Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.huiyuan-sh.com/

Overview

General Information

Sample URL:https://www.huiyuan-sh.com/
Analysis ID:1428472
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)

Classification

  • System is w10x64
  • chrome.exe (PID: 1220 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2232,i,6286027686562247848,12161036020932528935,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.huiyuan-sh.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://huiyuan-sh.comMatcher: Template: amazon matched with high similarity
Source: https://www.huiyuan-sh.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.huiyuan-sh.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.huiyuan-sh.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.huiyuan-sh.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.huiyuan-sh.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: www.huiyuan-sh.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginxDate: Thu, 18 Apr 2024 23:12:37 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encoding
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.win@16/5@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2232,i,6286027686562247848,12161036020932528935,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.huiyuan-sh.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2232,i,6286027686562247848,12161036020932528935,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.9.106
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalse
      unknown
      www.huiyuan-sh.com
      87.121.112.42
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://www.huiyuan-sh.com/false
          unknown
          https://www.huiyuan-sh.com/favicon.icofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.9.106
            www.google.comUnited States
            15169GOOGLEUSfalse
            87.121.112.42
            www.huiyuan-sh.comBulgaria
            34224NETERRA-ASBGfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1428472
            Start date and time:2024-04-19 01:11:40 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 18s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://www.huiyuan-sh.com/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.phis.win@16/5@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 74.125.136.94, 172.217.215.100, 172.217.215.113, 172.217.215.138, 172.217.215.139, 172.217.215.101, 172.217.215.102, 172.217.215.84, 34.104.35.123, 20.12.23.50, 72.21.81.240, 52.165.164.15, 192.229.211.108, 74.125.138.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://www.huiyuan-sh.com/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):194
            Entropy (8bit):5.02732657063762
            Encrypted:false
            SSDEEP:3:PIyPhxn0+7JD0bZxgROngsoMHXbZ6iMyF0U96LFa3RsxRNs+GBFK67hXW1Hj:pn0+1Q9xUigsoCX966F0CGxdGzKGSD
            MD5:CBB55BCC4E4C013040B33E22FAAA013D
            SHA1:7995E35B37532EE7ABE715F23225A88A81BEB5D2
            SHA-256:AFCA372F9959CB6C46BDE573D25172C1B223DAC52CBA20FFAD3C8FC2EA09CC8E
            SHA-512:751A6FA05158382C18079BFEB1BD155651C5C0B003AC4A097541FDCC08A1EB3B17E06073A8EC68E9B2F42FE58DE5F8B10CE0E10429FB45535A02352C8A5FFA49
            Malicious:false
            Reputation:low
            URL:https://www.huiyuan-sh.com/
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You dont have permission to access / on this server.</p></body></html>
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 4 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:downloaded
            Size (bytes):17542
            Entropy (8bit):2.247918084411713
            Encrypted:false
            SSDEEP:192:9dLhJ6/f2dh+xQLeZ10TLwhwOHae6nmErcglsIZS3F:3jaOdhQQu0TLwaOHEr6IZ
            MD5:CA6619B86C2F6E6068B69BA3AADDB7E4
            SHA1:C44A1BB9D14385334EB851FBB0AFB19D961C1EE7
            SHA-256:17D02E2DB6DBEDB95DD449D06868C147AC2C3B5371497BCB9407E75336A99E09
            SHA-512:30F8F8618BFBCD57925411E6860A10B6AD9A60F2A6B08D35C870EA3F4CEC4692596A937FF1457CEFF5847D5DA2B86CEBA0200706625E28C56A2455E6A8C121D3
            Malicious:false
            Reputation:low
            URL:https://www.huiyuan-sh.com/favicon.ico
            Preview:......00.... ..%..F... .... ......%........ ......6........ .h....@..(...0...`..... ......%.........................................E...................................................................................................................................................?...................................$...........................................................................................................................................................................................B............................................................................r...P..........................................................................................9...............-........................................................r...................................................>......................................................................$..............................................................................................................................
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 4 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:dropped
            Size (bytes):17542
            Entropy (8bit):2.247918084411713
            Encrypted:false
            SSDEEP:192:9dLhJ6/f2dh+xQLeZ10TLwhwOHae6nmErcglsIZS3F:3jaOdhQQu0TLwaOHEr6IZ
            MD5:CA6619B86C2F6E6068B69BA3AADDB7E4
            SHA1:C44A1BB9D14385334EB851FBB0AFB19D961C1EE7
            SHA-256:17D02E2DB6DBEDB95DD449D06868C147AC2C3B5371497BCB9407E75336A99E09
            SHA-512:30F8F8618BFBCD57925411E6860A10B6AD9A60F2A6B08D35C870EA3F4CEC4692596A937FF1457CEFF5847D5DA2B86CEBA0200706625E28C56A2455E6A8C121D3
            Malicious:false
            Reputation:low
            Preview:......00.... ..%..F... .... ......%........ ......6........ .h....@..(...0...`..... ......%.........................................E...................................................................................................................................................?...................................$...........................................................................................................................................................................................B............................................................................r...P..........................................................................................9...............-........................................................r...................................................>......................................................................$..............................................................................................................................
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 01:12:27.564065933 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 01:12:36.561697006 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.561750889 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:36.561918974 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.562427044 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.562499046 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.562505960 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:36.562513113 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:36.562788963 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.562788963 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:36.562917948 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.049457073 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.049815893 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.049879074 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.051146030 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.051223993 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.052252054 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.052324057 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.052530050 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.052539110 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.060066938 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.060396910 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.060456991 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.062158108 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.062236071 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.063060999 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.063193083 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.098799944 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.114522934 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.114599943 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.162481070 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.178023100 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 01:12:37.694225073 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.694473028 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.694535017 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.695646048 CEST49735443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.695666075 CEST4434973587.121.112.42192.168.2.4
            Apr 19, 2024 01:12:37.765732050 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:37.812194109 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.243926048 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.243980885 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.243999958 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244041920 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244060040 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244076967 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244168043 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244168043 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244168043 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244168043 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244168043 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244273901 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244306087 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244370937 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244370937 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.244390965 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244441032 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.244501114 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.247319937 CEST49736443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.247379065 CEST4434973687.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.532241106 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.532318115 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.532594919 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.533027887 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:38.533098936 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:38.844078064 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:38.844185114 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:38.844278097 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:38.846143007 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:38.846256971 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.014578104 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.015127897 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.015187025 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.018440008 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.018640041 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.020401001 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.020545959 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.020678043 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.020755053 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.020828962 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.021413088 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.021471024 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.026032925 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.026109934 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.063009977 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.100236893 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.100770950 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:39.100830078 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.102315903 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.102502108 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:39.104041100 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:39.104178905 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.156637907 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:39.156694889 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:39.197376013 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:39.252969027 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.253192902 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.259843111 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.259892941 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.260355949 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.312999010 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.325459003 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.372159004 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.449141979 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.449302912 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.449544907 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.449544907 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.449621916 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.449672937 CEST49741443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.449688911 CEST44349741184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.507739067 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.507824898 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.508174896 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.511720896 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.511754990 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.722202063 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722273111 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722300053 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722440958 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722493887 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722508907 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.722508907 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.722573996 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722642899 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.722642899 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.722650051 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.722686052 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.722877026 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.727801085 CEST49739443192.168.2.487.121.112.42
            Apr 19, 2024 01:12:39.727859974 CEST4434973987.121.112.42192.168.2.4
            Apr 19, 2024 01:12:39.731946945 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.732127905 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.746352911 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.746387959 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.746817112 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.760268927 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.808120966 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.937267065 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.937428951 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:39.938196898 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.938196898 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:39.938196898 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:40.251729012 CEST49742443192.168.2.4184.31.62.93
            Apr 19, 2024 01:12:40.251796961 CEST44349742184.31.62.93192.168.2.4
            Apr 19, 2024 01:12:49.099633932 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:49.099701881 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:12:49.100080967 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:50.596746922 CEST49740443192.168.2.4142.250.9.106
            Apr 19, 2024 01:12:50.596808910 CEST44349740142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.429946899 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:38.429986954 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.430069923 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:38.430274963 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:38.430285931 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.645816088 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.680659056 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:38.680681944 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.681802988 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.682166100 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:38.682337999 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:38.734713078 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:48.687160015 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:48.687298059 CEST44349750142.250.9.106192.168.2.4
            Apr 19, 2024 01:13:48.687494993 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:50.632096052 CEST49750443192.168.2.4142.250.9.106
            Apr 19, 2024 01:13:50.632124901 CEST44349750142.250.9.106192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 01:12:34.254106998 CEST53550921.1.1.1192.168.2.4
            Apr 19, 2024 01:12:34.406652927 CEST53642061.1.1.1192.168.2.4
            Apr 19, 2024 01:12:35.003467083 CEST53576491.1.1.1192.168.2.4
            Apr 19, 2024 01:12:36.194464922 CEST5213953192.168.2.41.1.1.1
            Apr 19, 2024 01:12:36.194593906 CEST6033153192.168.2.41.1.1.1
            Apr 19, 2024 01:12:36.507736921 CEST53521391.1.1.1192.168.2.4
            Apr 19, 2024 01:12:38.260327101 CEST6261653192.168.2.41.1.1.1
            Apr 19, 2024 01:12:38.260587931 CEST5006453192.168.2.41.1.1.1
            Apr 19, 2024 01:12:38.279340982 CEST5962053192.168.2.41.1.1.1
            Apr 19, 2024 01:12:38.279949903 CEST5984153192.168.2.41.1.1.1
            Apr 19, 2024 01:12:38.384285927 CEST53596201.1.1.1192.168.2.4
            Apr 19, 2024 01:12:38.385230064 CEST53598411.1.1.1192.168.2.4
            Apr 19, 2024 01:12:38.481750965 CEST53626161.1.1.1192.168.2.4
            Apr 19, 2024 01:12:39.044284105 CEST53603311.1.1.1192.168.2.4
            Apr 19, 2024 01:12:40.943825960 CEST53500641.1.1.1192.168.2.4
            Apr 19, 2024 01:12:52.139641047 CEST53494211.1.1.1192.168.2.4
            Apr 19, 2024 01:12:53.755527973 CEST138138192.168.2.4192.168.2.255
            Apr 19, 2024 01:13:11.300335884 CEST53549711.1.1.1192.168.2.4
            Apr 19, 2024 01:13:33.648232937 CEST53493941.1.1.1192.168.2.4
            Apr 19, 2024 01:13:33.917052984 CEST53500751.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Apr 19, 2024 01:12:39.044353962 CEST192.168.2.41.1.1.1c1e8(Port unreachable)Destination Unreachable
            Apr 19, 2024 01:12:40.943885088 CEST192.168.2.41.1.1.1c1e8(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 19, 2024 01:12:36.194464922 CEST192.168.2.41.1.1.10x12bdStandard query (0)www.huiyuan-sh.comA (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:36.194593906 CEST192.168.2.41.1.1.10x6faStandard query (0)www.huiyuan-sh.com65IN (0x0001)false
            Apr 19, 2024 01:12:38.260327101 CEST192.168.2.41.1.1.10xc16eStandard query (0)www.huiyuan-sh.comA (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.260587931 CEST192.168.2.41.1.1.10xc1edStandard query (0)www.huiyuan-sh.com65IN (0x0001)false
            Apr 19, 2024 01:12:38.279340982 CEST192.168.2.41.1.1.10x2515Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.279949903 CEST192.168.2.41.1.1.10xbb7bStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 19, 2024 01:12:36.507736921 CEST1.1.1.1192.168.2.40x12bdNo error (0)www.huiyuan-sh.com87.121.112.42A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.106A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.147A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.105A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.99A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.104A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.384285927 CEST1.1.1.1192.168.2.40x2515No error (0)www.google.com142.250.9.103A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:38.385230064 CEST1.1.1.1192.168.2.40xbb7bNo error (0)www.google.com65IN (0x0001)false
            Apr 19, 2024 01:12:38.481750965 CEST1.1.1.1192.168.2.40xc16eNo error (0)www.huiyuan-sh.com87.121.112.42A (IP address)IN (0x0001)false
            Apr 19, 2024 01:12:39.044284105 CEST1.1.1.1192.168.2.40x6faServer failure (2)www.huiyuan-sh.comnonenone65IN (0x0001)false
            Apr 19, 2024 01:12:40.943825960 CEST1.1.1.1192.168.2.40xc1edServer failure (2)www.huiyuan-sh.comnonenone65IN (0x0001)false
            Apr 19, 2024 01:12:51.998294115 CEST1.1.1.1192.168.2.40x4dabNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 01:12:51.998294115 CEST1.1.1.1192.168.2.40x4dabNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 01:13:07.232477903 CEST1.1.1.1192.168.2.40x730eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 01:13:07.232477903 CEST1.1.1.1192.168.2.40x730eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 01:13:26.415397882 CEST1.1.1.1192.168.2.40xe890No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 01:13:26.415397882 CEST1.1.1.1192.168.2.40xe890No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 01:13:46.705149889 CEST1.1.1.1192.168.2.40xedf5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 01:13:46.705149889 CEST1.1.1.1192.168.2.40xedf5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • www.huiyuan-sh.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44973587.121.112.424432004C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 23:12:37 UTC661OUTGET / HTTP/1.1
            Host: www.huiyuan-sh.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 23:12:37 UTC188INHTTP/1.1 403 Forbidden
            Server: nginx
            Date: Thu, 18 Apr 2024 23:12:37 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept-Encoding
            2024-04-18 23:12:37 UTC205INData Raw: 63 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 70 3e 59 6f 75 20 64 6f 6e 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 2f 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 30 0d 0a 0d 0a
            Data Ascii: c2<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You dont have permission to access / on this server.</p></body></html>0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973687.121.112.424432004C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 23:12:37 UTC592OUTGET /favicon.ico HTTP/1.1
            Host: www.huiyuan-sh.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://www.huiyuan-sh.com/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 23:12:38 UTC277INHTTP/1.1 200 OK
            Server: nginx
            Date: Thu, 18 Apr 2024 23:12:37 GMT
            Content-Type: image/x-icon
            Content-Length: 17542
            Last-Modified: Mon, 09 May 2022 09:40:28 GMT
            Connection: close
            ETag: "6278e18c-4486"
            Strict-Transport-Security: max-age=31536000
            Accept-Ranges: bytes
            2024-04-18 23:12:38 UTC16107INData Raw: 00 00 01 00 04 00 30 30 00 00 01 00 20 00 a8 25 00 00 46 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 ee 25 00 00 18 18 00 00 01 00 20 00 88 09 00 00 96 36 00 00 10 10 00 00 01 00 20 00 68 04 00 00 1e 40 00 00 28 00 00 00 30 00 00 00 60 00 00 00 01 00 20 00 00 00 00 00 80 25 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 45 ff ff ff 99 ff ff ff cc ff ff ff f3 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
            Data Ascii: 00 %F % 6 h@(0` %E
            2024-04-18 23:12:38 UTC1435INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 75 ff ff ff 09 ff ff ff c3 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff bd ff ff ff 06 00 00 00 00 ff ff ff 03 ff ff ff 75 ff ff ff d2 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff cf ff ff ff 75 ff ff ff 03 00 00 00 00 80 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
            Data Ascii: uuu


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44973987.121.112.424432004C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-18 23:12:39 UTC353OUTGET /favicon.ico HTTP/1.1
            Host: www.huiyuan-sh.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-18 23:12:39 UTC277INHTTP/1.1 200 OK
            Server: nginx
            Date: Thu, 18 Apr 2024 23:12:39 GMT
            Content-Type: image/x-icon
            Content-Length: 17542
            Last-Modified: Mon, 09 May 2022 09:40:28 GMT
            Connection: close
            ETag: "6278e18c-4486"
            Strict-Transport-Security: max-age=31536000
            Accept-Ranges: bytes
            2024-04-18 23:12:39 UTC16107INData Raw: 00 00 01 00 04 00 30 30 00 00 01 00 20 00 a8 25 00 00 46 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 ee 25 00 00 18 18 00 00 01 00 20 00 88 09 00 00 96 36 00 00 10 10 00 00 01 00 20 00 68 04 00 00 1e 40 00 00 28 00 00 00 30 00 00 00 60 00 00 00 01 00 20 00 00 00 00 00 80 25 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff 45 ff ff ff 99 ff ff ff cc ff ff ff f3 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
            Data Ascii: 00 %F % 6 h@(0` %E
            2024-04-18 23:12:39 UTC1435INData Raw: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 75 ff ff ff 09 ff ff ff c3 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff bd ff ff ff 06 00 00 00 00 ff ff ff 03 ff ff ff 75 ff ff ff d2 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff cf ff ff ff 75 ff ff ff 03 00 00 00 00 80 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
            Data Ascii: uuu


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.449741184.31.62.93443
            TimestampBytes transferredDirectionData
            2024-04-18 23:12:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-18 23:12:39 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/079C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=201042
            Date: Thu, 18 Apr 2024 23:12:39 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449742184.31.62.93443
            TimestampBytes transferredDirectionData
            2024-04-18 23:12:39 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-18 23:12:39 UTC805INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0778)
            X-CID: 11
            X-CCC: US
            X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
            X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
            Content-Type: application/octet-stream
            X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=201063
            Date: Thu, 18 Apr 2024 23:12:39 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-18 23:12:39 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:01:12:31
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:01:12:32
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2232,i,6286027686562247848,12161036020932528935,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:01:12:35
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.huiyuan-sh.com/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly