Windows Analysis Report
DownloadDirectorLauncher1.zip

Overview

General Information

Sample name: DownloadDirectorLauncher1.zip
Analysis ID: 1427739
MD5: d79ed2719bd67207dafde96dc71000d7
SHA1: a1277fe10a6dfff82dfcb6612d2db97cbd66350f
SHA256: ed1e8e934bf18c8f4698dd04c7e3b476659e7319b6851667f8dbb950eb17caf1
Infos:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Stores files to the Windows start menu directory

Classification

Source: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP Parser: No favicon
Source: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP Parser: No favicon
Source: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=wjjJycx7A6xdUH8ymV2wAZsbKFYleBfhF8M78a8nZ0f9I9xmxGqsZcDi4de3HWpwlf5odCOBWLTyz5Uf7Bn6iJyLK35QLtLGlBU67qESmK9mxN29oVR-6FuCKaXENR6UkgP__244I-nj6qgpOEaDoiRaMKZVWFmbNcQafOsK-kI2rqdMXqyqp7jPyowgz7wNrLOc87nXDsyxwDfprA85Hx2brNu0KST-f3giZLoYokBLsOTP5MHPjn8N0fzG5UkKoZaBGMpRytE1aR9bCt7kxNbWStTUVmo&cb=lk73a6yg16hu HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=wjjJycx7A6xdUH8ymV2wAZsbKFYleBfhF8M78a8nZ0f9I9xmxGqsZcDi4de3HWpwlf5odCOBWLTyz5Uf7Bn6iJyLK35QLtLGlBU67qESmK9mxN29oVR-6FuCKaXENR6UkgP__244I-nj6qgpOEaDoiRaMKZVWFmbNcQafOsK-kI2rqdMXqyqp7jPyowgz7wNrLOc87nXDsyxwDfprA85Hx2brNu0KST-f3giZLoYokBLsOTP5MHPjn8N0fzG5UkKoZaBGMpRytE1aR9bCt7kxNbWStTUVmo&cb=lk73a6yg16hu HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP Parser: No favicon
Source: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: Joe Sandbox View IP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 23.33.136.127
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rP1zYzBT3PL17Hh&MD=kDgTXRm9 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=rP1zYzBT3PL17Hh&MD=kDgTXRm9 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtTk0GInlgbEGIjAqSG6qzk0ra_97H04g98D6YmD7Q3oweFIUlIYySdkbCbloCe41Ki0htoN7VEj0BBcyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=mE19LzVEoqaHGsHyJIOfTP52AtkRlCrY_njRf47RaRhf1LrMMP82RGJ4VbdsyuW4FvCl5xahwpcu5Szio7cep5teQ8K92WeBxUNe4dg9jQlBmFh3ugRXtpHxsETBQuhwOU7do37YRUuPvaIFan23VQR-EHEdCpcaU4p53ZI_ejs
Source: global traffic HTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtTk0GInlgbEGIjDD_Fw62_katFhyo9zzmr8gQmeIehtlet4MzBVMpDoKind8jSRiUN-W8363LVjsk9AyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=v&oit=1&cp=1&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=vi&oit=1&cp=2&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=vis&oit=1&cp=3&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=visu&oit=1&cp=4&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=visur&oit=1&cp=5&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /p/AF1QipPWj31KawuEWhcSPEoG10VjL7pu_-t5hy76ZrpA=w92-h92-n-k-no HTTP/1.1Host: lh5.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=visurto&oit=1&cp=7&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=visurtot&oit=1&cp=8&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=visurtotal&oit=1&cp=10&pgcl=7&gs_rn=42&psi=RP5R0tSeoBvYmYQE&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /search?q=visurtotal&oq=visurtotal&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA&sourceid=chrome&ie=UTF-8 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4
Source: global traffic HTTP traffic detected: GET /sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api.js HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=wjjJycx7A6xdUH8ymV2wAZsbKFYleBfhF8M78a8nZ0f9I9xmxGqsZcDi4de3HWpwlf5odCOBWLTyz5Uf7Bn6iJyLK35QLtLGlBU67qESmK9mxN29oVR-6FuCKaXENR6UkgP__244I-nj6qgpOEaDoiRaMKZVWFmbNcQafOsK-kI2rqdMXqyqp7jPyowgz7wNrLOc87nXDsyxwDfprA85Hx2brNu0KST-f3giZLoYokBLsOTP5MHPjn8N0fzG5UkKoZaBGMpRytE1aR9bCt7kxNbWStTUVmo&cb=lk73a6yg16hu HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /js/bg/rIjZlM8ZNfOeVQTojtt5OPuY9YnE0CAT82tG0V-YUX0.js HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=wjjJycx7A6xdUH8ymV2wAZsbKFYleBfhF8M78a8nZ0f9I9xmxGqsZcDi4de3HWpwlf5odCOBWLTyz5Uf7Bn6iJyLK35QLtLGlBU67qESmK9mxN29oVR-6FuCKaXENR6UkgP__244I-nj6qgpOEaDoiRaMKZVWFmbNcQafOsK-kI2rqdMXqyqp7jPyowgz7wNrLOc87nXDsyxwDfprA85Hx2brNu0KST-f3giZLoYokBLsOTP5MHPjn8N0fzG5UkKoZaBGMpRytE1aR9bCt7kxNbWStTUVmo&cb=lk73a6yg16huAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/webworker.js?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm- HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: workerReferer: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=wjjJycx7A6xdUH8ymV2wAZsbKFYleBfhF8M78a8nZ0f9I9xmxGqsZcDi4de3HWpwlf5odCOBWLTyz5Uf7Bn6iJyLK35QLtLGlBU67qESmK9mxN29oVR-6FuCKaXENR6UkgP__244I-nj6qgpOEaDoiRaMKZVWFmbNcQafOsK-kI2rqdMXqyqp7jPyowgz7wNrLOc87nXDsyxwDfprA85Hx2brNu0KST-f3giZLoYokBLsOTP5MHPjn8N0fzG5UkKoZaBGMpRytE1aR9bCt7kxNbWStTUVmo&cb=lk73a6yg16huAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dvisurtotal%26oq%3Dvisurtotal%26gs_lcrp%3DEgZjaHJvbWUyBggAEEUYOTIPCAEQABgKGIMBGLEDGIAEMg8IAhAAGAoYgwEYsQMYgAQyDAgDEAAYChixAxiABDIJCAQQABgKGIAEMgkIBRAAGAoYgAQyCQgGEAAYChiABDIECAcQBdIBCDcwNTFqMGo3qAIAsAIA%26sourceid%3Dchrome%26ie%3DUTF-8&q=EgRRtTk0GJLlgbEGIjBFlmw-Z1Jr1gypU10CH7MqD41FI5YyaJtIY5ytq6NLWWR7LvXEHvlKJylF7TKn-sgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/reload?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7yxEwJrTQzKFdvzKXBPyepU7lkUD6FHF_xaRg9MITh_oBGwJBlnrTky_tJUTuRePPmh9rA1h38UdFZMrfj0veWAhi-6avQdfso_JuqEei9G1OBX8K271KlGTtCIxsfd5i-to_bzQRZa4agIbvfNy8oOaERLvakWtpQI_wIkaJLEVAOh_WWRq5gROK9kU9nKkvq62Ju&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7yxEwJrTQzKFdvzKXBPyepU7lkUD6FHF_xaRg9MITh_oBGwJBlnrTky_tJUTuRePPmh9rA1h38UdFZMrfj0veWAhi-6avQdfso_JuqEei9G1OBX8K271KlGTtCIxsfd5i-to_bzQRZa4agIbvfNy8oOaERLvakWtpQI_wIkaJLEVAOh_WWRq5gROK9kU9nKkvq62Ju&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7yxEwJrTQzKFdvzKXBPyepU7lkUD6FHF_xaRg9MITh_oBGwJBlnrTky_tJUTuRePPmh9rA1h38UdFZMrfj0veWAhi-6avQdfso_JuqEei9G1OBX8K271KlGTtCIxsfd5i-to_bzQRZa4agIbvfNy8oOaERLvakWtpQI_wIkaJLEVAOh_WWRq5gROK9kU9nKkvq62Ju&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&id=2 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/replaceimage?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7yxEwJrTQzKFdvzKXBPyepU7lkUD6FHF_xaRg9MITh_oBGwJBlnrTky_tJUTuRePPmh9rA1h38UdFZMrfj0veWAhi-6avQdfso_JuqEei9G1OBX8K271KlGTtCIxsfd5i-to_bzQRZa4agIbvfNy8oOaERLvakWtpQI_wIkaJLEVAOh_WWRq5gROK9kU9nKkvq62Ju&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&id=2 HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/userverify?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7h1gq_qS7al9HO7PQpzGTS5JWeX2FsfH159FjvTdvn_zUmpWU8JVsvm7trvqlPZ5_YAo-57ycQzgvbKn81Fot6-oIbceP5fjtRi2ZywiuvEXdVQJyV1I7MaV9pKPWF5fyGEszk2-PYs-dy74nFG0dBCsG9C4iuZVDbahfIj7unSSccRNQyV5eBz7q1hBqAgrSBfG_q&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7h1gq_qS7al9HO7PQpzGTS5JWeX2FsfH159FjvTdvn_zUmpWU8JVsvm7trvqlPZ5_YAo-57ycQzgvbKn81Fot6-oIbceP5fjtRi2ZywiuvEXdVQJyV1I7MaV9pKPWF5fyGEszk2-PYs-dy74nFG0dBCsG9C4iuZVDbahfIj7unSSccRNQyV5eBz7q1hBqAgrSBfG_q&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7h1gq_qS7al9HO7PQpzGTS5JWeX2FsfH159FjvTdvn_zUmpWU8JVsvm7trvqlPZ5_YAo-57ycQzgvbKn81Fot6-oIbceP5fjtRi2ZywiuvEXdVQJyV1I7MaV9pKPWF5fyGEszk2-PYs-dy74nFG0dBCsG9C4iuZVDbahfIj7unSSccRNQyV5eBz7q1hBqAgrSBfG_q&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&id=2 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/replaceimage?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7h1gq_qS7al9HO7PQpzGTS5JWeX2FsfH159FjvTdvn_zUmpWU8JVsvm7trvqlPZ5_YAo-57ycQzgvbKn81Fot6-oIbceP5fjtRi2ZywiuvEXdVQJyV1I7MaV9pKPWF5fyGEszk2-PYs-dy74nFG0dBCsG9C4iuZVDbahfIj7unSSccRNQyV5eBz7q1hBqAgrSBfG_q&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&id=2 HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/userverify?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7PcvxEYFJucuS82ElQVhj9hNdQMnoOrcf94c85gf0b7M2K9weu7o2GvjbBCx_A22Kkd8cDW84vB5kaPQz0WBRySb_QbFJJqxd4YA-TUzxAK18LWuaf6TZ8-o1hukGdqWZGtNRUmwZW6JZOCbzk9avrwNXRmkck1E6a3ZSxeTvXiKF8T_79HJH0JBwqI5it1DjWIeUt&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: global traffic HTTP traffic detected: GET /recaptcha/api2/payload?p=06AFcWeA7PcvxEYFJucuS82ElQVhj9hNdQMnoOrcf94c85gf0b7M2K9weu7o2GvjbBCx_A22Kkd8cDW84vB5kaPQz0WBRySb_QbFJJqxd4YA-TUzxAK18LWuaf6TZ8-o1hukGdqWZGtNRUmwZW6JZOCbzk9avrwNXRmkck1E6a3ZSxeTvXiKF8T_79HJH0JBwqI5it1DjWIeUt&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEIucrNAQiJ080BGMvYzQEY642lFw==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09AH0dGfQPRrZ_CbCVlvAzYcc3QNfHah5BSRB63Az9DjkgB73is8iMnQ5JcXIfyQ7PgYr4o_HpPrSr6q3ZmzBsxjs; 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: unknown DNS traffic detected: queries for: www.google.com
Source: unknown HTTP traffic detected: POST /recaptcha/api2/reload?k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b HTTP/1.1Host: www.google.comConnection: keep-aliveContent-Length: 7482sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-protobufferAccept: */*Origin: https://www.google.comX-Client-Data: CIu2yQEIprbJAQipncoBCLbgygEIlKHLAQj2mM0BCIWgzQEI3L3NAQiSys0BCLnKzQEIx9HNAQiJ080BCNzTzQEIy9bNAQj01s0BCIrXzQEIp9jNAQj5wNQVGLrSzQEYy9jNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-18-01; NID=513=EUpSlw5z64ofsc1VGKp8pfpuj3hZRgmZ4W_1gZa1WmZFaMdKtj3pSMC-rSFdFXlCZUCvynj4NqKLrxGrerGFR35ZmU76XoByKGDgkAvvpak0fwAK5cIHjfLMCvzsKH8CRigPq2BupXlATYbUpljj-GxoB-fA6jdT0GDjLMr4Cx4; AEC=AQTF6HybsPYqJbpgeyQHtkNvOsh5Fu0SNkrk8IDbh4M0JVq57opLkcgvhQ
Source: DownloadDirectorLauncher.exe.exe String found in binary or memory: http://gcc.gnu.org/bugs.html):
Source: chromecache_171.14.dr String found in binary or memory: https://cloud.google.com/contact
Source: chromecache_171.14.dr String found in binary or memory: https://cloud.google.com/recaptcha-enterprise/billing-information
Source: chromecache_171.14.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
Source: chromecache_171.14.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#localhost_support
Source: chromecache_171.14.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
Source: chromecache_171.14.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_171.14.dr String found in binary or memory: https://recaptcha.net
Source: chromecache_171.14.dr String found in binary or memory: https://support.google.com/recaptcha
Source: chromecache_171.14.dr String found in binary or memory: https://support.google.com/recaptcha#6262736
Source: chromecache_171.14.dr String found in binary or memory: https://support.google.com/recaptcha/#6175971
Source: chromecache_171.14.dr String found in binary or memory: https://support.google.com/recaptcha/?hl=en#6223828
Source: chromecache_139.14.dr, chromecache_171.14.dr String found in binary or memory: https://www.google.com/recaptcha/api2/
Source: chromecache_171.14.dr String found in binary or memory: https://www.gstatic.c..?/recaptcha/releases/rz4DvU-cY2JYCwHSTck0_qm-/recaptcha__.
Source: chromecache_139.14.dr, chromecache_150.14.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/rz4DvU-cY2JYCwHSTck0_qm-/recaptcha__en.js
Source: chromecache_126.14.dr, chromecache_132.14.dr, chromecache_148.14.dr String found in binary or memory: https://www.virustotal.com/
Source: DownloadDirectorLauncher.exe.exe String found in binary or memory: https://www14.software.ibm.com/dldirector/
Source: DownloadDirectorLauncher.exe.exe String found in binary or memory: https://www14.software.ibm.com/dldirector/%%26h%3D&h=///IBMDownloadDirectorApp.jnlpPATH;Javajavajrej
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49688 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.33.136.127:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: classification engine Classification label: clean1.winZIP@19/92@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe "C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe"
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe "C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe"
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1888,i,2403929920380648888,10293033927867228673,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=1888,i,2403929920380648888,10293033927867228673,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\Temp1_DownloadDirectorLauncher1.zip\DownloadDirectorLauncher.exe.exe Section loaded: wintypes.dll Jump to behavior
Source: Google Drive.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.13.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs