Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.qxeuwqccdzaaaqie6.info

Overview

General Information

Sample URL:https://www.qxeuwqccdzaaaqie6.info
Analysis ID:1428133
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1856 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1056 --field-trial-handle=2008,i,12713511431468982074,11000798207561646413,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6396 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.qxeuwqccdzaaaqie6.info" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.qxeuwqccdzaaaqie6.infoConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/log.php HTTP/1.1Host: documentatie.infoConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: www.qxeuwqccdzaaaqie6.info
Source: unknownHTTP traffic detected: POST /report/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 398Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 18 Apr 2024 13:42:20 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 876513d79b3fb0c1-ATLalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@18/0@8/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1056 --field-trial-handle=2008,i,12713511431468982074,11000798207561646413,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.qxeuwqccdzaaaqie6.info"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1056 --field-trial-handle=2008,i,12713511431468982074,11000798207561646413,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.qxeuwqccdzaaaqie6.info
104.21.40.211
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      a.nel.cloudflare.com
      35.190.80.1
      truefalse
        high
        documentatie.info
        172.67.185.106
        truefalse
          unknown
          www.google.com
          64.233.177.104
          truefalse
            high
            fp2e7a.wpc.phicdn.net
            192.229.211.108
            truefalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://www.qxeuwqccdzaaaqie6.info/false
                unknown
                https://documentatie.info/v/log.phpfalse
                  unknown
                  https://a.nel.cloudflare.com/report/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3Dfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    172.67.185.106
                    documentatie.infoUnited States
                    13335CLOUDFLARENETUSfalse
                    64.233.177.104
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    104.21.40.211
                    www.qxeuwqccdzaaaqie6.infoUnited States
                    13335CLOUDFLARENETUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    35.190.80.1
                    a.nel.cloudflare.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.16
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1428133
                    Start date and time:2024-04-18 15:41:26 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 8s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://www.qxeuwqccdzaaaqie6.info
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@18/0@8/7
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 173.194.219.94, 142.250.9.139, 142.250.9.101, 142.250.9.113, 142.250.9.102, 142.250.9.138, 142.250.9.100, 172.217.215.84, 34.104.35.123, 52.165.165.26, 199.232.210.172, 192.229.211.108, 20.3.187.198, 20.242.39.171, 142.250.105.94
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: https://www.qxeuwqccdzaaaqie6.info
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    No created / dropped files found
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 18, 2024 15:42:08.802995920 CEST49678443192.168.2.4104.46.162.224
                    Apr 18, 2024 15:42:10.865268946 CEST49675443192.168.2.4173.222.162.32
                    Apr 18, 2024 15:42:19.059273005 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.059315920 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.059376955 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.059647083 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.059659004 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.060106039 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.060142994 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.060190916 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.060421944 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.060431957 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.287318945 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.294509888 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.300184011 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.300219059 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.300313950 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.300339937 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.301402092 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.301490068 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.303301096 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.303410053 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.304672003 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.304780006 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.305778980 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.305973053 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.306273937 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.306288004 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.351211071 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.351212978 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.351222992 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.398161888 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.546241045 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.546322107 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.546381950 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.546879053 CEST49736443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:19.546894073 CEST44349736104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:19.683866024 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.683911085 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.683980942 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.684242010 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.684257984 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.916184902 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.916598082 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.916610003 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.917830944 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.917912960 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.919879913 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.919944048 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.920171022 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:19.920176983 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:19.970527887 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:20.473826885 CEST49675443192.168.2.4173.222.162.32
                    Apr 18, 2024 15:42:20.609988928 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:20.610055923 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:20.610107899 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:20.627331972 CEST49739443192.168.2.4172.67.185.106
                    Apr 18, 2024 15:42:20.627351999 CEST44349739172.67.185.106192.168.2.4
                    Apr 18, 2024 15:42:20.747098923 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:20.747127056 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:20.747176886 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:20.763847113 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:20.763859034 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:20.981313944 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:20.981591940 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:20.981609106 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:20.982580900 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:20.982641935 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.385665894 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.385962009 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.387326956 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.387336969 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.428163052 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.518682957 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.518758059 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.519778013 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.523407936 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.523447990 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.523607969 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.523801088 CEST49740443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.523828030 CEST4434974035.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.524231911 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.524255037 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.524315119 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.524863958 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.524876118 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.525219917 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.525229931 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.738409996 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.742156982 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.754127979 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.754141092 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.754548073 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.754558086 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.754582882 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.755312920 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.755387068 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.755636930 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.755690098 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.755904913 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.757359028 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.757436037 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.800120115 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.801245928 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.801269054 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:21.848134041 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:21.971812010 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:21.971904993 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:21.972038984 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:21.975743055 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.975927114 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:21.976813078 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.996673107 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:21.996716976 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:21.997308016 CEST49742443192.168.2.435.190.80.1
                    Apr 18, 2024 15:42:21.997323036 CEST4434974235.190.80.1192.168.2.4
                    Apr 18, 2024 15:42:22.212352991 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.212584019 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.217236996 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.217267036 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.217570066 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.270041943 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.282059908 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.328135014 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.413598061 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.413666964 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.413764954 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.413907051 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.413907051 CEST49743443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.413954973 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.413983107 CEST44349743184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.446115017 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.446185112 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.446297884 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.446551085 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.446584940 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.659971952 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.660239935 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.661514997 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.661528111 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.661761999 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.662827015 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.704123974 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.873111010 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.873286009 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.873352051 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.875581026 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.875619888 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:22.875654936 CEST49744443192.168.2.4184.31.62.93
                    Apr 18, 2024 15:42:22.875672102 CEST44349744184.31.62.93192.168.2.4
                    Apr 18, 2024 15:42:31.742455006 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:31.742598057 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:31.742652893 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:33.421530008 CEST49741443192.168.2.464.233.177.104
                    Apr 18, 2024 15:42:33.421588898 CEST4434974164.233.177.104192.168.2.4
                    Apr 18, 2024 15:42:34.270777941 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:34.270968914 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:42:34.271029949 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:35.037609100 CEST49735443192.168.2.4104.21.40.211
                    Apr 18, 2024 15:42:35.037645102 CEST44349735104.21.40.211192.168.2.4
                    Apr 18, 2024 15:43:21.436538935 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:21.436578035 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.436651945 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:21.436955929 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:21.436968088 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.649743080 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.650305033 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:21.650341988 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.650667906 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.651658058 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:21.651912928 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:21.692789078 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:31.649339914 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:31.649403095 CEST4434975364.233.177.104192.168.2.4
                    Apr 18, 2024 15:43:31.649451017 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:33.445421934 CEST49753443192.168.2.464.233.177.104
                    Apr 18, 2024 15:43:33.445456982 CEST4434975364.233.177.104192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 18, 2024 15:42:17.273623943 CEST53639881.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:17.322709084 CEST53534041.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:17.961827040 CEST53549061.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:18.921078920 CEST5267953192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:18.921533108 CEST5920053192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:19.055336952 CEST53526791.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:19.058598995 CEST53592001.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:19.549940109 CEST5573153192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:19.550093889 CEST5323153192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:19.683020115 CEST53532311.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:19.683357954 CEST53557311.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:20.632020950 CEST6354153192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:20.632805109 CEST6398153192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:20.736737967 CEST53635411.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:20.738065004 CEST53639811.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:21.388336897 CEST6377153192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:21.388736963 CEST5101753192.168.2.41.1.1.1
                    Apr 18, 2024 15:42:21.493350029 CEST53510171.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:21.495573997 CEST53637711.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:35.142836094 CEST53637621.1.1.1192.168.2.4
                    Apr 18, 2024 15:42:39.446417093 CEST138138192.168.2.4192.168.2.255
                    Apr 18, 2024 15:42:54.126239061 CEST53617671.1.1.1192.168.2.4
                    Apr 18, 2024 15:43:16.772136927 CEST53600121.1.1.1192.168.2.4
                    Apr 18, 2024 15:43:16.799074888 CEST53642081.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 18, 2024 15:42:18.921078920 CEST192.168.2.41.1.1.10x1cf1Standard query (0)www.qxeuwqccdzaaaqie6.infoA (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:18.921533108 CEST192.168.2.41.1.1.10xe28Standard query (0)www.qxeuwqccdzaaaqie6.info65IN (0x0001)false
                    Apr 18, 2024 15:42:19.549940109 CEST192.168.2.41.1.1.10x59b5Standard query (0)documentatie.infoA (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:19.550093889 CEST192.168.2.41.1.1.10x2cfaStandard query (0)documentatie.info65IN (0x0001)false
                    Apr 18, 2024 15:42:20.632020950 CEST192.168.2.41.1.1.10x857dStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:20.632805109 CEST192.168.2.41.1.1.10x2736Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                    Apr 18, 2024 15:42:21.388336897 CEST192.168.2.41.1.1.10xb966Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.388736963 CEST192.168.2.41.1.1.10x341fStandard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 18, 2024 15:42:19.055336952 CEST1.1.1.1192.168.2.40x1cf1No error (0)www.qxeuwqccdzaaaqie6.info104.21.40.211A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:19.055336952 CEST1.1.1.1192.168.2.40x1cf1No error (0)www.qxeuwqccdzaaaqie6.info172.67.188.96A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:19.058598995 CEST1.1.1.1192.168.2.40xe28No error (0)www.qxeuwqccdzaaaqie6.info65IN (0x0001)false
                    Apr 18, 2024 15:42:19.683020115 CEST1.1.1.1192.168.2.40x2cfaNo error (0)documentatie.info65IN (0x0001)false
                    Apr 18, 2024 15:42:19.683357954 CEST1.1.1.1192.168.2.40x59b5No error (0)documentatie.info172.67.185.106A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:19.683357954 CEST1.1.1.1192.168.2.40x59b5No error (0)documentatie.info104.21.76.20A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:20.736737967 CEST1.1.1.1192.168.2.40x857dNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.493350029 CEST1.1.1.1192.168.2.40x341fNo error (0)www.google.com65IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:21.495573997 CEST1.1.1.1192.168.2.40xb966No error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:33.008375883 CEST1.1.1.1192.168.2.40xe62bNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:33.008375883 CEST1.1.1.1192.168.2.40xe62bNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:33.519829035 CEST1.1.1.1192.168.2.40xe42eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 18, 2024 15:42:33.519829035 CEST1.1.1.1192.168.2.40xe42eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:42:46.220320940 CEST1.1.1.1192.168.2.40x50e7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 18, 2024 15:42:46.220320940 CEST1.1.1.1192.168.2.40x50e7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:43:09.220787048 CEST1.1.1.1192.168.2.40xb468No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 18, 2024 15:43:09.220787048 CEST1.1.1.1192.168.2.40xb468No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 18, 2024 15:43:29.504334927 CEST1.1.1.1192.168.2.40x8e6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 18, 2024 15:43:29.504334927 CEST1.1.1.1192.168.2.40x8e6No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • www.qxeuwqccdzaaaqie6.info
                    • documentatie.info
                    • a.nel.cloudflare.com
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449736104.21.40.2114435288C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:19 UTC669OUTGET / HTTP/1.1
                    Host: www.qxeuwqccdzaaaqie6.info
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 13:42:19 UTC677INHTTP/1.1 301 Moved Permanently
                    Date: Thu, 18 Apr 2024 13:42:19 GMT
                    Content-Type: text/html
                    Content-Length: 167
                    Connection: close
                    Cache-Control: max-age=3600
                    Expires: Thu, 18 Apr 2024 14:42:19 GMT
                    Location: https://documentatie.info/v/log.php
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HEzMdEBqTxBIH6gdfk6L7UTSq6NhrpuqVpxe8WMYekQJJQG2sUBlFp7NjGBOEek1McTUBFhBAzW92PqPsLAXS%2BHOfSWXgTgObLy2SgWy9ak8SIP2%2FtVfP2mJZPm4P%2B8SY%2BPVRDBFaLiAmktSNw%3D%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 876513d3be947cc4-ATL
                    alt-svc: h3=":443"; ma=86400
                    2024-04-18 13:42:19 UTC167INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>cloudflare</center></body></html>


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449739172.67.185.1064435288C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:19 UTC669OUTGET /v/log.php HTTP/1.1
                    Host: documentatie.info
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 13:42:20 UTC587INHTTP/1.1 404 Not Found
                    Date: Thu, 18 Apr 2024 13:42:20 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: close
                    CF-Cache-Status: DYNAMIC
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 876513d79b3fb0c1-ATL
                    alt-svc: h3=":443"; ma=86400
                    2024-04-18 13:42:20 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44974035.190.80.14435288C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:21 UTC544OUTOPTIONS /report/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3D HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Origin: https://documentatie.info
                    Access-Control-Request-Method: POST
                    Access-Control-Request-Headers: content-type
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 13:42:21 UTC336INHTTP/1.1 200 OK
                    Content-Length: 0
                    access-control-max-age: 86400
                    access-control-allow-methods: OPTIONS, POST
                    access-control-allow-origin: *
                    access-control-allow-headers: content-length, content-type
                    date: Thu, 18 Apr 2024 13:42:21 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.44974235.190.80.14435288C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:21 UTC484OUTPOST /report/v4?s=edk317n9ghiR%2FqvqcVVg6Ujjzko4tDgGC9wzq%2BO2knP4RUePcIwoJWx2mniXF98txZKUjsshKbPGcv56d0oCKo8lntSAyLfkqo6uwwBCaeWiVall6%2BmprwVSJ6AWTAXuE5SkSw%3D%3D HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Content-Length: 398
                    Content-Type: application/reports+json
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 13:42:21 UTC398OUTData Raw: 5b 7b 22 61 67 65 22 3a 32 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 30 37 36 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 38 35 2e 31 30 36 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 64 6f 63 75 6d 65 6e 74 61 74 69 65 2e 69
                    Data Ascii: [{"age":2,"body":{"elapsed_time":1076,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"172.67.185.106","status_code":404,"type":"http.error"},"type":"network-error","url":"https://documentatie.i
                    2024-04-18 13:42:21 UTC168INHTTP/1.1 200 OK
                    Content-Length: 0
                    date: Thu, 18 Apr 2024 13:42:21 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.449743184.31.62.93443
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:22 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-18 13:42:22 UTC467INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/079C)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus-z1
                    Cache-Control: public, max-age=235259
                    Date: Thu, 18 Apr 2024 13:42:22 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.449744184.31.62.93443
                    TimestampBytes transferredDirectionData
                    2024-04-18 13:42:22 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-18 13:42:22 UTC805INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/0778)
                    X-CID: 11
                    X-CCC: US
                    X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
                    X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
                    Content-Type: application/octet-stream
                    X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                    Cache-Control: public, max-age=235280
                    Date: Thu, 18 Apr 2024 13:42:22 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-04-18 13:42:22 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:15:42:12
                    Start date:18/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:15:42:15
                    Start date:18/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1056 --field-trial-handle=2008,i,12713511431468982074,11000798207561646413,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:15:42:18
                    Start date:18/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.qxeuwqccdzaaaqie6.info"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly