Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.orlidkz.top/

Overview

General Information

Sample URL:https://www.orlidkz.top/
Analysis ID:1428464
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1344 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2448,i,7999651277010272558,14678150477694211793,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.orlidkz.top/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.orlidkz.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.orlidkz.topConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.orlidkz.top/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.orlidkz.topConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: www.orlidkz.top
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2448,i,7999651277010272558,14678150477694211793,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.orlidkz.top/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2448,i,7999651277010272558,14678150477694211793,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.orlidkz.top
204.152.213.33
truefalse
    unknown
    www.google.com
    64.233.177.104
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://www.orlidkz.top/false
          unknown
          https://www.orlidkz.top/favicon.icofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            204.152.213.33
            www.orlidkz.topUnited States
            8100ASN-QUADRANET-GLOBALUSfalse
            64.233.177.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1428464
            Start date and time:2024-04-19 00:41:36 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 17s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://www.orlidkz.top/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/5@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 74.125.136.94, 142.250.9.100, 142.250.9.113, 142.250.9.102, 142.250.9.101, 142.250.9.139, 142.250.9.138, 64.233.177.84, 34.104.35.123, 20.114.59.183, 72.21.81.240, 192.229.211.108, 13.85.23.206, 13.95.31.18, 74.125.138.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://www.orlidkz.top/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2, orientation=upper-left], baseline, precision 8, 647x431, components 3
            Category:dropped
            Size (bytes):149935
            Entropy (8bit):7.762437484739168
            Encrypted:false
            SSDEEP:3072:0pLbjIgsmLXgtTFfRK4XDLjDLFPFKxo10M7agc/7RQks5vtJ2KroNoKVfzJs:QIkgtRws7DX10MGgc9/i32eioKVfG
            MD5:23F64C2C60FB33AA1DB779286F472095
            SHA1:846B8868A4EEA83BA2AE408C0B4C1E71F4C92BFA
            SHA-256:C7E0C0CE2E565A677722F1E0B839ABA8A7F2848A04F613859CF3992D186F2BE0
            SHA-512:ACAAC0210BE8ADEFCC7B5209B43226525F0634BE1411190D544EA3EC28C62C95E06A34DD67B07C4D9B933F1C0A70319F6C963ED8A68A71B6B9272C751C202BDA
            Malicious:false
            Reputation:low
            Preview:......JFIF.....H.H.....XExif..MM.*...................i.........&.................................................8Photoshop 3.0.8BIM........8BIM.%..................B~........................................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................................................................C....................................................................C......................................................................Q............?....[[.E.|.........7...v.......v..O..Zb.._.k~}......A..=.4......P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@..~.......#......z|[...)...k.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2, orientation=upper-left], baseline, precision 8, 647x431, components 3
            Category:downloaded
            Size (bytes):149935
            Entropy (8bit):7.762437484739168
            Encrypted:false
            SSDEEP:3072:0pLbjIgsmLXgtTFfRK4XDLjDLFPFKxo10M7agc/7RQks5vtJ2KroNoKVfzJs:QIkgtRws7DX10MGgc9/i32eioKVfG
            MD5:23F64C2C60FB33AA1DB779286F472095
            SHA1:846B8868A4EEA83BA2AE408C0B4C1E71F4C92BFA
            SHA-256:C7E0C0CE2E565A677722F1E0B839ABA8A7F2848A04F613859CF3992D186F2BE0
            SHA-512:ACAAC0210BE8ADEFCC7B5209B43226525F0634BE1411190D544EA3EC28C62C95E06A34DD67B07C4D9B933F1C0A70319F6C963ED8A68A71B6B9272C751C202BDA
            Malicious:false
            Reputation:low
            URL:https://www.orlidkz.top/favicon.ico
            Preview:......JFIF.....H.H.....XExif..MM.*...................i.........&.................................................8Photoshop 3.0.8BIM........8BIM.%..................B~........................................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................................................................C....................................................................C......................................................................Q............?....[[.E.|.........7...v.......v..O..Zb.._.k~}......A..=.4......P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@....P.@..~.......#......z|[...)...k.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:very short file (no magic)
            Category:downloaded
            Size (bytes):1
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3:v:v
            MD5:68B329DA9893E34099C7D8AD5CB9C940
            SHA1:ADC83B19E793491B1C6EA0FD8B46CD9F32E592FC
            SHA-256:01BA4719C80B6FE911B091A7C05124B64EEECE964E09C058EF8F9805DACA546B
            SHA-512:BE688838CA8686E5C90689BF2AB585CEF1137C999B48C70B92F67A5C34DC15697B5D11C982ED6D71BE1E1E7F7B4E0733884AA97C3F7A339A8ED03577CF74BE09
            Malicious:false
            Reputation:low
            URL:https://www.orlidkz.top/
            Preview:.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 00:42:19.365700006 CEST49678443192.168.2.4104.46.162.224
            Apr 19, 2024 00:42:20.412427902 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 00:42:27.547483921 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.547583103 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.547688007 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.547998905 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.548029900 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.548083067 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.548270941 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.548310995 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.548398018 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.548413038 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.865154982 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.865452051 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.865477085 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.866303921 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.866472006 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.866502047 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.866506100 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.866574049 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.867408991 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.867476940 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.868185997 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.868257046 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.868544102 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.868614912 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.868679047 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.868686914 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.915652037 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.915657043 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:27.915689945 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:27.959484100 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.177462101 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.177701950 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.177898884 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.180098057 CEST49736443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.180119991 CEST44349736204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.225492954 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.272123098 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534775972 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534837961 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534857988 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534874916 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534913063 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534930944 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.534985065 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.534986019 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.534986019 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.535068989 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535106897 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535125017 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535176039 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.535176039 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.535176039 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.535186052 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535226107 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535247087 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.535250902 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.535283089 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.577191114 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688297033 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688322067 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688380003 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688453913 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688523054 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688554049 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688559055 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688577890 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688591003 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688618898 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688627005 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688637018 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688651085 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688679934 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688680887 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688697100 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688699961 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688710928 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.688743114 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.688766003 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842241049 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842264891 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842330933 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842356920 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842397928 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842422962 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842444897 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842462063 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842480898 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842519999 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842618942 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842638969 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842673063 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842684031 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842699051 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842699051 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842734098 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.842744112 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842798948 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:28.842833042 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.852256060 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.926486015 CEST49735443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:28.926563025 CEST44349735204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.089901924 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.089940071 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.089993954 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.091285944 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.091299057 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.406291962 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.406928062 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.406953096 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.407891035 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.407951117 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.408682108 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.408725977 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.408993006 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.408998013 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.458395004 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.873059988 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873081923 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873090029 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873101950 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873127937 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873140097 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.873153925 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873166084 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873176098 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.873184919 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873198986 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873209953 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.873214006 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:29.873219967 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.873248100 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:29.926878929 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.020843983 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 00:42:30.026798964 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.026818991 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.026875019 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.026941061 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.026962042 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027025938 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.027168989 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027183056 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027229071 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.027241945 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027291059 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.027621031 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027632952 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027689934 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.027700901 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.027748108 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181333065 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181355000 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181430101 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181453943 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181492090 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181624889 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181638002 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181668043 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181672096 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181695938 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181708097 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181783915 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181797981 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181839943 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181843996 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181894064 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181946039 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181961060 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181992054 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.181997061 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.181999922 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.182037115 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.182053089 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.182055950 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.182065010 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.182102919 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.206712961 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.206763983 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.206836939 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.208209991 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.208236933 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.218651056 CEST49739443192.168.2.4204.152.213.33
            Apr 19, 2024 00:42:30.218708992 CEST44349739204.152.213.33192.168.2.4
            Apr 19, 2024 00:42:30.437331915 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.441415071 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.441472054 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.442459106 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.442583084 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.449399948 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.449480057 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.489484072 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.489509106 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:30.532958031 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.533001900 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.533252001 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.535635948 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.535665989 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.536393881 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:30.759396076 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.759598017 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.765383005 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.765399933 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.765666008 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.817601919 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.837404013 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.884119987 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.958918095 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.958997011 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.959134102 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.965801954 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.965801954 CEST49741443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:30.965823889 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:30.965841055 CEST4434974123.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.010988951 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.011061907 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.011607885 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.011607885 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.011653900 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.224612951 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.224860907 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.225811005 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.225831032 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.226038933 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.227441072 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.272123098 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.432459116 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.432518959 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.432578087 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.433427095 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.433454037 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:31.433468103 CEST49742443192.168.2.423.220.189.216
            Apr 19, 2024 00:42:31.433475971 CEST4434974223.220.189.216192.168.2.4
            Apr 19, 2024 00:42:40.457695961 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:40.457843065 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:42:40.458004951 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:41.891295910 CEST49740443192.168.2.464.233.177.104
            Apr 19, 2024 00:42:41.891362906 CEST4434974064.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.135705948 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:30.135757923 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.136174917 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:30.137015104 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:30.137044907 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.356699944 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.357172012 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:30.357188940 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.358284950 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.358866930 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:30.359044075 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:30.411364079 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:40.355300903 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:40.355443001 CEST4434975164.233.177.104192.168.2.4
            Apr 19, 2024 00:43:40.360311985 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:41.772576094 CEST49751443192.168.2.464.233.177.104
            Apr 19, 2024 00:43:41.772598982 CEST4434975164.233.177.104192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 00:42:25.770481110 CEST53631021.1.1.1192.168.2.4
            Apr 19, 2024 00:42:25.788161039 CEST53620791.1.1.1192.168.2.4
            Apr 19, 2024 00:42:26.388987064 CEST53557261.1.1.1192.168.2.4
            Apr 19, 2024 00:42:26.717888117 CEST5603753192.168.2.41.1.1.1
            Apr 19, 2024 00:42:26.718415976 CEST6514553192.168.2.41.1.1.1
            Apr 19, 2024 00:42:27.356741905 CEST53651451.1.1.1192.168.2.4
            Apr 19, 2024 00:42:27.546613932 CEST53560371.1.1.1192.168.2.4
            Apr 19, 2024 00:42:28.957556009 CEST5196553192.168.2.41.1.1.1
            Apr 19, 2024 00:42:28.957737923 CEST5634353192.168.2.41.1.1.1
            Apr 19, 2024 00:42:29.062819004 CEST53519651.1.1.1192.168.2.4
            Apr 19, 2024 00:42:29.823240042 CEST53563431.1.1.1192.168.2.4
            Apr 19, 2024 00:42:30.093590975 CEST4967153192.168.2.41.1.1.1
            Apr 19, 2024 00:42:30.093770027 CEST5607753192.168.2.41.1.1.1
            Apr 19, 2024 00:42:30.198008060 CEST53560771.1.1.1192.168.2.4
            Apr 19, 2024 00:42:30.198298931 CEST53496711.1.1.1192.168.2.4
            Apr 19, 2024 00:42:44.880994081 CEST53577211.1.1.1192.168.2.4
            Apr 19, 2024 00:42:49.887855053 CEST138138192.168.2.4192.168.2.255
            Apr 19, 2024 00:43:04.011702061 CEST53550501.1.1.1192.168.2.4
            Apr 19, 2024 00:43:25.176223040 CEST53601621.1.1.1192.168.2.4
            Apr 19, 2024 00:43:26.565486908 CEST53610881.1.1.1192.168.2.4
            Apr 19, 2024 00:43:53.424175978 CEST53530061.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Apr 19, 2024 00:42:29.823311090 CEST192.168.2.41.1.1.1c225(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 19, 2024 00:42:26.717888117 CEST192.168.2.41.1.1.10x48efStandard query (0)www.orlidkz.topA (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:26.718415976 CEST192.168.2.41.1.1.10x7e3cStandard query (0)www.orlidkz.top65IN (0x0001)false
            Apr 19, 2024 00:42:28.957556009 CEST192.168.2.41.1.1.10xc2fbStandard query (0)www.orlidkz.topA (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:28.957737923 CEST192.168.2.41.1.1.10x62e9Standard query (0)www.orlidkz.top65IN (0x0001)false
            Apr 19, 2024 00:42:30.093590975 CEST192.168.2.41.1.1.10x2d72Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.093770027 CEST192.168.2.41.1.1.10xf117Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 19, 2024 00:42:27.546613932 CEST1.1.1.1192.168.2.40x48efNo error (0)www.orlidkz.top204.152.213.33A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:29.062819004 CEST1.1.1.1192.168.2.40xc2fbNo error (0)www.orlidkz.top204.152.213.33A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198008060 CEST1.1.1.1192.168.2.40xf117No error (0)www.google.com65IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:30.198298931 CEST1.1.1.1192.168.2.40x2d72No error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:43.186456919 CEST1.1.1.1192.168.2.40x98f5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 00:42:43.186456919 CEST1.1.1.1192.168.2.40x98f5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 00:42:56.020327091 CEST1.1.1.1192.168.2.40x3ffeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 00:42:56.020327091 CEST1.1.1.1192.168.2.40x3ffeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 00:43:19.141748905 CEST1.1.1.1192.168.2.40xe0d2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 00:43:19.141748905 CEST1.1.1.1192.168.2.40xe0d2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 00:43:37.940974951 CEST1.1.1.1192.168.2.40x671eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 00:43:37.940974951 CEST1.1.1.1192.168.2.40x671eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • www.orlidkz.top
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449736204.152.213.33443416C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 22:42:27 UTC658OUTGET / HTTP/1.1
            Host: www.orlidkz.top
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 22:42:28 UTC170INHTTP/1.1 500 Internal Error
            Server: nginx
            Date: Thu, 18 Apr 2024 22:42:28 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            2024-04-18 22:42:28 UTC11INData Raw: 31 0d 0a 0a 0d 0a 30 0d 0a 0d 0a
            Data Ascii: 10


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735204.152.213.33443416C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 22:42:28 UTC586OUTGET /favicon.ico HTTP/1.1
            Host: www.orlidkz.top
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://www.orlidkz.top/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 22:42:28 UTC279INHTTP/1.1 200 OK
            Server: nginx
            Date: Thu, 18 Apr 2024 22:42:28 GMT
            Content-Type: image/x-icon
            Content-Length: 149935
            Last-Modified: Mon, 09 Oct 2023 17:18:51 GMT
            Connection: close
            ETag: "652435fb-249af"
            Strict-Transport-Security: max-age=31536000
            Accept-Ranges: bytes
            2024-04-18 22:42:28 UTC16105INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 48 00 48 00 00 ff e1 00 58 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 02 01 12 00 03 00 00 00 01 00 01 00 00 87 69 00 04 00 00 00 01 00 00 00 26 00 00 00 00 00 03 a0 01 00 03 00 00 00 01 00 01 00 00 a0 02 00 04 00 00 00 01 00 00 02 87 a0 03 00 04 00 00 00 01 00 00 01 af 00 00 00 00 ff ed 00 38 50 68 6f 74 6f 73 68 6f 70 20 33 2e 30 00 38 42 49 4d 04 04 00 00 00 00 00 00 38 42 49 4d 04 25 00 00 00 00 00 10 d4 1d 8c d9 8f 00 b2 04 e9 80 09 98 ec f8 42 7e ff c0 00 11 08 01 af 02 87 03 01 11 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51
            Data Ascii: JFIFHHXExifMM*i&8Photoshop 3.08BIM8BIM%B~}!1AQ
            2024-04-18 22:42:28 UTC16384INData Raw: 00 96 0b ff 00 0f 06 fd b7 3f e8 eb be 3f 7f e1 cd f1 2f ff 00 25 d6 bf f1 00 fc 26 ff 00 a2 27 25 ff 00 c2 2c 27 ff 00 28 17 fc 46 5f 10 ff 00 e8 a2 c7 7f e0 fa ff 00 fc b1 fe 7f 78 7f c3 c1 bf 6d df fa 3a ef 8f bf f8 73 bc 4d 9f fd 2b c6 6b 1f f8 80 9e 13 df fe 48 ac 9a d7 df ea 78 4d bd 3d 8d fe 57 f9 f5 2b fe 23 3f 88 7f f4 50 e3 bf f0 75 6f fe 58 1f f0 f0 5f db 70 f1 ff 00 0d 5d f1 fb 9e 3f e4 a6 f8 97 ff 00 92 eb 67 e0 1f 84 ff 00 f4 44 e4 bf 2c 16 13 ff 00 94 2f cf ee 27 fe 23 37 88 7d 78 8b 1d 6e b7 af 5f 6f 9d 4b 7d e7 e8 37 fc 12 c7 f6 c4 fd aa be 26 fe df 1f 01 3c 15 f1 0b f6 89 f8 c1 e3 6f 06 eb ba 87 8e a2 d5 fc 33 e2 8f 1b eb 1a b6 87 ab 47 67 f0 cf c7 17 da 79 be d2 2e 67 92 dc fd 96 eb 4f b1 bd 88 2b 6e 17 90 09 b2 0a 84 af c2 fc 7f f0 93
            Data Ascii: ??/%&'%,'(F_xm:sM+kHxM=W+#?PuoX_p]?gD,/'#7}xn_oK}7&<o3Ggy.gO+n
            2024-04-18 22:42:28 UTC16384INData Raw: 2a 33 f0 cb 8c fb 3c 9f 19 ef 25 67 67 83 aa 9d b6 6a e9 bf 5d f5 b5 8f ae e0 48 7b 4e 2c ca a8 df 49 e2 69 42 d6 ba 7c f5 39 6f 6d f4 b7 9d ef d2 de f7 b4 7f c1 4c ff 00 67 d6 fd 9b 7f 6d 2f 8c 9e 07 b5 b5 16 de 19 f1 16 b4 ff 00 14 bc 10 89 1f 95 00 f0 bf c4 59 a7 d6 cd ad ba ae ec 41 a3 78 84 f8 83 c3 e9 90 49 1a 4e 7e 5c ed 5f 97 fa 3e f1 8a e3 6f 0c 72 ac c3 1b 8a 78 9c ca 92 a9 82 cc 25 29 c5 d6 fa c6 0e aa a3 3a 95 69 c5 de 2e ab a6 ab 41 3b 73 52 a9 1a 8a ca 71 47 da 78 d9 c2 6b 83 38 d7 15 42 10 e4 c1 57 86 1e ae 17 75 17 0a b4 54 fa 26 94 97 32 4f 95 fc 5e eb b3 4f 97 e0 be 71 d7 9c 75 f7 f5 ef fc bf 3a fd c3 45 d3 45 d3 c9 74 fb 8f c7 6f a5 fa 6f 73 fa 6b ff 00 83 75 bf 68 28 f4 fd 7b e3 57 ec c9 ac 5e 14 1a f4 76 7f 18 bc 13 6d 24 c4 42 b7 d6
            Data Ascii: *3<%ggj]H{N,IiB|9omLgm/YAxIN~\_>orx%):i.A;sRqGxk8BWuT&2O^Oqu:EEtooskuh({W^vm$B
            2024-04-18 22:42:28 UTC16384INData Raw: ed fc 65 69 12 a0 cc 2d 17 8c b4 fd 6a ff 00 ec bb 98 47 6f aa 5a c8 bb 56 60 89 fe bc fd 15 38 ee 1c 4d e1 96 13 05 88 a8 ea 62 f8 7d bc 06 36 33 a9 3a 95 14 21 25 1c 23 9b 9c 62 e6 e7 87 54 6a 4a 51 e6 8a 94 9c 54 9b 52 3f ca 5f a4 97 08 be 18 e3 ec 55 58 c2 d8 3c c2 4a b6 1d 2a 6a 9d 3b ca 0a 75 a3 1b 73 24 a3 39 4e 09 ad 6d 1d 52 bf 29 f9 5c 18 f4 c6 4f 3d ff 00 fb 1f fd 9b fc 2b fa 79 c6 36 e6 bd a3 64 f6 e9 f7 a7 ff 00 92 fd db 9f cf 2f 67 db fa ed af dc 6c 7f c2 41 ae 1d 06 df c3 2d aa dd b6 81 67 ab 5c eb f6 da 3b 32 9d 36 0d 6e fe c2 c7 4c bf d5 23 b7 c6 e1 75 77 a7 e9 9a 75 bc 8e 25 3b 7e c7 03 47 f7 5c 37 9f fd 97 80 8d 59 66 11 a5 4f db e2 54 63 2c 57 24 7d b3 8d 1e 6e 48 ca 56 e6 71 8b 9c d4 57 34 ad cf 2d 9b bc b6 96 61 5f ea 5f 51 f6 b5 5e
            Data Ascii: ei-jGoZV`8Mb}63:!%#bTjJQTR?_UX<J*j;us$9NmR)\O=+y6d/glA-g\;26nL#uwu%;~G\7YfOTc,W$}nHVqW4-a__Q^
            2024-04-18 22:42:28 UTC16384INData Raw: f8 7c 48 d6 bf f9 85 af e8 65 f4 c6 f0 e2 ff 00 ef 18 b7 ae b6 c0 63 2f f9 3d 7e 5e b6 3f 07 7f 44 bf 13 6d 7f a9 ad af 7f 6f 45 2d 7a fc 6d 5b e5 f7 1e bf fb 3d 7f c1 10 ff 00 6d 8f 86 ff 00 1e be 09 fc 48 f1 1b fc 1e ff 00 84 7b c0 1f 16 7e 1d 78 d3 5c fe cf f1 de a5 75 75 2e 93 e1 7f 17 e8 fa e6 a2 ba 74 4d e1 38 85 cd cb da 69 f3 0b 68 e4 92 d9 65 93 6a 96 40 00 6f 97 e3 ef a5 57 87 3c 43 c1 f9 f6 49 80 c4 e2 d6 2f 35 cb 31 78 48 c6 78 2c 4c 7d fa f4 2a 52 8d b9 e3 08 29 7b eb e2 9a 57 6a f2 51 f7 8f 7f 82 fe 8c 3e 20 65 1c 45 97 66 18 ea 10 f6 78 2c 55 3a b3 b5 6a 2d 72 c6 a4 64 da 70 ab 39 35 6b d9 fb cb 4d 2f 6b 1f d8 d0 18 89 14 f5 55 41 f8 80 01 f4 fe 5f 95 7f 9a 92 7e f3 6b f9 9b 5f 7f f5 ea 7f a5 34 e0 e1 87 a5 07 bc 29 d3 8b f5 8c 62 9f 7e dd
            Data Ascii: |Hec/=~^?DmoE-zm[=mH{~x\uu.tM8ihej@oW<CI/51xHx,L}*R){WjQ> eEfx,U:j-rdp95kM/kUA_~k_4)b~
            2024-04-18 22:42:28 UTC16384INData Raw: 4d b7 d9 5d bf c3 fa fc 47 d5 73 c7 f9 e3 f7 c4 e8 f6 75 3f 92 7f f8 04 82 8e 78 ff 00 3c 7e f8 87 b3 a9 fc 93 ff 00 c0 24 14 73 c7 f9 e3 f7 c4 3d 9d 4f e4 9f fe 01 20 a3 9e 3f cf 1f be 21 ec ea 7f 24 ff 00 f0 09 05 1c f1 fe 78 fd f1 0f 67 53 f9 27 ff 00 80 48 2b a3 9e 1f cf 1b 7f 8a 26 1e ca af fc fa a9 ff 00 80 4b ff 00 95 85 73 f3 c7 f9 e3 f7 c4 df d9 d4 fe 49 ff 00 e0 12 0a 39 e3 fc f1 fb e2 1e ce a7 f2 4f ff 00 00 90 51 cf 1f e7 8f df 10 f6 75 3f 92 7f f8 04 82 8e 78 ff 00 3c 7e f8 87 b3 a9 fc 93 ff 00 c0 24 14 73 c7 f9 e3 f7 c4 3d 9d 4f e4 9f fe 01 20 a3 9e 3f cf 1f be 21 ec ea 7f 24 ff 00 f0 09 05 1c f1 fe 78 fd f1 0f 67 53 f9 27 ff 00 80 48 28 e7 8f f3 c7 ef 88 7b 3a 9f c9 3f fc 02 41 47 3c 7f 9e 3f 7c 43 d9 d4 fe 49 ff 00 e0 12 0a 39 e3 fc f1 fb
            Data Ascii: M]Gsu?x<~$s=O ?!$xgS'H+&KsI9OQu?x<~$s=O ?!$xgS'H({:?AG<?|CI9
            2024-04-18 22:42:28 UTC16384INData Raw: 95 4f 9a eb 97 96 dc d7 de db 6b bf 95 fa 9f c8 07 fc 16 d3 fe 0a 3e ff 00 14 7c 47 7d fb 20 fc 16 d7 f7 fc 37 f0 66 b2 b0 7c 66 f1 15 84 bb 6d 3c 73 e3 1d 3e e0 4f 07 82 ad ae 76 e6 eb c3 5e 0d ba 89 2e 35 9d 88 96 da d7 88 92 cc 24 8f 61 a3 ba ea 1f e9 37 d1 53 c0 a8 e5 b8 68 78 81 c5 59 7c bf b4 b1 0a f9 2e 0f 12 9a 78 2a 2e 3c b2 af 2a 52 8c 92 af 88 8b bd a7 fb ca 74 5c 69 fe ee 72 c4 42 5f e7 cf d2 63 c6 69 66 d8 a9 f0 7e 43 8d e5 cb f0 ce 71 cc 71 14 5f fb e4 ad ee c2 f1 7c c9 52 7a 25 17 69 3e 67 76 9c 5c 7f 9e 1c 63 8f 4f f3 ef fc ff 00 3a fe ee 49 24 a2 92 49 2b 24 b6 b7 63 f8 6e 4d ca 4d b6 e4 db 6e ef 5b eb be ba eb be bf a1 24 51 49 33 c5 0c 51 4f 34 f3 cf 0d bd bd bc 16 f3 cb 75 73 71 33 f9 30 db 5a da f9 42 6b 8b ab ab a2 b6 3a 7d b2 a0 7b
            Data Ascii: Ok>|G} 7f|fm<s>Ov^.5$a7ShxY|.x*.<*Rt\irB_cif~Cqq_|Rz%i>gv\cO:I$I+$cnMMn[$QI3QO4usq30ZBk:}{
            2024-04-18 22:42:28 UTC16384INData Raw: ba 9f cd 2d 4a ee 3d 55 e3 d1 3f 4b 6e bb 5b 4e f6 56 b0 50 a2 95 92 4b 42 d2 4b a7 eb f8 ff 00 5d ba 05 74 5a 3e 5f 72 ff 00 86 32 bc bf bd f7 bf f8 70 ac 0d 82 80 13 a0 e0 7a e3 fc f1 df df f2 a4 e3 19 2e 59 24 e0 de a9 ab af b9 df cf a7 de 63 0a 73 5c b2 e7 94 5a 69 f2 a6 fa 3b ee a4 97 9e cf 7d b7 3f 5e 3f e0 94 df f0 51 cf 18 fe c8 7f 14 74 0f 86 3e 34 d7 2e b5 4f d9 bb c7 ba d5 8e 93 af e8 fa 95 cf 9b 69 f0 d7 5a d5 6f a2 b1 83 c7 7e 1d 37 12 31 d2 ed 05 dc f8 f1 56 95 67 9b 3d 66 d3 3a 8f d8 c6 ba aa 5b f9 43 e9 27 e0 3e 5b c6 b9 25 4e 22 c8 30 50 a5 c5 59 6d 1a 95 25 52 87 25 35 8e a5 1b cb ea f5 63 ee 53 e5 51 e6 74 a5 2d 69 54 7c e9 c6 15 2a 42 7f d4 be 04 f8 cf 98 70 8e 75 87 c8 f3 0a d3 ab 90 e6 55 29 d3 5e d6 6e 6a 9d 45 a7 35 3e 69 73 2f 79
            Data Ascii: -J=U?Kn[NVPKBK]tZ>_r2pz.Y$cs\Zi;}?^?Qt>4.OiZo~71Vg=f:[C'>[%N"0PYm%R%5cSQt-iT|*BpuU)^njE5>is/y
            2024-04-18 22:42:28 UTC16384INData Raw: 7a 5d b8 b4 d3 f4 ad 27 4b b5 86 cb 4f b0 b3 81 32 90 db da db 41 1c 51 46 01 3f 29 24 b3 16 af f1 db 32 cc 71 f9 e6 3f 1b 98 e6 15 6a 55 c6 63 2b d4 af 89 c5 55 92 73 9c e7 39 54 6d a4 e3 15 7e 6b 28 c2 31 8c 23 68 28 b8 45 72 ff 00 ab f9 46 57 82 c9 f2 dc 0e 5f 80 84 28 e1 f0 74 a3 4e 95 0a 71 71 6f 96 11 8c ad 2d 1b d6 37 6d bb b6 db 69 dc e9 c5 cc 7b da 15 60 d2 08 e3 91 97 2b f2 a4 9b f6 74 27 ef 6c 6e 79 03 6f f1 74 ae 7f 67 3e 44 f9 65 cb 2b a5 3e 57 ca da 4a f6 7a 26 d5 d5 f5 d2 eb 6b dc f6 15 5a 4e 6e 9f b4 87 b4 5b d3 e7 8f 3a f5 8a 6d af d7 ce ce 47 91 7c 70 f8 2d f0 ff 00 f6 88 f8 59 e3 3f 83 bf 14 34 68 b5 df 06 78 df 49 9f 4a d5 ad 58 22 5c 5b 97 1b ac f5 2d 36 e5 a3 90 d9 6a da 4d e2 c1 a8 e9 77 b1 ab 3d a5 fd ad b5 c2 06 f2 f6 37 b7 c2 7c
            Data Ascii: z]'KO2AQF?)$2q?jUc+Us9Tm~k(1#h(ErFW_(tNqqo-7mi{`+t'lnyotg>De+>WJz&kZNn[:mG|p-Y?4hxIJX"\[-6jMw=7|
            2024-04-18 22:42:28 UTC2758INData Raw: 03 36 ff 00 f3 ee bf 94 1f fc 89 47 d4 b0 9f f4 0b 86 ff 00 c2 7a 21 f5 cc 6f fd 06 62 3f f0 6d 6f fe 58 19 b7 ff 00 9f 75 fc a0 ff 00 e4 4a 3e a5 84 ff 00 a0 5c 37 fe 13 d1 0f ae 63 7f e8 33 11 ff 00 83 6a ff 00 f2 c0 cd bf fc fb af e5 07 ff 00 22 51 f5 2c 27 fd 02 e1 bf f0 9e 89 3f 59 c5 ff 00 d0 4d 6f fc 19 53 ff 00 96 06 6d ff 00 e7 dd 7f 28 3f f9 12 8f a9 61 3f e8 17 0d ff 00 84 f4 4a fa e6 37 fe 83 31 1f f8 36 af ff 00 2c 2c 79 30 76 89 41 ec 76 41 ff 00 c8 ab fc c5 1f 52 c2 7f d0 2e 1b ff 00 09 e8 87 d7 31 bf f4 19 88 ff 00 c1 b5 bf f9 37 f9 7d e3 3c 84 e7 0a 80 67 a6 c3 fd 25 51 f9 2a fd 3f ba 7d 4b 09 ff 00 40 b8 6f fc 27 a2 1f 5b c5 bf f9 8a c4 7f e0 fa 9f ac d7 e5 f7 83 42 5b 19 61 c7 40 17 00 7d 39 3e bd 7f 0e 71 ba b4 8d 0a 30 f8 28 d2 8f f8
            Data Ascii: 6Gz!ob?moXuJ>\7c3j"Q,'?YMoSm(?a?J716,,y0vAvAR.17}<g%Q*?}K@o'[B[a@}9>q0(


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449739204.152.213.33443416C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 22:42:29 UTC350OUTGET /favicon.ico HTTP/1.1
            Host: www.orlidkz.top
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 22:42:29 UTC279INHTTP/1.1 200 OK
            Server: nginx
            Date: Thu, 18 Apr 2024 22:42:29 GMT
            Content-Type: image/x-icon
            Content-Length: 149935
            Last-Modified: Mon, 09 Oct 2023 17:18:51 GMT
            Connection: close
            ETag: "652435fb-249af"
            Strict-Transport-Security: max-age=31536000
            Accept-Ranges: bytes
            2024-04-18 22:42:29 UTC16105INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 48 00 48 00 00 ff e1 00 58 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 02 01 12 00 03 00 00 00 01 00 01 00 00 87 69 00 04 00 00 00 01 00 00 00 26 00 00 00 00 00 03 a0 01 00 03 00 00 00 01 00 01 00 00 a0 02 00 04 00 00 00 01 00 00 02 87 a0 03 00 04 00 00 00 01 00 00 01 af 00 00 00 00 ff ed 00 38 50 68 6f 74 6f 73 68 6f 70 20 33 2e 30 00 38 42 49 4d 04 04 00 00 00 00 00 00 38 42 49 4d 04 25 00 00 00 00 00 10 d4 1d 8c d9 8f 00 b2 04 e9 80 09 98 ec f8 42 7e ff c0 00 11 08 01 af 02 87 03 01 11 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51
            Data Ascii: JFIFHHXExifMM*i&8Photoshop 3.08BIM8BIM%B~}!1AQ
            2024-04-18 22:42:29 UTC16384INData Raw: 00 96 0b ff 00 0f 06 fd b7 3f e8 eb be 3f 7f e1 cd f1 2f ff 00 25 d6 bf f1 00 fc 26 ff 00 a2 27 25 ff 00 c2 2c 27 ff 00 28 17 fc 46 5f 10 ff 00 e8 a2 c7 7f e0 fa ff 00 fc b1 fe 7f 78 7f c3 c1 bf 6d df fa 3a ef 8f bf f8 73 bc 4d 9f fd 2b c6 6b 1f f8 80 9e 13 df fe 48 ac 9a d7 df ea 78 4d bd 3d 8d fe 57 f9 f5 2b fe 23 3f 88 7f f4 50 e3 bf f0 75 6f fe 58 1f f0 f0 5f db 70 f1 ff 00 0d 5d f1 fb 9e 3f e4 a6 f8 97 ff 00 92 eb 67 e0 1f 84 ff 00 f4 44 e4 bf 2c 16 13 ff 00 94 2f cf ee 27 fe 23 37 88 7d 78 8b 1d 6e b7 af 5f 6f 9d 4b 7d e7 e8 37 fc 12 c7 f6 c4 fd aa be 26 fe df 1f 01 3c 15 f1 0b f6 89 f8 c1 e3 6f 06 eb ba 87 8e a2 d5 fc 33 e2 8f 1b eb 1a b6 87 ab 47 67 f0 cf c7 17 da 79 be d2 2e 67 92 dc fd 96 eb 4f b1 bd 88 2b 6e 17 90 09 b2 0a 84 af c2 fc 7f f0 93
            Data Ascii: ??/%&'%,'(F_xm:sM+kHxM=W+#?PuoX_p]?gD,/'#7}xn_oK}7&<o3Ggy.gO+n
            2024-04-18 22:42:30 UTC16384INData Raw: 2a 33 f0 cb 8c fb 3c 9f 19 ef 25 67 67 83 aa 9d b6 6a e9 bf 5d f5 b5 8f ae e0 48 7b 4e 2c ca a8 df 49 e2 69 42 d6 ba 7c f5 39 6f 6d f4 b7 9d ef d2 de f7 b4 7f c1 4c ff 00 67 d6 fd 9b 7f 6d 2f 8c 9e 07 b5 b5 16 de 19 f1 16 b4 ff 00 14 bc 10 89 1f 95 00 f0 bf c4 59 a7 d6 cd ad ba ae ec 41 a3 78 84 f8 83 c3 e9 90 49 1a 4e 7e 5c ed 5f 97 fa 3e f1 8a e3 6f 0c 72 ac c3 1b 8a 78 9c ca 92 a9 82 cc 25 29 c5 d6 fa c6 0e aa a3 3a 95 69 c5 de 2e ab a6 ab 41 3b 73 52 a9 1a 8a ca 71 47 da 78 d9 c2 6b 83 38 d7 15 42 10 e4 c1 57 86 1e ae 17 75 17 0a b4 54 fa 26 94 97 32 4f 95 fc 5e eb b3 4f 97 e0 be 71 d7 9c 75 f7 f5 ef fc bf 3a fd c3 45 d3 45 d3 c9 74 fb 8f c7 6f a5 fa 6f 73 fa 6b ff 00 83 75 bf 68 28 f4 fd 7b e3 57 ec c9 ac 5e 14 1a f4 76 7f 18 bc 13 6d 24 c4 42 b7 d6
            Data Ascii: *3<%ggj]H{N,IiB|9omLgm/YAxIN~\_>orx%):i.A;sRqGxk8BWuT&2O^Oqu:EEtooskuh({W^vm$B
            2024-04-18 22:42:30 UTC16384INData Raw: ed fc 65 69 12 a0 cc 2d 17 8c b4 fd 6a ff 00 ec bb 98 47 6f aa 5a c8 bb 56 60 89 fe bc fd 15 38 ee 1c 4d e1 96 13 05 88 a8 ea 62 f8 7d bc 06 36 33 a9 3a 95 14 21 25 1c 23 9b 9c 62 e6 e7 87 54 6a 4a 51 e6 8a 94 9c 54 9b 52 3f ca 5f a4 97 08 be 18 e3 ec 55 58 c2 d8 3c c2 4a b6 1d 2a 6a 9d 3b ca 0a 75 a3 1b 73 24 a3 39 4e 09 ad 6d 1d 52 bf 29 f9 5c 18 f4 c6 4f 3d ff 00 fb 1f fd 9b fc 2b fa 79 c6 36 e6 bd a3 64 f6 e9 f7 a7 ff 00 92 fd db 9f cf 2f 67 db fa ed af dc 6c 7f c2 41 ae 1d 06 df c3 2d aa dd b6 81 67 ab 5c eb f6 da 3b 32 9d 36 0d 6e fe c2 c7 4c bf d5 23 b7 c6 e1 75 77 a7 e9 9a 75 bc 8e 25 3b 7e c7 03 47 f7 5c 37 9f fd 97 80 8d 59 66 11 a5 4f db e2 54 63 2c 57 24 7d b3 8d 1e 6e 48 ca 56 e6 71 8b 9c d4 57 34 ad cf 2d 9b bc b6 96 61 5f ea 5f 51 f6 b5 5e
            Data Ascii: ei-jGoZV`8Mb}63:!%#bTjJQTR?_UX<J*j;us$9NmR)\O=+y6d/glA-g\;26nL#uwu%;~G\7YfOTc,W$}nHVqW4-a__Q^
            2024-04-18 22:42:30 UTC16384INData Raw: f8 7c 48 d6 bf f9 85 af e8 65 f4 c6 f0 e2 ff 00 ef 18 b7 ae b6 c0 63 2f f9 3d 7e 5e b6 3f 07 7f 44 bf 13 6d 7f a9 ad af 7f 6f 45 2d 7a fc 6d 5b e5 f7 1e bf fb 3d 7f c1 10 ff 00 6d 8f 86 ff 00 1e be 09 fc 48 f1 1b fc 1e ff 00 84 7b c0 1f 16 7e 1d 78 d3 5c fe cf f1 de a5 75 75 2e 93 e1 7f 17 e8 fa e6 a2 ba 74 4d e1 38 85 cd cb da 69 f3 0b 68 e4 92 d9 65 93 6a 96 40 00 6f 97 e3 ef a5 57 87 3c 43 c1 f9 f6 49 80 c4 e2 d6 2f 35 cb 31 78 48 c6 78 2c 4c 7d fa f4 2a 52 8d b9 e3 08 29 7b eb e2 9a 57 6a f2 51 f7 8f 7f 82 fe 8c 3e 20 65 1c 45 97 66 18 ea 10 f6 78 2c 55 3a b3 b5 6a 2d 72 c6 a4 64 da 70 ab 39 35 6b d9 fb cb 4d 2f 6b 1f d8 d0 18 89 14 f5 55 41 f8 80 01 f4 fe 5f 95 7f 9a 92 7e f3 6b f9 9b 5f 7f f5 ea 7f a5 34 e0 e1 87 a5 07 bc 29 d3 8b f5 8c 62 9f 7e dd
            Data Ascii: |Hec/=~^?DmoE-zm[=mH{~x\uu.tM8ihej@oW<CI/51xHx,L}*R){WjQ> eEfx,U:j-rdp95kM/kUA_~k_4)b~
            2024-04-18 22:42:30 UTC16384INData Raw: 4d b7 d9 5d bf c3 fa fc 47 d5 73 c7 f9 e3 f7 c4 e8 f6 75 3f 92 7f f8 04 82 8e 78 ff 00 3c 7e f8 87 b3 a9 fc 93 ff 00 c0 24 14 73 c7 f9 e3 f7 c4 3d 9d 4f e4 9f fe 01 20 a3 9e 3f cf 1f be 21 ec ea 7f 24 ff 00 f0 09 05 1c f1 fe 78 fd f1 0f 67 53 f9 27 ff 00 80 48 2b a3 9e 1f cf 1b 7f 8a 26 1e ca af fc fa a9 ff 00 80 4b ff 00 95 85 73 f3 c7 f9 e3 f7 c4 df d9 d4 fe 49 ff 00 e0 12 0a 39 e3 fc f1 fb e2 1e ce a7 f2 4f ff 00 00 90 51 cf 1f e7 8f df 10 f6 75 3f 92 7f f8 04 82 8e 78 ff 00 3c 7e f8 87 b3 a9 fc 93 ff 00 c0 24 14 73 c7 f9 e3 f7 c4 3d 9d 4f e4 9f fe 01 20 a3 9e 3f cf 1f be 21 ec ea 7f 24 ff 00 f0 09 05 1c f1 fe 78 fd f1 0f 67 53 f9 27 ff 00 80 48 28 e7 8f f3 c7 ef 88 7b 3a 9f c9 3f fc 02 41 47 3c 7f 9e 3f 7c 43 d9 d4 fe 49 ff 00 e0 12 0a 39 e3 fc f1 fb
            Data Ascii: M]Gsu?x<~$s=O ?!$xgS'H+&KsI9OQu?x<~$s=O ?!$xgS'H({:?AG<?|CI9
            2024-04-18 22:42:30 UTC16384INData Raw: 95 4f 9a eb 97 96 dc d7 de db 6b bf 95 fa 9f c8 07 fc 16 d3 fe 0a 3e ff 00 14 7c 47 7d fb 20 fc 16 d7 f7 fc 37 f0 66 b2 b0 7c 66 f1 15 84 bb 6d 3c 73 e3 1d 3e e0 4f 07 82 ad ae 76 e6 eb c3 5e 0d ba 89 2e 35 9d 88 96 da d7 88 92 cc 24 8f 61 a3 ba ea 1f e9 37 d1 53 c0 a8 e5 b8 68 78 81 c5 59 7c bf b4 b1 0a f9 2e 0f 12 9a 78 2a 2e 3c b2 af 2a 52 8c 92 af 88 8b bd a7 fb ca 74 5c 69 fe ee 72 c4 42 5f e7 cf d2 63 c6 69 66 d8 a9 f0 7e 43 8d e5 cb f0 ce 71 cc 71 14 5f fb e4 ad ee c2 f1 7c c9 52 7a 25 17 69 3e 67 76 9c 5c 7f 9e 1c 63 8f 4f f3 ef fc ff 00 3a fe ee 49 24 a2 92 49 2b 24 b6 b7 63 f8 6e 4d ca 4d b6 e4 db 6e ef 5b eb be ba eb be bf a1 24 51 49 33 c5 0c 51 4f 34 f3 cf 0d bd bd bc 16 f3 cb 75 73 71 33 f9 30 db 5a da f9 42 6b 8b ab ab a2 b6 3a 7d b2 a0 7b
            Data Ascii: Ok>|G} 7f|fm<s>Ov^.5$a7ShxY|.x*.<*Rt\irB_cif~Cqq_|Rz%i>gv\cO:I$I+$cnMMn[$QI3QO4usq30ZBk:}{
            2024-04-18 22:42:30 UTC16384INData Raw: ba 9f cd 2d 4a ee 3d 55 e3 d1 3f 4b 6e bb 5b 4e f6 56 b0 50 a2 95 92 4b 42 d2 4b a7 eb f8 ff 00 5d ba 05 74 5a 3e 5f 72 ff 00 86 32 bc bf bd f7 bf f8 70 ac 0d 82 80 13 a0 e0 7a e3 fc f1 df df f2 a4 e3 19 2e 59 24 e0 de a9 ab af b9 df cf a7 de 63 0a 73 5c b2 e7 94 5a 69 f2 a6 fa 3b ee a4 97 9e cf 7d b7 3f 5e 3f e0 94 df f0 51 cf 18 fe c8 7f 14 74 0f 86 3e 34 d7 2e b5 4f d9 bb c7 ba d5 8e 93 af e8 fa 95 cf 9b 69 f0 d7 5a d5 6f a2 b1 83 c7 7e 1d 37 12 31 d2 ed 05 dc f8 f1 56 95 67 9b 3d 66 d3 3a 8f d8 c6 ba aa 5b f9 43 e9 27 e0 3e 5b c6 b9 25 4e 22 c8 30 50 a5 c5 59 6d 1a 95 25 52 87 25 35 8e a5 1b cb ea f5 63 ee 53 e5 51 e6 74 a5 2d 69 54 7c e9 c6 15 2a 42 7f d4 be 04 f8 cf 98 70 8e 75 87 c8 f3 0a d3 ab 90 e6 55 29 d3 5e d6 6e 6a 9d 45 a7 35 3e 69 73 2f 79
            Data Ascii: -J=U?Kn[NVPKBK]tZ>_r2pz.Y$cs\Zi;}?^?Qt>4.OiZo~71Vg=f:[C'>[%N"0PYm%R%5cSQt-iT|*BpuU)^njE5>is/y
            2024-04-18 22:42:30 UTC16384INData Raw: 7a 5d b8 b4 d3 f4 ad 27 4b b5 86 cb 4f b0 b3 81 32 90 db da db 41 1c 51 46 01 3f 29 24 b3 16 af f1 db 32 cc 71 f9 e6 3f 1b 98 e6 15 6a 55 c6 63 2b d4 af 89 c5 55 92 73 9c e7 39 54 6d a4 e3 15 7e 6b 28 c2 31 8c 23 68 28 b8 45 72 ff 00 ab f9 46 57 82 c9 f2 dc 0e 5f 80 84 28 e1 f0 74 a3 4e 95 0a 71 71 6f 96 11 8c ad 2d 1b d6 37 6d bb b6 db 69 dc e9 c5 cc 7b da 15 60 d2 08 e3 91 97 2b f2 a4 9b f6 74 27 ef 6c 6e 79 03 6f f1 74 ae 7f 67 3e 44 f9 65 cb 2b a5 3e 57 ca da 4a f6 7a 26 d5 d5 f5 d2 eb 6b dc f6 15 5a 4e 6e 9f b4 87 b4 5b d3 e7 8f 3a f5 8a 6d af d7 ce ce 47 91 7c 70 f8 2d f0 ff 00 f6 88 f8 59 e3 3f 83 bf 14 34 68 b5 df 06 78 df 49 9f 4a d5 ad 58 22 5c 5b 97 1b ac f5 2d 36 e5 a3 90 d9 6a da 4d e2 c1 a8 e9 77 b1 ab 3d a5 fd ad b5 c2 06 f2 f6 37 b7 c2 7c
            Data Ascii: z]'KO2AQF?)$2q?jUc+Us9Tm~k(1#h(ErFW_(tNqqo-7mi{`+t'lnyotg>De+>WJz&kZNn[:mG|p-Y?4hxIJX"\[-6jMw=7|
            2024-04-18 22:42:30 UTC2758INData Raw: 03 36 ff 00 f3 ee bf 94 1f fc 89 47 d4 b0 9f f4 0b 86 ff 00 c2 7a 21 f5 cc 6f fd 06 62 3f f0 6d 6f fe 58 19 b7 ff 00 9f 75 fc a0 ff 00 e4 4a 3e a5 84 ff 00 a0 5c 37 fe 13 d1 0f ae 63 7f e8 33 11 ff 00 83 6a ff 00 f2 c0 cd bf fc fb af e5 07 ff 00 22 51 f5 2c 27 fd 02 e1 bf f0 9e 89 3f 59 c5 ff 00 d0 4d 6f fc 19 53 ff 00 96 06 6d ff 00 e7 dd 7f 28 3f f9 12 8f a9 61 3f e8 17 0d ff 00 84 f4 4a fa e6 37 fe 83 31 1f f8 36 af ff 00 2c 2c 79 30 76 89 41 ec 76 41 ff 00 c8 ab fc c5 1f 52 c2 7f d0 2e 1b ff 00 09 e8 87 d7 31 bf f4 19 88 ff 00 c1 b5 bf f9 37 f9 7d e3 3c 84 e7 0a 80 67 a6 c3 fd 25 51 f9 2a fd 3f ba 7d 4b 09 ff 00 40 b8 6f fc 27 a2 1f 5b c5 bf f9 8a c4 7f e0 fa 9f ac d7 e5 f7 83 42 5b 19 61 c7 40 17 00 7d 39 3e bd 7f 0e 71 ba b4 8d 0a 30 f8 28 d2 8f f8
            Data Ascii: 6Gz!ob?moXuJ>\7c3j"Q,'?YMoSm(?a?J716,,y0vAvAR.17}<g%Q*?}K@o'[B[a@}9>q0(


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974123.220.189.216443
            TimestampBytes transferredDirectionData
            2024-04-18 22:42:30 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-18 22:42:30 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/073D)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=202842
            Date: Thu, 18 Apr 2024 22:42:30 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.44974223.220.189.216443
            TimestampBytes transferredDirectionData
            2024-04-18 22:42:31 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-18 22:42:31 UTC535INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=202818
            Date: Thu, 18 Apr 2024 22:42:31 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-18 22:42:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:00:42:20
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:00:42:23
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2448,i,7999651277010272558,14678150477694211793,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:00:42:25
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.orlidkz.top/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly