Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://welcome.visionaryyouth.org

Overview

General Information

Sample URL:http://welcome.visionaryyouth.org
Analysis ID:1431849
Infos:

Detection

Score:80
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic

Classification

  • System is w10x64
  • chrome.exe (PID: 4520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6048 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2792 --field-trial-handle=2228,i,4122967588436644115,14582160470057251167,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6480 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://welcome.visionaryyouth.org" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:04/25/24-21:39:30.423909
SID:2051635
Source Port:49744
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/25/24-21:39:22.842621
SID:2051634
Source Port:57284
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/25/24-21:39:22.842790
SID:2051634
Source Port:64175
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/25/24-21:39:23.569292
SID:2051635
Source Port:49738
Destination Port:443
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:04/25/24-21:39:23.278850
SID:2051634
Source Port:62520
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:04/25/24-21:39:23.278850
SID:2051634
Source Port:63627
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://welcome.visionaryyouth.orgAvira URL Cloud: detection malicious, Label: malware
Source: https://welcome.visionaryyouth.org/favicon.icoAvira URL Cloud: Label: malware
Source: http://welcome.visionaryyouth.org/Avira URL Cloud: Label: malware
Source: http://welcome.visionaryyouth.org/Virustotal: Detection: 15%Perma Link
Source: http://welcome.visionaryyouth.orgVirustotal: Detection: 15%Perma Link
Source: https://welcome.visionaryyouth.org/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2051634 ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org) 192.168.2.4:57284 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051634 ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org) 192.168.2.4:64175 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051634 ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org) 192.168.2.4:62520 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051634 ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org) 192.168.2.4:63627 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2051635 ET TROJAN SocGholish Domain in TLS SNI (welcome .visionaryyouth .org) 192.168.2.4:49738 -> 88.119.175.92:443
Source: TrafficSnort IDS: 2051635 ET TROJAN SocGholish Domain in TLS SNI (welcome .visionaryyouth .org) 192.168.2.4:49744 -> 88.119.175.92:443
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: welcome.visionaryyouth.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: welcome.visionaryyouth.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://welcome.visionaryyouth.org/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: welcome.visionaryyouth.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: welcome.visionaryyouth.org
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Apr 2024 19:39:30 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal80.win@17/2@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2792 --field-trial-handle=2228,i,4122967588436644115,14582160470057251167,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://welcome.visionaryyouth.org"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2792 --field-trial-handle=2228,i,4122967588436644115,14582160470057251167,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://welcome.visionaryyouth.org15%VirustotalBrowse
http://welcome.visionaryyouth.org100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://welcome.visionaryyouth.org/favicon.ico100%Avira URL Cloudmalware
http://welcome.visionaryyouth.org/100%Avira URL Cloudmalware
http://welcome.visionaryyouth.org/15%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
108.177.122.147
truefalse
    high
    welcome.visionaryyouth.org
    88.119.175.92
    truetrue
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://welcome.visionaryyouth.org/true
        • 15%, Virustotal, Browse
        • Avira URL Cloud: malware
        unknown
        https://welcome.visionaryyouth.org/favicon.icotrue
        • Avira URL Cloud: malware
        unknown
        https://welcome.visionaryyouth.org/false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.9.104
          unknownUnited States
          15169GOOGLEUSfalse
          108.177.122.147
          www.google.comUnited States
          15169GOOGLEUSfalse
          88.119.175.92
          welcome.visionaryyouth.orgLithuania
          61272IST-ASLTtrue
          IP
          192.168.2.4
          192.168.2.5
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1431849
          Start date and time:2024-04-25 21:38:30 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 17s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://welcome.visionaryyouth.org
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal80.win@17/2@8/6
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 74.125.138.94, 172.253.124.102, 172.253.124.113, 172.253.124.139, 172.253.124.101, 172.253.124.138, 172.253.124.100, 172.253.124.84, 34.104.35.123, 40.68.123.157, 23.40.205.67, 23.40.205.56, 23.40.205.64, 23.40.205.65, 23.40.205.9, 23.40.205.81, 23.40.205.73, 23.40.205.43, 23.40.205.74, 192.229.211.108, 13.85.23.206, 20.242.39.171, 64.233.177.94
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):203
          Entropy (8bit):5.139523437629011
          Encrypted:false
          SSDEEP:6:pn0+t9xqObRKr6TQzetSzRx3G0CezowoG:J0+t9xqeRKWTQzetSzRxGezn
          MD5:A368EBDB8002FBB3142E16BC34B326D8
          SHA1:E727C702FB6BE3CBEFA0B0847717B2334CE9B8FD
          SHA-256:7BB4BE9184710E7D3067CE155A3F8E37C248BDF649906EA40AF66A324ACE61A4
          SHA-512:2550B4B0040F566D106E24E8180DE41225FEDA5B82C68A31BC7DBCF422B6751CC1701CD3F1CC51A7FFDBD57FDCDCCABF1F3B6444AFDA681221F8E6F734C40DAD
          Malicious:false
          Reputation:low
          URL:https://welcome.visionaryyouth.org/
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">..<html><head>..<title>404 Not Found</title>..</head><body>..<h1>Not Found</h1>..<p>The requested URL was not found on this server.</p>..</body></html>..
          No static file info
          TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
          04/25/24-21:39:30.423909TCP2051635ET TROJAN SocGholish Domain in TLS SNI (welcome .visionaryyouth .org)49744443192.168.2.488.119.175.92
          04/25/24-21:39:22.842621UDP2051634ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org)5728453192.168.2.41.1.1.1
          04/25/24-21:39:22.842790UDP2051634ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org)6417553192.168.2.41.1.1.1
          04/25/24-21:39:23.569292TCP2051635ET TROJAN SocGholish Domain in TLS SNI (welcome .visionaryyouth .org)49738443192.168.2.488.119.175.92
          04/25/24-21:39:23.278850UDP2051634ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org)6252053192.168.2.41.1.1.1
          04/25/24-21:39:23.278850UDP2051634ET TROJAN SocGholish Domain in DNS Lookup (welcome .visionaryyouth .org)6362753192.168.2.41.1.1.1
          TimestampSource PortDest PortSource IPDest IP
          Apr 25, 2024 21:39:12.537827015 CEST49678443192.168.2.4104.46.162.224
          Apr 25, 2024 21:39:14.772008896 CEST49675443192.168.2.4173.222.162.32
          Apr 25, 2024 21:39:23.023734093 CEST4973580192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.023739100 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.116908073 CEST4973780192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.149777889 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.149938107 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.150203943 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.150670052 CEST804973588.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.150785923 CEST4973580192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.241990089 CEST804973788.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.242185116 CEST4973780192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.275188923 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.275207996 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.320184946 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.568600893 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.568650961 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.569030046 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.569292068 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.569308043 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.959695101 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.960181952 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.960201025 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.961220980 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.961498022 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.962564945 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:23.962630033 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:23.962682962 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:24.004142046 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:24.051220894 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:24.051248074 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:24.097193956 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:24.380079985 CEST49675443192.168.2.4173.222.162.32
          Apr 25, 2024 21:39:24.904273987 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:24.904316902 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:24.904381037 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:24.904934883 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:24.904948950 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.138946056 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.139446974 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:25.139456987 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.141189098 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.141253948 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:25.143532991 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:25.143641949 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.184649944 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:25.184664965 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:25.226314068 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:25.931649923 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:25.931696892 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:25.932432890 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:25.934091091 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:25.934118986 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.173039913 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.173238039 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.181070089 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.181109905 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.181468010 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.224751949 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.311345100 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.352128029 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.421794891 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.421881914 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.422044039 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.422158957 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.422158957 CEST49742443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.422179937 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.422187090 CEST44349742184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.497056961 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.497097969 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.501367092 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.505044937 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.505057096 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.735151052 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.735239029 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.738368034 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.738374949 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.738703012 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.745280981 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.788121939 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.951301098 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.951392889 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.951452017 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.960663080 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.960675955 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:26.960686922 CEST49743443192.168.2.4184.31.62.93
          Apr 25, 2024 21:39:26.960691929 CEST44349743184.31.62.93192.168.2.4
          Apr 25, 2024 21:39:30.261305094 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.261431932 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.261550903 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.279922962 CEST49738443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.279946089 CEST4434973888.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.423475027 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.423588991 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.423676014 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.423908949 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.423959970 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.680025101 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.680401087 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.680480003 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.680811882 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.681209087 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.681288958 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.681435108 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.724126101 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.974117041 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.974199057 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:30.974318981 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.974711895 CEST49744443192.168.2.488.119.175.92
          Apr 25, 2024 21:39:30.974755049 CEST4434974488.119.175.92192.168.2.4
          Apr 25, 2024 21:39:35.137538910 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:35.137605906 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:39:35.137681007 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:35.620007038 CEST49741443192.168.2.4108.177.122.147
          Apr 25, 2024 21:39:35.620037079 CEST44349741108.177.122.147192.168.2.4
          Apr 25, 2024 21:40:08.162440062 CEST4973580192.168.2.488.119.175.92
          Apr 25, 2024 21:40:08.256158113 CEST4973780192.168.2.488.119.175.92
          Apr 25, 2024 21:40:08.287571907 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:40:08.289556026 CEST804973588.119.175.92192.168.2.4
          Apr 25, 2024 21:40:08.381378889 CEST804973788.119.175.92192.168.2.4
          Apr 25, 2024 21:40:08.412540913 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:40:23.278245926 CEST804973588.119.175.92192.168.2.4
          Apr 25, 2024 21:40:23.278321028 CEST4973580192.168.2.488.119.175.92
          Apr 25, 2024 21:40:23.367368937 CEST804973788.119.175.92192.168.2.4
          Apr 25, 2024 21:40:23.367438078 CEST4973780192.168.2.488.119.175.92
          Apr 25, 2024 21:40:23.617017031 CEST4973580192.168.2.488.119.175.92
          Apr 25, 2024 21:40:23.617053986 CEST4973780192.168.2.488.119.175.92
          Apr 25, 2024 21:40:23.742059946 CEST804973788.119.175.92192.168.2.4
          Apr 25, 2024 21:40:23.744112015 CEST804973588.119.175.92192.168.2.4
          Apr 25, 2024 21:40:25.503856897 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:25.503942013 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.504013062 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:25.504303932 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:25.504357100 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.729252100 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.730549097 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:25.730578899 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.731062889 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.767647028 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:25.768055916 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:25.818218946 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:28.275573969 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:40:28.275679111 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:40:29.616797924 CEST4973680192.168.2.488.119.175.92
          Apr 25, 2024 21:40:29.741745949 CEST804973688.119.175.92192.168.2.4
          Apr 25, 2024 21:40:31.490355015 CEST4972480192.168.2.4199.232.214.172
          Apr 25, 2024 21:40:31.490470886 CEST4972380192.168.2.4199.232.214.172
          Apr 25, 2024 21:40:31.599601030 CEST8049724199.232.214.172192.168.2.4
          Apr 25, 2024 21:40:31.599715948 CEST8049723199.232.214.172192.168.2.4
          Apr 25, 2024 21:40:31.600023985 CEST8049723199.232.214.172192.168.2.4
          Apr 25, 2024 21:40:31.600037098 CEST8049724199.232.214.172192.168.2.4
          Apr 25, 2024 21:40:31.600096941 CEST4972380192.168.2.4199.232.214.172
          Apr 25, 2024 21:40:31.600122929 CEST4972480192.168.2.4199.232.214.172
          Apr 25, 2024 21:40:35.773550987 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:35.773627996 CEST44349754142.250.9.104192.168.2.4
          Apr 25, 2024 21:40:35.773737907 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:37.617240906 CEST49754443192.168.2.4142.250.9.104
          Apr 25, 2024 21:40:37.617331028 CEST44349754142.250.9.104192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Apr 25, 2024 21:39:21.513135910 CEST53591901.1.1.1192.168.2.4
          Apr 25, 2024 21:39:21.529330015 CEST53530301.1.1.1192.168.2.4
          Apr 25, 2024 21:39:22.155507088 CEST53600111.1.1.1192.168.2.4
          Apr 25, 2024 21:39:22.842621088 CEST5728453192.168.2.41.1.1.1
          Apr 25, 2024 21:39:22.842789888 CEST6417553192.168.2.41.1.1.1
          Apr 25, 2024 21:39:22.986695051 CEST53572841.1.1.1192.168.2.4
          Apr 25, 2024 21:39:23.132777929 CEST53641751.1.1.1192.168.2.4
          Apr 25, 2024 21:39:23.278850079 CEST6252053192.168.2.41.1.1.1
          Apr 25, 2024 21:39:23.278850079 CEST6362753192.168.2.41.1.1.1
          Apr 25, 2024 21:39:23.567315102 CEST53625201.1.1.1192.168.2.4
          Apr 25, 2024 21:39:23.568169117 CEST53636271.1.1.1192.168.2.4
          Apr 25, 2024 21:39:24.790098906 CEST5715253192.168.2.41.1.1.1
          Apr 25, 2024 21:39:24.790410042 CEST6165553192.168.2.41.1.1.1
          Apr 25, 2024 21:39:24.900222063 CEST53571521.1.1.1192.168.2.4
          Apr 25, 2024 21:39:24.900571108 CEST53616551.1.1.1192.168.2.4
          Apr 25, 2024 21:39:39.470323086 CEST53635611.1.1.1192.168.2.4
          Apr 25, 2024 21:39:43.065637112 CEST138138192.168.2.4192.168.2.255
          Apr 25, 2024 21:39:58.304508924 CEST53536821.1.1.1192.168.2.4
          Apr 25, 2024 21:40:20.468826056 CEST53576491.1.1.1192.168.2.4
          Apr 25, 2024 21:40:20.930331945 CEST53528891.1.1.1192.168.2.4
          Apr 25, 2024 21:40:25.390552044 CEST5362953192.168.2.41.1.1.1
          Apr 25, 2024 21:40:25.390886068 CEST5239653192.168.2.41.1.1.1
          Apr 25, 2024 21:40:25.500881910 CEST53523961.1.1.1192.168.2.4
          Apr 25, 2024 21:40:25.502176046 CEST53536291.1.1.1192.168.2.4
          TimestampSource IPDest IPChecksumCodeType
          Apr 25, 2024 21:39:23.132987976 CEST192.168.2.41.1.1.1c252(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 25, 2024 21:39:22.842621088 CEST192.168.2.41.1.1.10xfb8fStandard query (0)welcome.visionaryyouth.orgA (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:22.842789888 CEST192.168.2.41.1.1.10x595aStandard query (0)welcome.visionaryyouth.org65IN (0x0001)false
          Apr 25, 2024 21:39:23.278850079 CEST192.168.2.41.1.1.10x2307Standard query (0)welcome.visionaryyouth.orgA (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:23.278850079 CEST192.168.2.41.1.1.10x58dStandard query (0)welcome.visionaryyouth.org65IN (0x0001)false
          Apr 25, 2024 21:39:24.790098906 CEST192.168.2.41.1.1.10xe1bcStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.790410042 CEST192.168.2.41.1.1.10xeb62Standard query (0)www.google.com65IN (0x0001)false
          Apr 25, 2024 21:40:25.390552044 CEST192.168.2.41.1.1.10x3c8fStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.390886068 CEST192.168.2.41.1.1.10x44e2Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 25, 2024 21:39:22.986695051 CEST1.1.1.1192.168.2.40xfb8fNo error (0)welcome.visionaryyouth.org88.119.175.92A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:23.567315102 CEST1.1.1.1192.168.2.40x2307No error (0)welcome.visionaryyouth.org88.119.175.92A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.147A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.104A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.103A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.99A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.106A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900222063 CEST1.1.1.1192.168.2.40xe1bcNo error (0)www.google.com108.177.122.105A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:24.900571108 CEST1.1.1.1192.168.2.40xeb62No error (0)www.google.com65IN (0x0001)false
          Apr 25, 2024 21:39:37.657483101 CEST1.1.1.1192.168.2.40xba79No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 25, 2024 21:39:37.657483101 CEST1.1.1.1192.168.2.40xba79No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 25, 2024 21:39:50.648263931 CEST1.1.1.1192.168.2.40x8ca0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 25, 2024 21:39:50.648263931 CEST1.1.1.1192.168.2.40x8ca0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:13.383357048 CEST1.1.1.1192.168.2.40x1b1aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 25, 2024 21:40:13.383357048 CEST1.1.1.1192.168.2.40x1b1aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.500881910 CEST1.1.1.1192.168.2.40x44e2No error (0)www.google.com65IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.104A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.147A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.103A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.99A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.105A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:25.502176046 CEST1.1.1.1192.168.2.40x3c8fNo error (0)www.google.com142.250.9.106A (IP address)IN (0x0001)false
          Apr 25, 2024 21:40:33.226362944 CEST1.1.1.1192.168.2.40x6db9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 25, 2024 21:40:33.226362944 CEST1.1.1.1192.168.2.40x6db9No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • welcome.visionaryyouth.org
          • fs.microsoft.com
          • https:
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44973688.119.175.92806048C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 25, 2024 21:39:23.150203943 CEST441OUTGET / HTTP/1.1
          Host: welcome.visionaryyouth.org
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Apr 25, 2024 21:39:23.275207996 CEST365INHTTP/1.1 301 Moved Permanently
          Server: nginx
          Date: Thu, 25 Apr 2024 19:39:23 GMT
          Content-Type: text/html
          Content-Length: 162
          Connection: keep-alive
          Location: https://welcome.visionaryyouth.org/
          Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
          Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
          Apr 25, 2024 21:40:08.287571907 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44973588.119.175.92806048C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 25, 2024 21:40:08.162440062 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.44973788.119.175.92806048C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 25, 2024 21:40:08.256158113 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44973888.119.175.924436048C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-04-25 19:39:23 UTC669OUTGET / HTTP/1.1
          Host: welcome.visionaryyouth.org
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-04-25 19:39:30 UTC165INHTTP/1.1 404 Not Found
          Server: nginx
          Date: Thu, 25 Apr 2024 19:39:30 GMT
          Content-Type: text/html; charset=UTF-8
          Transfer-Encoding: chunked
          Connection: close
          2024-04-25 19:39:30 UTC209INData Raw: 63 62 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a
          Data Ascii: cb<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>
          2024-04-25 19:39:30 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.449742184.31.62.93443
          TimestampBytes transferredDirectionData
          2024-04-25 19:39:26 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-25 19:39:26 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0790)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=127449
          Date: Thu, 25 Apr 2024 19:39:26 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.449743184.31.62.93443
          TimestampBytes transferredDirectionData
          2024-04-25 19:39:26 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-25 19:39:26 UTC515INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/0758)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus-z1
          Cache-Control: public, max-age=127449
          Date: Thu, 25 Apr 2024 19:39:26 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-25 19:39:26 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.44974488.119.175.924436048C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-04-25 19:39:30 UTC608OUTGET /favicon.ico HTTP/1.1
          Host: welcome.visionaryyouth.org
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://welcome.visionaryyouth.org/
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-04-25 19:39:30 UTC98INHTTP/1.1 204 No Content
          Server: nginx
          Date: Thu, 25 Apr 2024 19:39:30 GMT
          Connection: close


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:21:39:17
          Start date:25/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:21:39:19
          Start date:25/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2792 --field-trial-handle=2228,i,4122967588436644115,14582160470057251167,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:21:39:22
          Start date:25/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://welcome.visionaryyouth.org"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly