Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://alumnoeseit.edu.co

Overview

General Information

Sample URL:http://alumnoeseit.edu.co
Analysis ID:1432182
Infos:
Errors
  • URL not reachable

Detection

Score:20
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Found suspicious QR code URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 1988 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,13037938025454584876,2762468571744981583,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3208 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:/// MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4024 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2000,i,16255536715985720032,13152113976248923233,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://alumnoeseit.edu.co" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: QR Code extractorURL: http://
Source: QR Code extractorURL: http://
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGMb4rrEGIjB_Hl3xkuM2buIj_fhZuZvubLNwP7UPnD01lIboCe2qlBky6GyoOQIiFSytb4PKZwYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-26-14; NID=513=Mk6dmwXYcJkGS-1yRrpGTUKOG2b-tR52ZaNCRN4MEZAVrf9xukJ-J-l-Fsmm05f8f_ksBOdM8C7aZlr62QRmnevD5nXHKKhYGIAfNJ9DpBcaTmlTx2XKsbwuVUYky1QPOVnR0tl3ZgSC1chYD_vhb8gEigiDhVgwOwk2aBbayWA
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGMb4rrEGIjAG6d2Oed0kzoNdKwq2lS3p7cXT2GZOIIZfVi9CInLDS2liYGXYv-2-moOfJvpI_dsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-26-14; NID=513=M_aMdvzOviEndbSgRdFy0MOnf9QSJZf1AiMkyWeeK0arZ-tQ07E6D-eqB8Ln8eFMt5fdGdhYYzTL2y9_SwzdANfr7PycOmHXZcv0yV6sXIvgiEWTR0sStblstNYNYklVjY-CDyxx3Anoj1ntkdyXGCrftK1gKGD_I6-K2ABzp1I
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: alumnoeseit.edu.co
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: classification engineClassification label: sus20.phis.win@26/8@12/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,13037938025454584876,2762468571744981583,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2000,i,16255536715985720032,13152113976248923233,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://alumnoeseit.edu.co"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,13037938025454584876,2762468571744981583,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2000,i,16255536715985720032,13152113976248923233,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1432182 URL: http://alumnoeseit.edu.co Startdate: 26/04/2024 Architecture: WINDOWS Score: 20 19 alumnoeseit.edu.co 2->19 31 Found suspicious QR code URL 2->31 7 chrome.exe 8 2->7         started        10 chrome.exe 2->10         started        12 chrome.exe 2->12         started        signatures3 process4 dnsIp5 21 192.168.2.5, 443, 49342, 49703 unknown unknown 7->21 23 239.255.255.250 unknown Reserved 7->23 14 chrome.exe 7->14         started        17 chrome.exe 10->17         started        process6 dnsIp7 25 www.google.com 142.250.64.196, 443, 49707, 49708 GOOGLEUS United States 14->25 27 google.com 14->27 29 alumnoeseit.edu.co 14->29

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://alumnoeseit.edu.co0%Avira URL Cloudsafe
http://alumnoeseit.edu.co0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
alumnoeseit.edu.co0%VirustotalBrowse
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.165.206
truefalse
    high
    edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
    162.222.107.20
    truefalseunknown
    www.google.com
    142.250.64.196
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalseunknown
      alumnoeseit.edu.co
      unknown
      unknownfalseunknown
      NameMaliciousAntivirus DetectionReputation
      https://www.google.com/async/newtab_promosfalse
        high
        https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
          high
          https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0false
            high
            https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGMb4rrEGIjB_Hl3xkuM2buIj_fhZuZvubLNwP7UPnD01lIboCe2qlBky6GyoOQIiFSytb4PKZwYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
              high
              https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGMb4rrEGIjAG6d2Oed0kzoNdKwq2lS3p7cXT2GZOIIZfVi9CInLDS2liYGXYv-2-moOfJvpI_dsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.64.196
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                IP
                192.168.2.5
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1432182
                Start date and time:2024-04-26 16:37:05 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 25s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://alumnoeseit.edu.co
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:9
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:SUS
                Classification:sus20.phis.win@26/8@12/3
                Cookbook Comments:
                • URL browsing timeout or error
                • URL not reachable
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.189.131, 142.251.107.84, 142.250.64.206, 34.104.35.123, 23.204.76.112, 13.85.23.86, 162.222.107.20, 192.229.211.108, 20.242.39.171
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                SourceURL
                Screenshothttp://
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 13:38:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.975137693041391
                Encrypted:false
                SSDEEP:48:8ddrTzTzHPidAKZdA19ehwiZUklqehly+3:87r1qy
                MD5:BF03CF7F188181A793F4F6341686004F
                SHA1:3C65C6A691513F93E826038702D7DF9EE5C2471C
                SHA-256:5BC10CE4A54933A9DD6BD3F28B1B4DD12E951A0F9D751A7BBC192FEBF35DD41B
                SHA-512:50AF4F6432FC86737B4B4832E30001C5BD6FCC66057FB98014CB520ACA28293390667E626827E30E58F26A01EC7DCC23C386C2C856696BAF41C5690205F821C3
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......sV...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 13:37:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):3.9922660628269107
                Encrypted:false
                SSDEEP:48:8jdrTzTzHPidAKZdA1weh/iZUkAQkqehay+2:8xrv9Qny
                MD5:4BE140665D91E7BA77E515A20DA0FE82
                SHA1:3CDC144047FABC461BA925010A9D20C5EBDF54C9
                SHA-256:7A73576D23AC72480D12DC116C0C6D35FB0FE4BE6854F90CAFDFFC270C1D412B
                SHA-512:42F525BA0721EBE10FC3649AF352AABD34A458B56A6D580680640D3CB97E527BAB67E79377F2C3B0073989F303C04CAD36150900853B6AF8E1AD75ED41A63314
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....(.vU...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2693
                Entropy (8bit):4.001295457018038
                Encrypted:false
                SSDEEP:48:8xsdrTzTsHPidAKZdA14tseh7sFiZUkmgqeh7sMy+BX:8x8rKnmy
                MD5:E843FD59C8B70284E7933110BF606E5D
                SHA1:1EE952EE83DF8CAE3DBA93E06C50B30A780BEE24
                SHA-256:CDE9329D2E2D66DC5A27BA3F4534425A73142923D1D1577C018CA40F8032D9BC
                SHA-512:3E71B65F77E81213C1A09C6343B26D640229F27BDD282EAA1EC6768DFD6495185701F39FF342FA359A1C8022CA5D13B32797BCD9CFCCE0675F1E8C80E23E1AEF
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 13:37:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.9884779600547096
                Encrypted:false
                SSDEEP:48:8KdrTzTzHPidAKZdA1vehDiZUkwqehey+R:86rMky
                MD5:8A9526200ADDCD10CEC2F250E561A7FA
                SHA1:AB0A6A63B824DA733967D633D83775E02CE1C098
                SHA-256:1CA6654A9E971D35285147245F1ED022D2802CFAE08689227C42A805E4A5A3EF
                SHA-512:75B330669267126D28F3AD03D2CE50B81AE0CED90D11C367C8EBC36D3F00E132FE2184453E2D5ACF761AA28115368320B9D6917AC6C307AB525BB3C5BFD96AFD
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....fKU...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 13:38:00 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.9782685295027513
                Encrypted:false
                SSDEEP:48:80drTzTzHPidAKZdA1hehBiZUk1W1qehoy+C:8kr89Iy
                MD5:34DDE5B64826DC137777E3376D8133FD
                SHA1:A52BA187BB8E6046841C554BEC1F96FEC27CEF6B
                SHA-256:0FA7D60BABC01B4751A9896548C4A28CDD276CD275A1E4AEF8670E64772BD1A4
                SHA-512:6DE4293314E82926085C96D6DA5A970D46DB0C479343D0ADDF349A2463230C8B802E7BD791207C01E6BE4F1223152DBBE8525873129695BC5C96AD9D56510729
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....ZV...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 13:37:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2683
                Entropy (8bit):3.990288757560389
                Encrypted:false
                SSDEEP:48:85drTzTzHPidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbmy+yT+:8/rST/TbxWOvTbmy7T
                MD5:2C0BC20DA39DB97762F7DD4DE2B13DF6
                SHA1:A907E41F469EBBCC7A1165D4036DBC2D5D37F6BB
                SHA-256:07B4C7A939062982D6876A126955044CA15015AD945F57C317319839E9786F75
                SHA-512:2E8C21AD785000181C56B6C443EF3963C3CEB10359B94448C1B862B6EE73DA865EDEA0D4EC051D4D34FBA820B8BA86D2E5907964EFA6B51732D415DF651CF65A
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....<.AU...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X.t....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........i.y.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (788)
                Category:downloaded
                Size (bytes):793
                Entropy (8bit):5.128709918023649
                Encrypted:false
                SSDEEP:24:IHgqG1RWzBFh0UvwBHslgT9lCuABuoB7HHHHHHHYqmffffffo:IHgDRWOjKlgZ01BuSEqmffffffo
                MD5:86C3141301EF9A121C23C5B537615580
                SHA1:59C19487A8C6B485BE24017FE3CF468FFE7CCC2E
                SHA-256:258BEC6F09080FC705F3722A10616B4BCB69B905E386D61BA9B87EEBF6C214CB
                SHA-512:4BE1B870A000F431927E24CAF67ED09E79F0B9C51F18AD71395D82815A8CCCB1B7F6629329E569A3AC2750C475FD3A509906B7A3DE073DF30410FB3A9C5488AD
                Malicious:false
                Reputation:low
                URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                Preview:)]}'.["",["american horror story delicate ending","alphabet stock earnings","derby horses","apple iphone 16 pro max","weather storms tornadoes","netflix mindhunter season 3","household cavalry horses london","home depot halloween skeleton dog"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 26, 2024 16:37:49.843332052 CEST49674443192.168.2.523.1.237.91
                Apr 26, 2024 16:37:49.843689919 CEST49675443192.168.2.523.1.237.91
                Apr 26, 2024 16:37:49.952708960 CEST49673443192.168.2.523.1.237.91
                Apr 26, 2024 16:37:57.618056059 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.618122101 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.618196011 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.618446112 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.618467093 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.653126001 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.653218985 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.653280973 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.653676033 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.653707027 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.747669935 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.747709990 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.747770071 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.748009920 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.748016119 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.822509050 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.822563887 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.822652102 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.823365927 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.823396921 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.996586084 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:57.998717070 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:57.998760939 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.000417948 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.000566959 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.012931108 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.014058113 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.014244080 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.014260054 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.014288902 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.014676094 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.014699936 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.018230915 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.018383980 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.018815994 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.018815994 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.018990040 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.088855982 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.088860035 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.088892937 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.088898897 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.143389940 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.144918919 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.144932985 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.146348000 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.146466017 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.147856951 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.147857904 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.147937059 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.158895016 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.159396887 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.159415007 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.162972927 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.163079977 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.164174080 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.164263964 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.281999111 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.282006979 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.282007933 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.282035112 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.297513962 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.297523022 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.356683016 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.356825113 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.358325005 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.358355045 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.359880924 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.360238075 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.360238075 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.407025099 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.485169888 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.690536022 CEST49708443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.690598965 CEST44349708142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.783010006 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.783132076 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.783175945 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.783366919 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.783890963 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.783926010 CEST44349707142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.783956051 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.783956051 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.784219980 CEST49707443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.785924911 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.828140974 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.840044022 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.840122938 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.840213060 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.840362072 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.840414047 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.841109037 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.841126919 CEST44349709142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.841167927 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.841167927 CEST49709443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.843487978 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.843518972 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.843574047 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.843930006 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.843943119 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.956712008 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.956854105 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.956901073 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:58.956917048 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.957161903 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:58.957211971 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.001355886 CEST49710443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.001394033 CEST44349710142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.171868086 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.222099066 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.242815018 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.242829084 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.243201971 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.243994951 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.244055033 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.244127035 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.292121887 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.456433058 CEST49675443192.168.2.523.1.237.91
                Apr 26, 2024 16:37:59.487662077 CEST49674443192.168.2.523.1.237.91
                Apr 26, 2024 16:37:59.503963947 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504002094 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504040956 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504049063 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.504065037 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504105091 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.504112959 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504122019 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:37:59.504163980 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:37:59.565808058 CEST49673443192.168.2.523.1.237.91
                Apr 26, 2024 16:38:01.074110985 CEST4434970323.1.237.91192.168.2.5
                Apr 26, 2024 16:38:01.074217081 CEST49703443192.168.2.523.1.237.91
                Apr 26, 2024 16:38:01.162794113 CEST49713443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.162864923 CEST44349713142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.175142050 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.175214052 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.175286055 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.175882101 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.175915956 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.563616991 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.565207005 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.565268040 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.565571070 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.566972017 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:01.567042112 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:01.704224110 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:11.552628040 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:11.552700996 CEST44349715142.250.64.196192.168.2.5
                Apr 26, 2024 16:38:11.552799940 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:12.082343102 CEST49715443192.168.2.5142.250.64.196
                Apr 26, 2024 16:38:12.082359076 CEST44349715142.250.64.196192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Apr 26, 2024 16:37:56.956554890 CEST53526431.1.1.1192.168.2.5
                Apr 26, 2024 16:37:57.015712976 CEST53564111.1.1.1192.168.2.5
                Apr 26, 2024 16:37:57.491297007 CEST5682753192.168.2.51.1.1.1
                Apr 26, 2024 16:37:57.491491079 CEST6536553192.168.2.51.1.1.1
                Apr 26, 2024 16:37:57.616935968 CEST53653651.1.1.1192.168.2.5
                Apr 26, 2024 16:37:57.616998911 CEST53568271.1.1.1192.168.2.5
                Apr 26, 2024 16:37:58.021039009 CEST53570131.1.1.1192.168.2.5
                Apr 26, 2024 16:38:18.676280975 CEST53609721.1.1.1192.168.2.5
                Apr 26, 2024 16:38:24.742835999 CEST5428253192.168.2.51.1.1.1
                Apr 26, 2024 16:38:24.743108034 CEST5868253192.168.2.51.1.1.1
                Apr 26, 2024 16:38:25.402277946 CEST53542821.1.1.1192.168.2.5
                Apr 26, 2024 16:38:25.407412052 CEST53586821.1.1.1192.168.2.5
                Apr 26, 2024 16:38:25.409138918 CEST5554353192.168.2.51.1.1.1
                Apr 26, 2024 16:38:26.069204092 CEST53555431.1.1.1192.168.2.5
                Apr 26, 2024 16:38:26.148566961 CEST5008053192.168.2.58.8.8.8
                Apr 26, 2024 16:38:26.148871899 CEST4934253192.168.2.51.1.1.1
                Apr 26, 2024 16:38:26.274610043 CEST53493421.1.1.1192.168.2.5
                Apr 26, 2024 16:38:26.313397884 CEST53500808.8.8.8192.168.2.5
                Apr 26, 2024 16:38:28.908561945 CEST5002353192.168.2.51.1.1.1
                Apr 26, 2024 16:38:28.909070015 CEST5114453192.168.2.51.1.1.1
                Apr 26, 2024 16:38:29.169610023 CEST53500231.1.1.1192.168.2.5
                Apr 26, 2024 16:38:29.573101044 CEST53511441.1.1.1192.168.2.5
                Apr 26, 2024 16:38:34.240283966 CEST5796653192.168.2.51.1.1.1
                Apr 26, 2024 16:38:34.240284920 CEST5883153192.168.2.51.1.1.1
                Apr 26, 2024 16:38:34.499831915 CEST53579661.1.1.1192.168.2.5
                Apr 26, 2024 16:38:34.501090050 CEST53588311.1.1.1192.168.2.5
                Apr 26, 2024 16:38:34.501971960 CEST5320653192.168.2.51.1.1.1
                Apr 26, 2024 16:38:34.631148100 CEST53532061.1.1.1192.168.2.5
                Apr 26, 2024 16:38:40.731731892 CEST53609001.1.1.1192.168.2.5
                TimestampSource IPDest IPChecksumCodeType
                Apr 26, 2024 16:38:29.573201895 CEST192.168.2.51.1.1.1c230(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 26, 2024 16:37:57.491297007 CEST192.168.2.51.1.1.10xf1d0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 26, 2024 16:37:57.491491079 CEST192.168.2.51.1.1.10x89b5Standard query (0)www.google.com65IN (0x0001)false
                Apr 26, 2024 16:38:24.742835999 CEST192.168.2.51.1.1.10x6515Standard query (0)alumnoeseit.edu.coA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:24.743108034 CEST192.168.2.51.1.1.10x38dStandard query (0)alumnoeseit.edu.co65IN (0x0001)false
                Apr 26, 2024 16:38:25.409138918 CEST192.168.2.51.1.1.10xfb3aStandard query (0)alumnoeseit.edu.coA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.148566961 CEST192.168.2.58.8.8.80x3605Standard query (0)google.comA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.148871899 CEST192.168.2.51.1.1.10x976cStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:28.908561945 CEST192.168.2.51.1.1.10x58daStandard query (0)alumnoeseit.edu.coA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:28.909070015 CEST192.168.2.51.1.1.10xacfbStandard query (0)alumnoeseit.edu.co65IN (0x0001)false
                Apr 26, 2024 16:38:34.240283966 CEST192.168.2.51.1.1.10x5399Standard query (0)alumnoeseit.edu.coA (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:34.240284920 CEST192.168.2.51.1.1.10x753fStandard query (0)alumnoeseit.edu.co65IN (0x0001)false
                Apr 26, 2024 16:38:34.501971960 CEST192.168.2.51.1.1.10x2afeStandard query (0)alumnoeseit.edu.coA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 26, 2024 16:37:57.616935968 CEST1.1.1.1192.168.2.50x89b5No error (0)www.google.com65IN (0x0001)false
                Apr 26, 2024 16:37:57.616998911 CEST1.1.1.1192.168.2.50xf1d0No error (0)www.google.com142.250.64.196A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.20A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.36A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.23A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.35A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.40A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.37A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:10.770181894 CEST1.1.1.1192.168.2.50x8b09No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com162.222.107.24A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:11.170543909 CEST1.1.1.1192.168.2.50x1ca4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 26, 2024 16:38:11.170543909 CEST1.1.1.1192.168.2.50x1ca4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:24.797046900 CEST1.1.1.1192.168.2.50xd480No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 26, 2024 16:38:24.797046900 CEST1.1.1.1192.168.2.50xd480No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.274610043 CEST1.1.1.1192.168.2.50x976cNo error (0)google.com172.217.165.206A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.138A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.113A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.100A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.101A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.139A (IP address)IN (0x0001)false
                Apr 26, 2024 16:38:26.313397884 CEST8.8.8.8192.168.2.50x3605No error (0)google.com142.250.113.102A (IP address)IN (0x0001)false
                • www.google.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.549708142.250.64.1964435640C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-26 14:37:58 UTC615OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-26 14:37:58 UTC1703INHTTP/1.1 200 OK
                Date: Fri, 26 Apr 2024 14:37:58 GMT
                Pragma: no-cache
                Expires: -1
                Cache-Control: no-cache, must-revalidate
                Content-Type: text/javascript; charset=UTF-8
                Strict-Transport-Security: max-age=31536000
                Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-JwZLFcoX5extDn6W6uajhg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                Accept-CH: Sec-CH-UA-Platform
                Accept-CH: Sec-CH-UA-Platform-Version
                Accept-CH: Sec-CH-UA-Full-Version
                Accept-CH: Sec-CH-UA-Arch
                Accept-CH: Sec-CH-UA-Model
                Accept-CH: Sec-CH-UA-Bitness
                Accept-CH: Sec-CH-UA-Full-Version-List
                Accept-CH: Sec-CH-UA-WoW64
                Permissions-Policy: unload=()
                Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                Content-Disposition: attachment; filename="f.txt"
                Server: gws
                X-XSS-Protection: 0
                X-Frame-Options: SAMEORIGIN
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-04-26 14:37:58 UTC800INData Raw: 33 31 39 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 61 6d 65 72 69 63 61 6e 20 68 6f 72 72 6f 72 20 73 74 6f 72 79 20 64 65 6c 69 63 61 74 65 20 65 6e 64 69 6e 67 22 2c 22 61 6c 70 68 61 62 65 74 20 73 74 6f 63 6b 20 65 61 72 6e 69 6e 67 73 22 2c 22 64 65 72 62 79 20 68 6f 72 73 65 73 22 2c 22 61 70 70 6c 65 20 69 70 68 6f 6e 65 20 31 36 20 70 72 6f 20 6d 61 78 22 2c 22 77 65 61 74 68 65 72 20 73 74 6f 72 6d 73 20 74 6f 72 6e 61 64 6f 65 73 22 2c 22 6e 65 74 66 6c 69 78 20 6d 69 6e 64 68 75 6e 74 65 72 20 73 65 61 73 6f 6e 20 33 22 2c 22 68 6f 75 73 65 68 6f 6c 64 20 63 61 76 61 6c 72 79 20 68 6f 72 73 65 73 20 6c 6f 6e 64 6f 6e 22 2c 22 68 6f 6d 65 20 64 65 70 6f 74 20 68 61 6c 6c 6f 77 65 65 6e 20 73 6b 65 6c 65 74 6f 6e 20 64 6f 67 22 5d 2c 5b 22 22 2c 22
                Data Ascii: 319)]}'["",["american horror story delicate ending","alphabet stock earnings","derby horses","apple iphone 16 pro max","weather storms tornadoes","netflix mindhunter season 3","household cavalry horses london","home depot halloween skeleton dog"],["","
                2024-04-26 14:37:58 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.549707142.250.64.1964435640C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-26 14:37:58 UTC518OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-26 14:37:58 UTC1843INHTTP/1.1 302 Found
                Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGMb4rrEGIjB_Hl3xkuM2buIj_fhZuZvubLNwP7UPnD01lIboCe2qlBky6GyoOQIiFSytb4PKZwYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                x-hallmonitor-challenge: CgwIxviusQYQkPSxwgISBGaBmNw
                Content-Type: text/html; charset=UTF-8
                Strict-Transport-Security: max-age=31536000
                Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                Permissions-Policy: unload=()
                Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                Date: Fri, 26 Apr 2024 14:37:58 GMT
                Server: gws
                Content-Length: 458
                X-XSS-Protection: 0
                X-Frame-Options: SAMEORIGIN
                Set-Cookie: 1P_JAR=2024-04-26-14; expires=Sun, 26-May-2024 14:37:58 GMT; path=/; domain=.google.com; Secure; SameSite=none
                Set-Cookie: NID=513=Mk6dmwXYcJkGS-1yRrpGTUKOG2b-tR52ZaNCRN4MEZAVrf9xukJ-J-l-Fsmm05f8f_ksBOdM8C7aZlr62QRmnevD5nXHKKhYGIAfNJ9DpBcaTmlTx2XKsbwuVUYky1QPOVnR0tl3ZgSC1chYD_vhb8gEigiDhVgwOwk2aBbayWA; expires=Sat, 26-Oct-2024 14:37:58 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-26 14:37:58 UTC458INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 25 33 46 68
                Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fh


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.549709142.250.64.1964435640C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-26 14:37:58 UTC353OUTGET /async/newtab_promos HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-26 14:37:58 UTC1761INHTTP/1.1 302 Found
                Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGMb4rrEGIjAG6d2Oed0kzoNdKwq2lS3p7cXT2GZOIIZfVi9CInLDS2liYGXYv-2-moOfJvpI_dsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                x-hallmonitor-challenge: CgwIxviusQYQw6XI3QISBGaBmNw
                Content-Type: text/html; charset=UTF-8
                Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                Permissions-Policy: unload=()
                Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                Date: Fri, 26 Apr 2024 14:37:58 GMT
                Server: gws
                Content-Length: 417
                X-XSS-Protection: 0
                X-Frame-Options: SAMEORIGIN
                Set-Cookie: 1P_JAR=2024-04-26-14; expires=Sun, 26-May-2024 14:37:58 GMT; path=/; domain=.google.com; Secure; SameSite=none
                Set-Cookie: NID=513=M_aMdvzOviEndbSgRdFy0MOnf9QSJZf1AiMkyWeeK0arZ-tQ07E6D-eqB8Ln8eFMt5fdGdhYYzTL2y9_SwzdANfr7PycOmHXZcv0yV6sXIvgiEWTR0sStblstNYNYklVjY-CDyxx3Anoj1ntkdyXGCrftK1gKGD_I6-K2ABzp1I; expires=Sat, 26-Oct-2024 14:37:58 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-26 14:37:58 UTC417INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 26
                Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.549710142.250.64.1964435640C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-26 14:37:58 UTC920OUTGET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGMb4rrEGIjB_Hl3xkuM2buIj_fhZuZvubLNwP7UPnD01lIboCe2qlBky6GyoOQIiFSytb4PKZwYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: 1P_JAR=2024-04-26-14; NID=513=Mk6dmwXYcJkGS-1yRrpGTUKOG2b-tR52ZaNCRN4MEZAVrf9xukJ-J-l-Fsmm05f8f_ksBOdM8C7aZlr62QRmnevD5nXHKKhYGIAfNJ9DpBcaTmlTx2XKsbwuVUYky1QPOVnR0tl3ZgSC1chYD_vhb8gEigiDhVgwOwk2aBbayWA
                2024-04-26 14:37:58 UTC356INHTTP/1.1 429 Too Many Requests
                Date: Fri, 26 Apr 2024 14:37:58 GMT
                Pragma: no-cache
                Expires: Fri, 01 Jan 1990 00:00:00 GMT
                Cache-Control: no-store, no-cache, must-revalidate
                Content-Type: text/html
                Server: HTTP server (unknown)
                Content-Length: 3186
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-26 14:37:58 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 3f 68 6c 3d 65 6e 2d 55 53 26 61 6d 70 3b 61 73 79
                Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_ogb?hl=en-US&amp;asy
                2024-04-26 14:37:58 UTC1255INData Raw: 0a 3c 73 63 72 69 70 74 3e 76 61 72 20 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 41 51 55 5f 72 75 39 39 72
                Data Ascii: <script>var submitCallback = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="AQU_ru99r
                2024-04-26 14:37:58 UTC1032INData Raw: 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 2e 34 65 6d 3b 22 3e 0a 54 68 69 73 20 70 61 67 65 20 61 70 70 65 61 72 73 20 77 68 65 6e 20 47 6f 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74
                Data Ascii: ; line-height:1.4em;">This page appears when Google automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly aft


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.549713142.250.64.1964435640C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-26 14:37:59 UTC738OUTGET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGMb4rrEGIjAG6d2Oed0kzoNdKwq2lS3p7cXT2GZOIIZfVi9CInLDS2liYGXYv-2-moOfJvpI_dsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                Host: www.google.com
                Connection: keep-alive
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: 1P_JAR=2024-04-26-14; NID=513=M_aMdvzOviEndbSgRdFy0MOnf9QSJZf1AiMkyWeeK0arZ-tQ07E6D-eqB8Ln8eFMt5fdGdhYYzTL2y9_SwzdANfr7PycOmHXZcv0yV6sXIvgiEWTR0sStblstNYNYklVjY-CDyxx3Anoj1ntkdyXGCrftK1gKGD_I6-K2ABzp1I
                2024-04-26 14:37:59 UTC356INHTTP/1.1 429 Too Many Requests
                Date: Fri, 26 Apr 2024 14:37:59 GMT
                Pragma: no-cache
                Expires: Fri, 01 Jan 1990 00:00:00 GMT
                Cache-Control: no-store, no-cache, must-revalidate
                Content-Type: text/html
                Server: HTTP server (unknown)
                Content-Length: 3114
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close
                2024-04-26 14:37:59 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64
                Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_promos</title></head
                2024-04-26 14:37:59 UTC1255INData Raw: 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 75 76 45 55 6c 65 34 36 73 31 4e 4e 32 38 67 5a 65 39 57 61 69 71 31 4d 69 36 62 31 31 45 4d 61 2d
                Data Ascii: ack = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="uvEUle46s1NN28gZe9Waiq1Mi6b11EMa-
                2024-04-26 14:37:59 UTC960INData Raw: 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74 65 72 20 74 68 6f 73 65 20 72 65 71 75 65 73 74 73 20 73 74 6f 70 2e 20 20 49 6e 20 74 68 65 20 6d 65 61 6e 74 69 6d 65 2c 20 73 6f 6c 76 69 6e
                Data Ascii: ogle automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly after those requests stop. In the meantime, solvin


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:16:37:50
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:16:37:55
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,13037938025454584876,2762468571744981583,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:16:37:56
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                Target ID:4
                Start time:16:37:56
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=2000,i,16255536715985720032,13152113976248923233,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                Target ID:7
                Start time:16:38:23
                Start date:26/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://alumnoeseit.edu.co"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly