Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png

Overview

General Information

Sample URL:https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn
Analysis ID:1430593
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 2888 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kbl8wfhm2.????.??/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2708 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1948,i,12575257087268405274,18063810118260740557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.pngAvira URL Cloud: detection malicious, Label: phishing
Source: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/favicon.icoAvira URL Cloud: Label: phishing
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: global trafficHTTP traffic detected: GET /lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png HTTP/1.1Host: kbl8wfhm2.xn--90a1ajj.xn--p1aiConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kbl8wfhm2.xn--90a1ajj.xn--p1aiConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.pngAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Gll1t4AtWA2GC7z&MD=64fmf2OU HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Gll1t4AtWA2GC7z&MD=64fmf2OU HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: kbl8wfhm2.xn--90a1ajj.xn--p1ai
Source: unknownHTTP traffic detected: POST /report/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 655Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 23 Apr 2024 21:05:34 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closeCache-Control: max-age=14400CF-Cache-Status: MISSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8790cfff7d175080-ATLalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: classification engineClassification label: mal56.win@14/8@6/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kbl8wfhm2.????.??/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1948,i,12575257087268405274,18063810118260740557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1948,i,12575257087268405274,18063810118260740557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    www.google.com
    142.251.15.104
    truefalse
      high
      kbl8wfhm2.xn--90a1ajj.xn--p1ai
      172.67.169.56
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/favicon.icofalse
        • Avira URL Cloud: phishing
        unknown
        https://a.nel.cloudflare.com/report/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3Dfalse
          high
          https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.pngtrue
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            35.190.80.1
            a.nel.cloudflare.comUnited States
            15169GOOGLEUSfalse
            172.67.169.56
            kbl8wfhm2.xn--90a1ajj.xn--p1aiUnited States
            13335CLOUDFLARENETUSfalse
            142.251.15.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.16
            192.168.2.6
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1430593
            Start date and time:2024-04-23 23:05:06 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 20s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowsinteractivecookbook.jbs
            Sample URL:https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:14
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal56.win@14/8@6/6
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.215.94, 142.250.9.84, 142.250.105.138, 142.250.105.102, 142.250.105.100, 142.250.105.139, 142.250.105.101, 142.250.105.113, 34.104.35.123, 72.21.81.240, 64.233.176.94, 172.217.215.100, 172.217.215.139, 172.217.215.138, 172.217.215.102, 172.217.215.113, 172.217.215.101
            • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 20:05:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2673
            Entropy (8bit):3.9865821846678178
            Encrypted:false
            SSDEEP:48:85d5ThpWHQidAKZdA1FehwiZUklqehhy+3:8tPNiy
            MD5:85DE593391BB024C8C1C210EDD493007
            SHA1:407E212DB241FFCB42E7412468D5A664EF324A5E
            SHA-256:FDE5E2C2A38AF854F07D44E65B7F0428C27933D1EDF76E83BC9A725B07A1784D
            SHA-512:6B0D9F48A97FB97DBEA863493F517DC3BBCDBE8AADE46E03330A0C3997DEB55A59F0C7E082646EF251E7FD1753791508AC7B1D913EC17939B0B95CB265099B81
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....>+D.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 20:05:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2675
            Entropy (8bit):4.005452304226934
            Encrypted:false
            SSDEEP:48:8ed5ThpWHQidAKZdA1seh/iZUkAQkqehSy+2:84Pj9Q/y
            MD5:45DA94D9FC62AE74956DDE3D8C85BA1C
            SHA1:DB88C8BCBE1DA9DB3D8306B9782478C1F0AA3D07
            SHA-256:913B279CE11FF89CF2AC3DF4EBF9C82029D319EDA566524DD44F1B17AAFA52CB
            SHA-512:7A00F5D7416F950A47076A38C3DF85CA3CB5796E3DC85B0F55241DB677774511107CE4E296384652891445E115340213F39DD8B0A045F34A54037D70BF6B66A4
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....6.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2689
            Entropy (8bit):4.010454342659941
            Encrypted:false
            SSDEEP:48:8Od5ThpAHQidAKZdA14meh7sFiZUkmgqeh7sgy+BX:8IPxnmy
            MD5:D0BCB0FF260134281B326ACEE4CDD242
            SHA1:4483D06E8712C51B85845384E14FDD9BB1ACD78D
            SHA-256:0EF7420C217244E0214A297DEE0D17C9A059C8D0D161DF7892BB17EBA4AFFA9E
            SHA-512:283000CEF0A2A20A9F0891A41B85F6E93DCA49096070EA25A24820DED72D44D51B786BF1105C05ABA237834AED22F14AAC1A13F607EE380992D5237AF95A0CCC
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 20:05:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):4.002029201439545
            Encrypted:false
            SSDEEP:48:8td5ThpWHQidAKZdA1TehDiZUkwqehuy+R:8ZPQoy
            MD5:118B46DC37B7D9B842AA980AA08145ED
            SHA1:395D2AA6CE9E40FDAE559B59210477C7A69E443A
            SHA-256:E370B74C9E7946A2C7EAD02149D2130221EA45A8A8B9095385D05E0C1B6BCB24
            SHA-512:6576FF46BFC7D6E035AD1A87D20AD75486F3230924913E3DC165744C1B3E621B4E42FACF12AD2D9B34554B79D89E06B20EE688210DF70DE573802A1926907C0D
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....7|0.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 20:05:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9894528081568525
            Encrypted:false
            SSDEEP:48:8Xid5ThpWHQidAKZdA1dehBiZUk1W1qehEy+C:8kPw9ky
            MD5:592E1D4DD675468FF08F5549D7CAA69E
            SHA1:3DF81D753B84DF2F15778715D01C5001976F8E65
            SHA-256:532E43D13F638972AB1735C0948F406B7266A8F5E0E378B2E36DD05BBF7230BF
            SHA-512:B6BFCF150C9D2C32EBA8C56D965F539974D2E64078294387BACFF108C1BDDF2657DDB803E120090972C8B0FD7C1275B4DF3C7FE34AF04EDEFD975CC7493BE2A5
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....t=.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 20:05:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):4.0005555993495205
            Encrypted:false
            SSDEEP:48:85d5ThpWHQidAKZdA1duTeehOuTbbiZUk5OjqehOuTbmy+yT+:8tPiTfTbxWOvTbmy7T
            MD5:05815269CFD99E5BD9CA2653B8BAA322
            SHA1:67685C3BFF3D7DC31DC5878D2359208327952968
            SHA-256:36993861F247D599E2845EDDD862E84E22C1BBA682BC49B2F45F127167150896
            SHA-512:556518090E36127593ABBEEA1CBC443B1056FBE3EAB02E0A41FD65CCDCF69FEC7B14FF42BD936334DC1CAD4E5A0892C7267B18E117CDF245249206D329BE38FD
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,...._.$.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i\:P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):209
            Entropy (8bit):5.143049113812332
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3ezJLM4KCezocKqD:J0+oxBeRmR9etdzRxy17ez1T
            MD5:18FFB59B61525F781CF9251045BE575D
            SHA1:BD7318B00B15B7A1C8A48524419FA2E5C27A5B6D
            SHA-256:B6682CAB65D3243B5B75EFB7279DBF49491957484780F2BA0A87632CC0E25642
            SHA-512:A032F853ABD9492232E1183D1CB1D14110B623F2E9DEC56B7B64DD576A0317DDA8D51125763E11D6642433C5364B2BD10A994EE4F1514629A4950BBAB3ABA499
            Malicious:false
            Reputation:low
            URL:https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/favicon.ico
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL /favicon.ico was not found on this server.</p>.</body></html>.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 23, 2024 23:05:33.727893114 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.727916002 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.727993965 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.728419065 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.728432894 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.728847027 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.728880882 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.728939056 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.729142904 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.729157925 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.956974983 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.957189083 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.957205057 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.957921982 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.958134890 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.958148003 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.959247112 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.959310055 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.959428072 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.959506989 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.960237026 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.960306883 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.960407972 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.960500956 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:33.960510015 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:33.960566044 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.012151957 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.012168884 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.012195110 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.060153008 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.554248095 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.554466009 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.554601908 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.555183887 CEST49699443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.555202961 CEST44349699172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.585381031 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.632165909 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.953670979 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.953830957 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:34.953917027 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.955537081 CEST49700443192.168.2.16172.67.169.56
            Apr 23, 2024 23:05:34.955579996 CEST44349700172.67.169.56192.168.2.16
            Apr 23, 2024 23:05:35.062932968 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.062992096 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.063100100 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.063313007 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.063338041 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.292279005 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.292733908 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.292757988 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.294235945 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.294327974 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.295474052 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.295564890 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.295623064 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.337178946 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.337194920 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.385207891 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.525063038 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.525181055 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.525248051 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.525482893 CEST49702443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.525502920 CEST4434970235.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.526026964 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.526084900 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.526170015 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.526444912 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.526459932 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.748636961 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.749033928 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.749047995 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.750207901 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.750602961 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.750778913 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.750818014 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.792149067 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.799276114 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.986789942 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.987019062 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.987102985 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.987231970 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.987256050 CEST4434970335.190.80.1192.168.2.16
            Apr 23, 2024 23:05:35.987267017 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:35.987309933 CEST49703443192.168.2.1635.190.80.1
            Apr 23, 2024 23:05:38.096601963 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:38.400227070 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:38.525652885 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.525715113 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.525804996 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.526071072 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.526088953 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.752857924 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.753241062 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.753294945 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.754952908 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.755059004 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.756419897 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.756525993 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.799206018 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:38.799227953 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:38.847214937 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:39.007188082 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:40.076776981 CEST4968980192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:40.215153933 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:42.628159046 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:44.422735929 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.422820091 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.422939062 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.425018072 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.425056934 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.649868965 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.649986982 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.654207945 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.654231071 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.654568911 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.691960096 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.736121893 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.853311062 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.853404999 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.853581905 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.853631973 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.853632927 CEST49710443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.853669882 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.853696108 CEST44349710184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.897840023 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.897896051 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:44.898010969 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.898251057 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:44.898263931 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.120570898 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.120677948 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.122042894 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.122061968 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.122824907 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.123989105 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.168131113 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.329119921 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.329278946 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.329358101 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.329988956 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.330020905 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:45.330034018 CEST49711443192.168.2.16184.31.62.93
            Apr 23, 2024 23:05:45.330041885 CEST44349711184.31.62.93192.168.2.16
            Apr 23, 2024 23:05:46.266601086 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:46.567198992 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:47.170188904 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:47.441236973 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:05:47.904742002 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:47.904787064 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:47.904999018 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:47.906002045 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:47.906028032 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:48.379194021 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:48.523283005 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:48.523382902 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:48.527652979 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:48.527688980 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:48.528137922 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:48.568187952 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:48.590529919 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:48.632138968 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:48.762392044 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:48.762464046 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:48.762558937 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:49.098872900 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.098906994 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.098917007 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.098928928 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.098958015 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.098994017 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.099042892 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.099081993 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.099124908 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.099127054 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.099219084 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.110466957 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.110500097 CEST49712443192.168.2.1640.127.169.103
            Apr 23, 2024 23:05:49.110500097 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.110507965 CEST4434971240.127.169.103192.168.2.16
            Apr 23, 2024 23:05:49.829904079 CEST49704443192.168.2.16142.251.15.104
            Apr 23, 2024 23:05:49.829962015 CEST44349704142.251.15.104192.168.2.16
            Apr 23, 2024 23:05:50.738356113 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:50.786206007 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:51.041203022 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:51.648221970 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:52.863328934 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:55.275222063 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:05:55.594225883 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:05:57.049245119 CEST49673443192.168.2.16204.79.197.203
            Apr 23, 2024 23:06:00.083257914 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:06:05.207226992 CEST49678443192.168.2.1620.189.173.10
            Apr 23, 2024 23:06:09.695275068 CEST4968080192.168.2.16192.229.211.108
            Apr 23, 2024 23:06:25.453262091 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:25.453303099 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:25.453421116 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:25.453783035 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:25.453792095 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.058532953 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.058619022 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.060344934 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.060354948 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.060657024 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.062222004 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.108120918 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.646822929 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.646886110 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.646928072 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.647165060 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.647191048 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.647212982 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.647378922 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.649945974 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.649966955 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:26.649979115 CEST49713443192.168.2.1640.127.169.103
            Apr 23, 2024 23:06:26.649985075 CEST4434971340.127.169.103192.168.2.16
            Apr 23, 2024 23:06:38.483586073 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:38.483622074 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.483750105 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:38.483990908 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:38.484004974 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.702748060 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.703109980 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:38.703130007 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.703824997 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.704214096 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:38.704298019 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:38.753415108 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:40.159337044 CEST49688443192.168.2.16204.79.197.200
            Apr 23, 2024 23:06:48.716645002 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:48.716706038 CEST44349715142.251.15.104192.168.2.16
            Apr 23, 2024 23:06:48.716814041 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:49.825911999 CEST49715443192.168.2.16142.251.15.104
            Apr 23, 2024 23:06:49.825943947 CEST44349715142.251.15.104192.168.2.16
            TimestampSource PortDest PortSource IPDest IP
            Apr 23, 2024 23:05:33.593314886 CEST5516153192.168.2.161.1.1.1
            Apr 23, 2024 23:05:33.593457937 CEST5697053192.168.2.161.1.1.1
            Apr 23, 2024 23:05:33.681731939 CEST53522771.1.1.1192.168.2.16
            Apr 23, 2024 23:05:33.700665951 CEST53581621.1.1.1192.168.2.16
            Apr 23, 2024 23:05:33.703366041 CEST53551611.1.1.1192.168.2.16
            Apr 23, 2024 23:05:33.879743099 CEST53569701.1.1.1192.168.2.16
            Apr 23, 2024 23:05:34.306057930 CEST53653561.1.1.1192.168.2.16
            Apr 23, 2024 23:05:34.955204964 CEST6334453192.168.2.161.1.1.1
            Apr 23, 2024 23:05:34.955394030 CEST6526753192.168.2.161.1.1.1
            Apr 23, 2024 23:05:35.061753988 CEST53652671.1.1.1192.168.2.16
            Apr 23, 2024 23:05:35.062236071 CEST53633441.1.1.1192.168.2.16
            Apr 23, 2024 23:05:38.417387962 CEST6071653192.168.2.161.1.1.1
            Apr 23, 2024 23:05:38.417594910 CEST6540953192.168.2.161.1.1.1
            Apr 23, 2024 23:05:38.524199009 CEST53607161.1.1.1192.168.2.16
            Apr 23, 2024 23:05:38.524302959 CEST53654091.1.1.1192.168.2.16
            Apr 23, 2024 23:05:51.244976044 CEST53616631.1.1.1192.168.2.16
            Apr 23, 2024 23:06:10.203921080 CEST53626641.1.1.1192.168.2.16
            Apr 23, 2024 23:06:32.795056105 CEST53550931.1.1.1192.168.2.16
            Apr 23, 2024 23:06:33.674376965 CEST53546711.1.1.1192.168.2.16
            Apr 23, 2024 23:06:42.440502882 CEST138138192.168.2.16192.168.2.255
            Apr 23, 2024 23:07:02.376108885 CEST53502701.1.1.1192.168.2.16
            TimestampSource IPDest IPChecksumCodeType
            Apr 23, 2024 23:05:33.879828930 CEST192.168.2.161.1.1.1c249(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 23, 2024 23:05:33.593314886 CEST192.168.2.161.1.1.10x6e39Standard query (0)kbl8wfhm2.xn--90a1ajj.xn--p1aiA (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:33.593457937 CEST192.168.2.161.1.1.10x8a98Standard query (0)kbl8wfhm2.xn--90a1ajj.xn--p1ai65IN (0x0001)false
            Apr 23, 2024 23:05:34.955204964 CEST192.168.2.161.1.1.10x54cdStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:34.955394030 CEST192.168.2.161.1.1.10xa3cStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
            Apr 23, 2024 23:05:38.417387962 CEST192.168.2.161.1.1.10x61f4Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.417594910 CEST192.168.2.161.1.1.10xb9acStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 23, 2024 23:05:33.703366041 CEST1.1.1.1192.168.2.160x6e39No error (0)kbl8wfhm2.xn--90a1ajj.xn--p1ai172.67.169.56A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:33.703366041 CEST1.1.1.1192.168.2.160x6e39No error (0)kbl8wfhm2.xn--90a1ajj.xn--p1ai104.21.79.72A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:33.879743099 CEST1.1.1.1192.168.2.160x8a98No error (0)kbl8wfhm2.xn--90a1ajj.xn--p1ai65IN (0x0001)false
            Apr 23, 2024 23:05:35.062236071 CEST1.1.1.1192.168.2.160x54cdNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.104A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.103A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.147A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.106A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.105A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524199009 CEST1.1.1.1192.168.2.160x61f4No error (0)www.google.com142.251.15.99A (IP address)IN (0x0001)false
            Apr 23, 2024 23:05:38.524302959 CEST1.1.1.1192.168.2.160xb9acNo error (0)www.google.com65IN (0x0001)false
            • kbl8wfhm2.xn--90a1ajj.xn--p1ai
            • https:
            • a.nel.cloudflare.com
            • fs.microsoft.com
            • slscr.update.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.1649699172.67.169.564432708C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:33 UTC878OUTGET /lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png HTTP/1.1
            Host: kbl8wfhm2.xn--90a1ajj.xn--p1ai
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-23 21:05:34 UTC628INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 21:05:34 GMT
            Content-Type: text/html; charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            X-Powered-By: PHP/5.4.16
            CF-Cache-Status: DYNAMIC
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rPrlFQvBKDIrWyApK3h%2FZagBvms03KnnxBXWncEKUTFH03%2Bxc7Fzz7onzCjiVUYL4Uwh%2BLzo9Y9Yrp7l%2FVR%2BMtpLABCbDeNwJc01McFhO3RENw9KHAvxxE%2BQ%2BCmIA7LjikA3tZ7CY9REN7qTlLFGEtI%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            Server: cloudflare
            CF-RAY: 8790cffc7a9f135f-ATL
            alt-svc: h3=":443"; ma=86400
            2024-04-23 21:05:34 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.1649700172.67.169.564432708C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:34 UTC821OUTGET /favicon.ico HTTP/1.1
            Host: kbl8wfhm2.xn--90a1ajj.xn--p1ai
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-23 21:05:34 UTC637INHTTP/1.1 404 Not Found
            Date: Tue, 23 Apr 2024 21:05:34 GMT
            Content-Type: text/html; charset=iso-8859-1
            Transfer-Encoding: chunked
            Connection: close
            Cache-Control: max-age=14400
            CF-Cache-Status: MISS
            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3D"}],"group":"cf-nel","max_age":604800}
            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
            Server: cloudflare
            CF-RAY: 8790cfff7d175080-ATL
            alt-svc: h3=":443"; ma=86400
            2024-04-23 21:05:34 UTC215INData Raw: 64 31 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0d 0a
            Data Ascii: d1<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /favicon.ico was not found on this server.</p></body></html>
            2024-04-23 21:05:34 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.164970235.190.80.14432708C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:35 UTC575OUTOPTIONS /report/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Origin: https://kbl8wfhm2.xn--90a1ajj.xn--p1ai
            Access-Control-Request-Method: POST
            Access-Control-Request-Headers: content-type
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-23 21:05:35 UTC336INHTTP/1.1 200 OK
            Content-Length: 0
            access-control-max-age: 86400
            access-control-allow-methods: POST, OPTIONS
            access-control-allow-origin: *
            access-control-allow-headers: content-length, content-type
            date: Tue, 23 Apr 2024 21:05:35 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.164970335.190.80.14432708C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:35 UTC502OUTPOST /report/v4?s=ft%2F6lj72jKIrBkB678NW5ycg424iB9y8nu0N0tIA2WyEdbo5GHiQcW2nTjunNcrCXhiG0MK%2FuNQYPBVlqr%2Fj9gwIQlqToajOvaVPYl1jxmaOC%2BEAzioj7eBska5dGcYor4N8Pj3%2FA3vWQAMJMqXWGWg%3D HTTP/1.1
            Host: a.nel.cloudflare.com
            Connection: keep-alive
            Content-Length: 655
            Content-Type: application/reports+json
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-23 21:05:35 UTC655OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 33 36 38 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 6b 62 6c 38 77 66 68 6d 32 2e 78 6e 2d 2d 39 30 61 31 61 6a 6a 2e 78 6e 2d 2d 70 31 61 69 2f 6c 6d 2e 70 68 70 3f 74 6b 3d 55 32 56 6a 64 58 4a 70 64 48 6b 4a 43 51 6c 7a 5a 57 4e 31 63 6d 6c 30 65 55 42 32 5a 57 4e 30 63 6d 45 75 59 57 6b 4a 4e 7a 49 78 4d 6a 6b 31 4e 44 49 31 43 54 51 34 4e 54 45 34 4d 54 67 79 4d 6a 41 35 4e 54 55 32 4f 51 6c 51 65 58 52 6f 62 32 35 66 54 6d 56 33 43 54 45 34 4f 54 6b 79 4f 44
            Data Ascii: [{"age":0,"body":{"elapsed_time":368,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://kbl8wfhm2.xn--90a1ajj.xn--p1ai/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyOD
            2024-04-23 21:05:35 UTC168INHTTP/1.1 200 OK
            Content-Length: 0
            date: Tue, 23 Apr 2024 21:05:35 GMT
            Via: 1.1 google
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.1649710184.31.62.93443
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:44 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 21:05:44 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/079C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=35894
            Date: Tue, 23 Apr 2024 21:05:44 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.1649711184.31.62.93443
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:45 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 21:05:45 UTC804INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0778)
            X-CID: 11
            X-CCC: US
            X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
            X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
            Content-Type: application/octet-stream
            X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
            Cache-Control: public, max-age=35840
            Date: Tue, 23 Apr 2024 21:05:45 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-23 21:05:45 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.164971240.127.169.103443
            TimestampBytes transferredDirectionData
            2024-04-23 21:05:48 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Gll1t4AtWA2GC7z&MD=64fmf2OU HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-04-23 21:05:49 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
            MS-CorrelationId: ea146882-8c06-4fe2-ba61-6eddf7b0bad1
            MS-RequestId: 46259bcc-7ba8-42e9-bf0c-96311142f66e
            MS-CV: tYg+/9YYWUCqFwrh.0
            X-Microsoft-SLSClientCache: 2880
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Tue, 23 Apr 2024 21:05:48 GMT
            Connection: close
            Content-Length: 24490
            2024-04-23 21:05:49 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
            Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
            2024-04-23 21:05:49 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
            Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            7192.168.2.164971340.127.169.103443
            TimestampBytes transferredDirectionData
            2024-04-23 21:06:26 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Gll1t4AtWA2GC7z&MD=64fmf2OU HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-04-23 21:06:26 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
            MS-CorrelationId: 08fbaad3-3be0-4754-ab38-1dfd4ece170c
            MS-RequestId: 5067c2da-0358-4276-875c-b7f9a589ccb8
            MS-CV: WA3/FylPCEm0cnRm.0
            X-Microsoft-SLSClientCache: 2160
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Tue, 23 Apr 2024 21:06:26 GMT
            Connection: close
            Content-Length: 25457
            2024-04-23 21:06:26 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
            Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
            2024-04-23 21:06:26 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
            Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:23:05:32
            Start date:23/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://kbl8wfhm2.????.??/lm.php?tk=U2VjdXJpdHkJCQlzZWN1cml0eUB2ZWN0cmEuYWkJNzIxMjk1NDI1CTQ4NTE4MTgyMjA5NTU2OQlQeXRob25fTmV3CTE4OTkyODA2NDIJb3Blbglubwlubw==&url=https%3A%2F%2FS8p8QERcQ.xn--90a1ajj.xn--p1ai%2Flm%2Fpictures%2Fcti.png
            Imagebase:0x7ff7f9810000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:1
            Start time:23:05:32
            Start date:23/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1948,i,12575257087268405274,18063810118260740557,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff7f9810000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            No disassembly