Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://fernwork.com/

Overview

General Information

Sample URL:https://fernwork.com/
Analysis ID:1430611
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2312 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1880 --field-trial-handle=1988,i,4519568244183972402,11343462911106918720,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6456 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fernwork.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://fernwork.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fernwork.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /vendor/vendor.23238u92u82.js HTTP/1.1Host: fernwork.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://fernwork.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
Source: global trafficHTTP traffic detected: GET /index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14b HTTP/1.1Host: fernwork.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://fernwork.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: fernwork.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://fernwork.com/index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14bAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: fernwork.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
Source: unknownDNS traffic detected: queries for: fernwork.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@7/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1880 --field-trial-handle=1988,i,4519568244183972402,11343462911106918720,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fernwork.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1880 --field-trial-handle=1988,i,4519568244183972402,11343462911106918720,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://fernwork.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://fernwork.com/vendor/vendor.23238u92u82.js0%Avira URL Cloudsafe
https://fernwork.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.101.106
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalse
      unknown
      fernwork.com
      208.87.207.65
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://fernwork.com/vendor/vendor.23238u92u82.jsfalse
        • Avira URL Cloud: safe
        unknown
        https://fernwork.com/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        https://fernwork.com/index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14bfalse
          unknown
          https://fernwork.com/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.101.106
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            208.87.207.65
            fernwork.comUnited States
            35986VYVE-BROADBANDUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1430611
            Start date and time:2024-04-24 00:12:27 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 7s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://fernwork.com/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/5@7/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.251.2.84, 142.251.2.139, 142.251.2.102, 142.251.2.100, 142.251.2.138, 142.251.2.113, 142.251.2.101, 74.125.137.94, 34.104.35.123, 13.85.23.86, 23.206.188.27, 192.229.211.108, 52.165.164.15, 142.250.101.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://fernwork.com/
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 3 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:dropped
            Size (bytes):22382
            Entropy (8bit):2.2117771924639604
            Encrypted:false
            SSDEEP:48:nq/LDQsHmq5crBEQB+PLH4euMerTHb+qvceiJqIsxOOBfHiqcfzO58Vpnh:qXQomseyHc7b+qvcHsxNwqcfzR
            MD5:576287A38D00E198B1E8B4881932BE10
            SHA1:8401D5110333717C59E4165D34DCE913EB117697
            SHA-256:3850A133BFE3AC48100036A9452F60BFC74538BD94CED9AA53DB40B5654749E5
            SHA-512:7EABF7ABF5A0655E714A7EA7B55D124A33B82246C0AD932099348CE5FF92A4FFB25106719DD2C3A6E56BEB856D1C1368D89234CFC68D89997BA35BEF26577B98
            Malicious:false
            Reputation:low
            Preview:......@@.... .(B..6... .... .....^B........ .h....S..(...@......... .............................................3..)3...3...3...3...3...3.......................3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3..)................................3...3...3...3...3...3...3...3...3...a:..................3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3.......................3...3...3...3...3...3...3...3...3...3...5...................5...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...............3...3...3...3...3...3...3...3...3...3...3...3...................\3..3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (325), with CRLF line terminators
            Category:downloaded
            Size (bytes):4981
            Entropy (8bit):5.113240961469081
            Encrypted:false
            SSDEEP:96:zDEqwrbv1+GtJ8VuCDJwSUZ+pO8/npbKdHR9BweSW5WRq1EB6eOkkCGomn:zDlMzkGf8VuCJpO8ktRoeSWoq1Ece39m
            MD5:48DE24BB73AF029E4812C12060509B28
            SHA1:E715A83CBF612971F0275FFDFBA2E45604BE742A
            SHA-256:AE9DA3C9A568A7B3602DC54E10C324166DB3ABE1D3A6892770D6CE6A7CC8C1C6
            SHA-512:FFE85C26D576B7FFBB6052BE6D26E8D48D354FC927D05A2395B0C88F0D87A56E7A5077CDBAEB905F10B17895ACA49353ED4E46B01D5061ECB514617069AA9900
            Malicious:false
            Reputation:low
            URL:https://fernwork.com/vendor/vendor.23238u92u82.js
            Preview:const e = window, t = document;..function y(){.. return 'aHR0cDovLzEyNy4wLjAuMQ==';..}..function x() {.. return history.pushState(null,'',window.location.assign(atob(y())))..}..function _n(i) {.. const r1 = /\./;.. let k = navigator, u=r1.test(i);.... return (undefined === i) ? 0 :.. (u===true) ? k[i.split('.')[0]][i.split('.')[1]] :.. k[i]..}..function i() {.. return "function" != typeof t.createElement.. ? t.createElement(arguments[0]).. : E.. ? t.createElementNS.call(t, "http://www.w3.org/2000/svg", arguments[0]).. : t.createElement.apply(t, arguments);..}..function cs() {.. var j = 'cookieEnabled'.. return !(_n(j) === true) ? 0 : 1;..}..function c(){.. var e = i("canvas");.. return !(!e.getContext || !e.getContext("2d")) ? 1 : 0;..}..function g(){.. var e,t,r;.. if(c()){.. (e = i("canvas")),.. (t = e.getContext("webgl") || e.getContext("experimental-webgl")),.. (r
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows icon resource - 3 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
            Category:downloaded
            Size (bytes):22382
            Entropy (8bit):2.2117771924639604
            Encrypted:false
            SSDEEP:48:nq/LDQsHmq5crBEQB+PLH4euMerTHb+qvceiJqIsxOOBfHiqcfzO58Vpnh:qXQomseyHc7b+qvcHsxNwqcfzR
            MD5:576287A38D00E198B1E8B4881932BE10
            SHA1:8401D5110333717C59E4165D34DCE913EB117697
            SHA-256:3850A133BFE3AC48100036A9452F60BFC74538BD94CED9AA53DB40B5654749E5
            SHA-512:7EABF7ABF5A0655E714A7EA7B55D124A33B82246C0AD932099348CE5FF92A4FFB25106719DD2C3A6E56BEB856D1C1368D89234CFC68D89997BA35BEF26577B98
            Malicious:false
            Reputation:low
            URL:https://fernwork.com/favicon.ico
            Preview:......@@.... .(B..6... .... .....^B........ .h....S..(...@......... .............................................3..)3...3...3...3...3...3.......................3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3..)................................3...3...3...3...3...3...3...3...3...a:..................3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3.......................3...3...3...3...3...3...3...3...3...3...5...................5...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...............3...3...3...3...3...3...3...3...3...3...3...3...................\3..3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3...3.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 00:13:09.830506086 CEST49678443192.168.2.4104.46.162.224
            Apr 24, 2024 00:13:11.424288988 CEST49675443192.168.2.4173.222.162.32
            Apr 24, 2024 00:13:20.096997023 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.097040892 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.097115993 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.097640038 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.097706079 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.097775936 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.097894907 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.097910881 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.098082066 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.098112106 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.666121006 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.668180943 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.668219090 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.669785976 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.669872046 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.671019077 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.671116114 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.671242952 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.671257973 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.675693035 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.677078962 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.677155018 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.678059101 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.678169966 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.678519011 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.678581953 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.721386909 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.721396923 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:20.721435070 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:20.767040014 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.036458015 CEST49675443192.168.2.4173.222.162.32
            Apr 24, 2024 00:13:21.218014002 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.219014883 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.219118118 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.222556114 CEST49736443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.222598076 CEST44349736208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.268974066 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.312150955 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.564937115 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.564994097 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.565017939 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.565059900 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.565084934 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.565098047 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.565975904 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.566041946 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.572613955 CEST49735443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.572630882 CEST44349735208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.590255976 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.590312958 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.590374947 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.592375040 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.592426062 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.592480898 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.595056057 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.595077038 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:21.595762014 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:21.595778942 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.151581049 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.152034998 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.152096033 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.153317928 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.153876066 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.154055119 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.154189110 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.176832914 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.177051067 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.177074909 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.178204060 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.179037094 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.179126024 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.196144104 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:22.221726894 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:22.352245092 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.352293968 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.352368116 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.354600906 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.354617119 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.716450930 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.716721058 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.716741085 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.717740059 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.717809916 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.719047070 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.719118118 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.755109072 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:22.755146027 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:22.755285978 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:22.758651972 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:22.758663893 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:22.766290903 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:22.766299963 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:22.813916922 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:23.113746881 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.113869905 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.117495060 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.117501974 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.117752075 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.157776117 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.222459078 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.264161110 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.443382978 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.443460941 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.443530083 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.443707943 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.443731070 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.443749905 CEST49742443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.443756104 CEST4434974223.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.481247902 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.481352091 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.481507063 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.481823921 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.481877089 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.825978041 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.826050997 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.866291046 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.866329908 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.866600990 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:23.869411945 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:23.916131973 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:24.167130947 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:24.167321920 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:24.167398930 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:24.203864098 CEST49743443192.168.2.423.202.57.177
            Apr 24, 2024 00:13:24.203906059 CEST4434974323.202.57.177192.168.2.4
            Apr 24, 2024 00:13:26.769277096 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:26.769458055 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:26.769526005 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:26.769828081 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:26.769853115 CEST44349740208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:26.769893885 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:26.769903898 CEST49740443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:26.808726072 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:26.856125116 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.116590023 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.116620064 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.116628885 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.116668940 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.116693020 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.159522057 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.408678055 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.408715963 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.408751965 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.408768892 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.408791065 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.408807993 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.408818007 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.408828020 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.408854008 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.409024000 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.409085035 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.409359932 CEST49739443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.409375906 CEST44349739208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.755601883 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.755646944 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:27.755728006 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.755951881 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:27.755964994 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.328893900 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.329931021 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.329952955 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.330980062 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.331043959 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.331521988 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.331582069 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.332051992 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.332058907 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.376018047 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.914571047 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.914639950 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.914660931 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.914710999 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.914736032 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:28.914750099 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:28.985383034 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.196259975 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196295023 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196357012 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196372032 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.196376085 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196393013 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196423054 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.196453094 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.196537971 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:29.196590900 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.705532074 CEST49744443192.168.2.4208.87.207.65
            Apr 24, 2024 00:13:29.705559015 CEST44349744208.87.207.65192.168.2.4
            Apr 24, 2024 00:13:32.497157097 CEST49672443192.168.2.4173.222.162.32
            Apr 24, 2024 00:13:32.497191906 CEST44349672173.222.162.32192.168.2.4
            Apr 24, 2024 00:13:32.744695902 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:32.744751930 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:13:32.744796038 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:34.190999031 CEST49741443192.168.2.4142.250.101.106
            Apr 24, 2024 00:13:34.191020966 CEST44349741142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.321254015 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.321300983 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.321372032 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.322089911 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.322103024 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.683720112 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.735862970 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.743505001 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.743520975 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.744688034 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.745642900 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:22.745812893 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:22.798465014 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:28.814618111 CEST4972380192.168.2.4199.232.214.172
            Apr 24, 2024 00:14:28.814901114 CEST4972480192.168.2.4199.232.214.172
            Apr 24, 2024 00:14:28.976758957 CEST8049723199.232.214.172192.168.2.4
            Apr 24, 2024 00:14:28.976782084 CEST8049723199.232.214.172192.168.2.4
            Apr 24, 2024 00:14:28.976831913 CEST4972380192.168.2.4199.232.214.172
            Apr 24, 2024 00:14:28.977183104 CEST8049724199.232.214.172192.168.2.4
            Apr 24, 2024 00:14:28.977197886 CEST8049724199.232.214.172192.168.2.4
            Apr 24, 2024 00:14:28.977317095 CEST4972480192.168.2.4199.232.214.172
            Apr 24, 2024 00:14:32.678580046 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:32.678740025 CEST44349753142.250.101.106192.168.2.4
            Apr 24, 2024 00:14:32.678983927 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:34.178462982 CEST49753443192.168.2.4142.250.101.106
            Apr 24, 2024 00:14:34.178498030 CEST44349753142.250.101.106192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 00:13:18.142559052 CEST53563011.1.1.1192.168.2.4
            Apr 24, 2024 00:13:18.144093037 CEST53599381.1.1.1192.168.2.4
            Apr 24, 2024 00:13:19.111671925 CEST53550961.1.1.1192.168.2.4
            Apr 24, 2024 00:13:19.837073088 CEST6415353192.168.2.41.1.1.1
            Apr 24, 2024 00:13:19.837199926 CEST5419453192.168.2.41.1.1.1
            Apr 24, 2024 00:13:20.051223040 CEST53641531.1.1.1192.168.2.4
            Apr 24, 2024 00:13:22.187460899 CEST4931253192.168.2.41.1.1.1
            Apr 24, 2024 00:13:22.187643051 CEST5872953192.168.2.41.1.1.1
            Apr 24, 2024 00:13:22.342665911 CEST53493121.1.1.1192.168.2.4
            Apr 24, 2024 00:13:22.342724085 CEST53587291.1.1.1192.168.2.4
            Apr 24, 2024 00:13:25.936752081 CEST53541941.1.1.1192.168.2.4
            Apr 24, 2024 00:13:27.413934946 CEST6491353192.168.2.41.1.1.1
            Apr 24, 2024 00:13:27.414088964 CEST5717353192.168.2.41.1.1.1
            Apr 24, 2024 00:13:27.567924023 CEST53571731.1.1.1192.168.2.4
            Apr 24, 2024 00:13:27.568392992 CEST4942253192.168.2.41.1.1.1
            Apr 24, 2024 00:13:27.722265959 CEST53494221.1.1.1192.168.2.4
            Apr 24, 2024 00:13:27.735250950 CEST53649131.1.1.1192.168.2.4
            Apr 24, 2024 00:13:36.251810074 CEST53517211.1.1.1192.168.2.4
            Apr 24, 2024 00:13:40.351126909 CEST138138192.168.2.4192.168.2.255
            Apr 24, 2024 00:13:55.463495970 CEST53506791.1.1.1192.168.2.4
            Apr 24, 2024 00:14:17.675921917 CEST53635501.1.1.1192.168.2.4
            Apr 24, 2024 00:14:18.375808001 CEST53529311.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Apr 24, 2024 00:13:25.936835051 CEST192.168.2.41.1.1.1c1e2(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 24, 2024 00:13:19.837073088 CEST192.168.2.41.1.1.10xb819Standard query (0)fernwork.comA (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:19.837199926 CEST192.168.2.41.1.1.10xcd0eStandard query (0)fernwork.com65IN (0x0001)false
            Apr 24, 2024 00:13:22.187460899 CEST192.168.2.41.1.1.10x6049Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.187643051 CEST192.168.2.41.1.1.10x70a9Standard query (0)www.google.com65IN (0x0001)false
            Apr 24, 2024 00:13:27.413934946 CEST192.168.2.41.1.1.10xa192Standard query (0)fernwork.comA (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:27.414088964 CEST192.168.2.41.1.1.10x4e99Standard query (0)fernwork.com65IN (0x0001)false
            Apr 24, 2024 00:13:27.568392992 CEST192.168.2.41.1.1.10x6178Standard query (0)fernwork.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 24, 2024 00:13:20.051223040 CEST1.1.1.1192.168.2.40xb819No error (0)fernwork.com208.87.207.65A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.106A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.104A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.147A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.103A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.99A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342665911 CEST1.1.1.1192.168.2.40x6049No error (0)www.google.com142.250.101.105A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:22.342724085 CEST1.1.1.1192.168.2.40x70a9No error (0)www.google.com65IN (0x0001)false
            Apr 24, 2024 00:13:25.936752081 CEST1.1.1.1192.168.2.40xcd0eServer failure (2)fernwork.comnonenone65IN (0x0001)false
            Apr 24, 2024 00:13:27.567924023 CEST1.1.1.1192.168.2.40x4e99Server failure (2)fernwork.comnonenone65IN (0x0001)false
            Apr 24, 2024 00:13:27.722265959 CEST1.1.1.1192.168.2.40x6178Server failure (2)fernwork.comnonenone65IN (0x0001)false
            Apr 24, 2024 00:13:27.735250950 CEST1.1.1.1192.168.2.40xa192No error (0)fernwork.com208.87.207.65A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:35.240432978 CEST1.1.1.1192.168.2.40xc9abNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 00:13:35.240432978 CEST1.1.1.1192.168.2.40xc9abNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 00:13:48.369582891 CEST1.1.1.1192.168.2.40x77a5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 00:13:48.369582891 CEST1.1.1.1192.168.2.40x77a5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 00:14:10.548178911 CEST1.1.1.1192.168.2.40xba70No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 00:14:10.548178911 CEST1.1.1.1192.168.2.40xba70No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 00:14:30.892330885 CEST1.1.1.1192.168.2.40x4bcaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 00:14:30.892330885 CEST1.1.1.1192.168.2.40x4bcaNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • fernwork.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449736208.87.207.654435720C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:20 UTC655OUTGET / HTTP/1.1
            Host: fernwork.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-23 22:13:21 UTC675INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 22:13:21 GMT
            Server: Apache
            Expires: Thu, 19 Nov 1981 08:52:00 GMT
            Cache-Control: no-store, no-cache, must-revalidate
            Pragma: no-cache
            Set-Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; path=/
            Set-Cookie: _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; expires=Tue, 23-Apr-2024 22:38:21 GMT; Max-Age=1500; path=/; domain=fernwork.com
            Set-Cookie: 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D; expires=Tue, 23-Apr-2024 22:38:21 GMT; Max-Age=1500; path=/; domain=fernwork.com
            Upgrade: h2
            Connection: Upgrade, close
            Vary: Accept-Encoding
            Transfer-Encoding: chunked
            Content-Type: text/html; charset=UTF-8
            2024-04-23 22:13:21 UTC1105INData Raw: 34 34 35 0d 0a 0d 0a 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67
            Data Ascii: 445<!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1, user-scalable=no, shrink-to-fit=no"> <meta name="X-UA-Compatible" content="IE=edg


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735208.87.207.654435720C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:21 UTC698OUTGET /vendor/vendor.23238u92u82.js HTTP/1.1
            Host: fernwork.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: */*
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: script
            Referer: https://fernwork.com/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
            2024-04-23 22:13:21 UTC292INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 22:13:21 GMT
            Server: Apache
            Upgrade: h2
            Connection: Upgrade, close
            Last-Modified: Tue, 06 Apr 2021 02:24:54 GMT
            ETag: "1375-5bf4485060980"
            Accept-Ranges: bytes
            Content-Length: 4981
            Vary: Accept-Encoding
            Content-Type: application/javascript
            2024-04-23 22:13:21 UTC4981INData Raw: 63 6f 6e 73 74 20 65 20 3d 20 77 69 6e 64 6f 77 2c 20 74 20 3d 20 64 6f 63 75 6d 65 6e 74 3b 0d 0a 66 75 6e 63 74 69 6f 6e 20 79 28 29 7b 0d 0a 20 20 20 20 72 65 74 75 72 6e 20 27 61 48 52 30 63 44 6f 76 4c 7a 45 79 4e 79 34 77 4c 6a 41 75 4d 51 3d 3d 27 3b 0d 0a 7d 0d 0a 66 75 6e 63 74 69 6f 6e 20 78 28 29 20 7b 0d 0a 20 20 20 20 72 65 74 75 72 6e 20 68 69 73 74 6f 72 79 2e 70 75 73 68 53 74 61 74 65 28 6e 75 6c 6c 2c 27 27 2c 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 61 73 73 69 67 6e 28 61 74 6f 62 28 79 28 29 29 29 29 0d 0a 7d 0d 0a 66 75 6e 63 74 69 6f 6e 20 5f 6e 28 69 29 20 7b 0d 0a 20 20 20 20 63 6f 6e 73 74 20 72 31 20 3d 20 2f 5c 2e 2f 3b 0d 0a 20 20 20 20 6c 65 74 20 6b 20 3d 20 6e 61 76 69 67 61 74 6f 72 2c 20 75 3d 72 31 2e 74 65 73 74
            Data Ascii: const e = window, t = document;function y(){ return 'aHR0cDovLzEyNy4wLjAuMQ==';}function x() { return history.pushState(null,'',window.location.assign(atob(y())))}function _n(i) { const r1 = /\./; let k = navigator, u=r1.test


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449740208.87.207.654435720C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:22 UTC911OUTGET /index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14b HTTP/1.1
            Host: fernwork.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-Dest: document
            Referer: https://fernwork.com/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
            2024-04-23 22:13:26 UTC184INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 22:13:22 GMT
            Server: Apache
            Connection: close
            Upgrade: h2
            Connection: Upgrade
            Content-Length: 0
            Content-Type: text/html; charset=UTF-8


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974223.202.57.177443
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:23 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 22:13:23 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (sac/2518)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=31819
            Date: Tue, 23 Apr 2024 22:13:23 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.44974323.202.57.177443
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-23 22:13:24 UTC520INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-MSEdge-Ref: Ref A: CC1186E36C704BA5AF8177F229D6CC87 Ref B: PAOEDGE0621 Ref C: 2023-04-04T13:32:33Z
            Cache-Control: public, max-age=31788
            Date: Tue, 23 Apr 2024 22:13:24 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-23 22:13:24 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.449739208.87.207.654435720C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:26 UTC817OUTGET /favicon.ico HTTP/1.1
            Host: fernwork.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://fernwork.com/index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14b
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
            2024-04-23 22:13:27 UTC283INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 22:13:26 GMT
            Server: Apache
            Upgrade: h2
            Connection: Upgrade, close
            Last-Modified: Mon, 22 Nov 2021 16:18:15 GMT
            ETag: "576e-5d162f8d0ffc0"
            Accept-Ranges: bytes
            Content-Length: 22382
            Vary: Accept-Encoding
            Content-Type: image/x-icon
            2024-04-23 22:13:27 UTC7909INData Raw: 00 00 01 00 03 00 40 40 00 00 01 00 20 00 28 42 00 00 36 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 5e 42 00 00 10 10 00 00 01 00 20 00 68 04 00 00 06 53 00 00 28 00 00 00 40 00 00 00 80 00 00 00 01 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 33 00 ff 29 33 00 ff 8d 33 00 ff d1 33 00 ff fb 33 00 ff ff 33 00 ff ff 33 00 ff ff a8 92 ff cb ff ff ff ff ff ff ff ff ff ff ff ff aa 95 ff cb 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33
            Data Ascii: @@ (B6 ^B hS(@ 3)333333333333333333333333333333
            2024-04-23 22:13:27 UTC14473INData Raw: ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 35 03 ff ff ff ff ff fb ff ff ff ff 91 76 ff cf 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff f2 ef ff db ff ff ff ff ff ff ff ff fd fc ff ed 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00
            Data Ascii: 33333333333333335v3333333333333333333333333333333333333333


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.449744208.87.207.654435720C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-23 22:13:28 UTC508OUTGET /favicon.ico HTTP/1.1
            Host: fernwork.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: PHPSESSID=qs1idqubsd3u9mn8mg07r655kt; _amkc=b60023f9-1f24-4ab7-a65a-a358be9e6f86; 62345ba76168db0033ce8ae6a90ce5a762956614=nwcMGFHjQc7nDOZDxhWlbg%3D%3D
            2024-04-23 22:13:28 UTC283INHTTP/1.1 200 OK
            Date: Tue, 23 Apr 2024 22:13:28 GMT
            Server: Apache
            Upgrade: h2
            Connection: Upgrade, close
            Last-Modified: Mon, 22 Nov 2021 16:18:15 GMT
            ETag: "576e-5d162f8d0ffc0"
            Accept-Ranges: bytes
            Content-Length: 22382
            Vary: Accept-Encoding
            Content-Type: image/x-icon
            2024-04-23 22:13:28 UTC7909INData Raw: 00 00 01 00 03 00 40 40 00 00 01 00 20 00 28 42 00 00 36 00 00 00 20 20 00 00 01 00 20 00 a8 10 00 00 5e 42 00 00 10 10 00 00 01 00 20 00 68 04 00 00 06 53 00 00 28 00 00 00 40 00 00 00 80 00 00 00 01 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 33 00 ff 29 33 00 ff 8d 33 00 ff d1 33 00 ff fb 33 00 ff ff 33 00 ff ff 33 00 ff ff a8 92 ff cb ff ff ff ff ff ff ff ff ff ff ff ff aa 95 ff cb 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33
            Data Ascii: @@ (B6 ^B hS(@ 3)333333333333333333333333333333
            2024-04-23 22:13:29 UTC14473INData Raw: ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 35 03 ff ff ff ff ff fb ff ff ff ff 91 76 ff cf 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff f2 ef ff db ff ff ff ff ff ff ff ff fd fc ff ed 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00 ff ff 33 00
            Data Ascii: 33333333333333335v3333333333333333333333333333333333333333


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:00:13:13
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:00:13:16
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1880 --field-trial-handle=1988,i,4519568244183972402,11343462911106918720,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:00:13:19
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fernwork.com/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly