag: "661c5de8-88c"
                Cache-Control: max-age=14400
                CF-Cache-Status: HIT
                Age: 1
                Accept-Ranges: bytes
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1sH5TznDrgKBHjVanQvst9%2FnGy0Q8tXP8Q3eqHYPmaXvAKjxI6tamgAfXP9eNAYsNUrORwRHs%2F42fo%2BUcQ%2BwAG0sPoheVdzbpCeWuHV3CAeUuA%2BhQHfQrxhD2cuAX0PDuY62u48%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 87581ea42ccf6746-ATL
                alt-svc: h3=":443"; ma=86400
                2024-04-16 23:57:47 UTC684INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 c8 08 06 00 00 00 ad 58 ae 9e 00 00 00 04 73 42 49 54 08 08 08 08 7c 08 64 88 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 08 2e 49 44 41 54 78 9c ed dd 5d a8 5c 57 19 87 f1 e7 24 6d aa 46 db 9a 36 98 fa d1 5a 41 a2 a6 b4 a9 22 52 c5 cf 62 8b e2 5d 5b 89 20 bd 10 04 6f 04 e9 85 78 a7 57 de e8 85 17 55 b0 22 8c a8 f5 13 15 15 94 62 ec 80 22 48 23 d5 da 98 52 95 f8 51 ac da d4 a6 c9 89 25 4d 93 e3 c5 9a 31 87 70 66 cf 5e 7b f6 cc bb 66 d6 f3 83 cd b9 d9 67 bf ef 39 67 ff cf ec 3d b3 d6 da 20 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 d2 aa 59 8b 6e 60 93
                Data Ascii: PNGIHDRXsBIT|dpHYs.IDATx]\W$mF6ZA"Rb][ oxWU"b"H#RQ%M1pf^{fg9g= I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$IYn`
                2024-04-16 23:57:47 UTC1369INData Raw: 01 d7 75 3c de b5 c0 0f 46 c7 f9 f3 e8 eb f7 49 e1 d3 02 0d 99 ff 58 ac 9b 48 a3 86 b7 3a f6 11 f2 a7 74 1e 20 3d 89 75 ab e3 fd 02 d8 31 63 bf b9 ae 04 fe 38 a1 9f 93 c0 5b 33 8f b7 8f b4 ea fe 56 c7 fb 17 29 3c 7d 19 4c a8 53 cc 58 ac 68 43 e6 1b 90 6d a4 10 34 1d ff 11 da 87 e4 00 70 76 ca f1 ee 9a a1 df 2e be 38 a5 9f 75 da 87 a4 29 1c e3 ed 47 3d f6 3e 98 52 cb 80 30 df 80 bc a1 c5 f1 db 86 a4 4d 38 36 80 df cc d0 6f ae 6d c0 89 16 3d b5 09 49 9b 70 6c 00 e7 e8 6f 9e f8 a0 45 bd 61 4f b5 3a 59 f5 7b 90 ab 5b ee b7 97 74 8f 32 29 24 07 80 af d3 ee f7 75 4d cb 9a 7d b8 8c 76 37 e4 3b 81 9f 30 39 24 fb 48 3f 7f 9b e7 01 ae 01 2f 6f d5 dd 0a 58 f5 80 e4 4c e9 9d 14 92 9c 70 c0 62 a7 88 9e a0 fd ac cc 49 21 c9 09 c7 58 35 53 a5 57 3d 20 87 80 bf 66 ec 7f
                Data Ascii: u<FIXH:t =u1c8[3V)<}LSXhCm4pv.8u)G=>R0M86om=IploEaO:Y{[t2)$uM}v7;09$H?/oXLpbI!X5SW= f
                2024-04-16 23:57:47 UTC135INData Raw: f6 30 b0 2f ba 09 15 e9 21 d2 8c cf 30 d1 af 20 00 fb 49 cb 7f 9e 8d 6e 44 c5 38 0b 7c 13 b8 31 ba 91 12 5e 41 c6 b6 01 d7 01 db 81 a7 82 7b 51 8c 5d a4 67 bd 1f a6 e2 85 22 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 92 24 49 9a af ff 01 de fe a0 40 55 2d af 35 00 00 00 00 49 45 4e 44 ae 42 60 82
                Data Ascii: 0/!0 InD8|1^A{Q]g"$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I$I@U-5IENDB`


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.449744104.123.200.136443
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:47 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-16 23:57:47 UTC468INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus2-z1
                Cache-Control: public, max-age=111962
                Date: Tue, 16 Apr 2024 23:57:47 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.449746104.123.200.136443
                TimestampBytes transferredDirectionData
                2024-04-16 23:57:47 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-16 23:57:48 UTC531INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=111880
                Date: Tue, 16 Apr 2024 23:57:48 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-16 23:57:48 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:01:57:37
                Start date:17/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:01:57:39
                Start date:17/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1900,i,8584048215130342334,13196278809595615715,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:01:57:43
                Start date:17/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dhl.link66820.site/order/ZxWKPP2i/"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly