Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://leonel.hopto.org

Overview

General Information

Sample URL:http://leonel.hopto.org
Analysis ID:1432233
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2784 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2024,i,9996346690695380267,11245280075574120504,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:/// MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1988,i,13045010664898347522,3139502761922582221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6632 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://leonel.hopto.org" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGPqgr7EGIjCZIYU-ZGJMudpGz-F5WpmZ_ULl49xF6bXf07v_UMi_tIY27zH__o_BHu3k_2jrfIQyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-26-16; NID=513=nkOwmosa55JK7DpoQrbMQ27K4d6WlrsDqf4I66QFr8yWCPZqJMObqhyDYvBmgJ44PBl_rrQ-pz3uJbjSw9PUKIYp7rfQyL55e18t9SLV8aPicxz8V6NCcafj8qUdo-s2uzoxACnMBbnWjhzzMfRWHb-7pZK9p-IfBWAoN_VaOwI
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGPqgr7EGIjA7fHiwVOlLVNA7Hz5_nTNsrKNd8-89gXJkwv88z382bRV0q9hgD5CmUYZyfbvjI7EyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 1P_JAR=2024-04-26-16; NID=513=mv1udKdJkD3Kx-Pz1q3l6c1oywl3DLjXS63ruLUzxDlIFbHPGy1xJIWXkFfi1AGYLq9Q-U5jINQxX2pktNiyqJqTJcFRIZVSpco9JTqw86QUZr2p_NZjzlQ7GVirA0sjwAEFOmwbj7loDxHb-M4D2xrqy8FT38eU5h04fPmsBak
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: leonel.hopto.org
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@26/2@14/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2024,i,9996346690695380267,11245280075574120504,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1988,i,13045010664898347522,3139502761922582221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://leonel.hopto.org"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2024,i,9996346690695380267,11245280075574120504,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1988,i,13045010664898347522,3139502761922582221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1432233 URL: http://leonel.hopto.org Startdate: 26/04/2024 Architecture: WINDOWS Score: 0 18 leonel.hopto.org 2->18 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        11 chrome.exe 2->11         started        process3 dnsIp4 20 192.168.2.4, 138, 443, 49270 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 13 chrome.exe 6->13         started        16 chrome.exe 9->16         started        process5 dnsIp6 24 www.google.com 142.250.217.164, 443, 49733, 49734 GOOGLEUS United States 13->24 26 leonel.hopto.org 13->26 28 google.com 13->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://leonel.hopto.org0%Avira URL Cloudsafe
http://leonel.hopto.org1%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
192.178.50.46
truefalse
    high
    www.google.com
    142.250.217.164
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        leonel.hopto.org
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://www.google.com/async/newtab_promosfalse
            high
            https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
              high
              https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0false
                high
                https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGPqgr7EGIjCZIYU-ZGJMudpGz-F5WpmZ_ULl49xF6bXf07v_UMi_tIY27zH__o_BHu3k_2jrfIQyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
                  high
                  https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGPqgr7EGIjA7fHiwVOlLVNA7Hz5_nTNsrKNd8-89gXJkwv88z382bRV0q9hgD5CmUYZyfbvjI7EyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUMfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.217.164
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1432233
                    Start date and time:2024-04-26 18:03:17 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 29s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://leonel.hopto.org
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:9
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:UNKNOWN
                    Classification:unknown0.win@26/2@14/3
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    Cookbook Comments:
                    • URL browsing timeout or error
                    • URL not reachable
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 192.178.50.46, 173.194.211.84, 142.250.189.131, 34.104.35.123, 23.204.76.112, 20.12.23.50, 23.45.182.69, 23.45.182.78, 23.45.182.68, 23.45.182.96, 23.45.182.79, 23.45.182.97, 23.45.182.73, 23.45.182.70, 23.45.182.100, 192.229.211.108, 52.165.164.15, 20.166.126.56
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with very long lines (794)
                    Category:downloaded
                    Size (bytes):799
                    Entropy (8bit):5.154483947035427
                    Encrypted:false
                    SSDEEP:24:LFTJwV7YyDzmBHslgT9lCuABuoB7HHHHHHHYqmffffffo:j2zmKlgZ01BuSEqmffffffo
                    MD5:0AD7B63B649F57B4E1EA110EB493F616
                    SHA1:E5B1B09A6CA1A2F2717ED4429A3E11BB9C6F1C40
                    SHA-256:174B1040660CD9C31A3EAB5D7AE827C44EFCA65AD61C523779A5979F767674EF
                    SHA-512:E4335BEC9890CE6FB27F1E636DB5A8DA1E0AE1ACA058FD8DDB48B323CD56D77AE049A8A8F2ECDC1AE9A78BBD36A8A1C7D50C54C8369187319B30C752067C6984
                    Malicious:false
                    Reputation:low
                    URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                    Preview:)]}'.["",["major league soccer indianapolis","philly pretzel factory free pretzel day","nyt connections hints april 26","apple iphone 16 pro max","nasa mars spiders","stanley cup playoffs bracket","reddit outage","new smyrna beach florida explosion"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 26, 2024 18:03:59.509735107 CEST49678443192.168.2.4104.46.162.224
                    Apr 26, 2024 18:03:59.650296926 CEST49675443192.168.2.4173.222.162.32
                    Apr 26, 2024 18:04:09.445962906 CEST49675443192.168.2.4173.222.162.32
                    Apr 26, 2024 18:04:09.902173996 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.902239084 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:09.902304888 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.902872086 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.902894020 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:09.964307070 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.964344978 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:09.964431047 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.964658022 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:09.964670897 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.023628950 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.023669004 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.023916960 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.024128914 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.024133921 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.087878942 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.087934971 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.087991953 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.088291883 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.088306904 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.301266909 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.301682949 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.301704884 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.302783966 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.302839994 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.303971052 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.304050922 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.304338932 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.304347038 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.356038094 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.356065035 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.356535912 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.356565952 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.356702089 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.356725931 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.357626915 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.357698917 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.358083010 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.358145952 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.358169079 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.358221054 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.358577967 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.358659983 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.358937025 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.358946085 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.359006882 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.359014988 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.400357008 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.445826054 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.445833921 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.550429106 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.550757885 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.550781965 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.554558992 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.554630995 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.554992914 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.555080891 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.633191109 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.633199930 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.720675945 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.720799923 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.720971107 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.720997095 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.722101927 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.722223997 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.722306967 CEST49734443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:10.722317934 CEST44349734142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:10.742554903 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.084377050 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.084479094 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.084542036 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.084625959 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.084707022 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.091100931 CEST49733443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.091135025 CEST44349733142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.093971014 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.121258974 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.121351004 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.121434927 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.121670008 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.121725082 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.122445107 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.122503996 CEST44349735142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.122534990 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.122562885 CEST49735443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.129440069 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.129503965 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.129581928 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.129856110 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.129875898 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.136142015 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.319113970 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.319185019 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.319252014 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.319289923 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.319349051 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.320305109 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.320369005 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.320419073 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.323118925 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.323138952 CEST44349736142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.323154926 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.323184967 CEST49736443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.575958967 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.633114100 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.652838945 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:11.652874947 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.653523922 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:11.758094072 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:13.383519888 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:13.383805990 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:13.385843039 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:13.428122044 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224558115 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224617004 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224687099 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224714041 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:14.224761009 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224787951 CEST44349739142.250.217.164192.168.2.4
                    Apr 26, 2024 18:04:14.224833012 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:14.224833012 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:14.225466967 CEST49739443192.168.2.4142.250.217.164
                    Apr 26, 2024 18:04:14.225500107 CEST44349739142.250.217.164192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 26, 2024 18:04:09.380219936 CEST53578811.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:09.763268948 CEST5945753192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:09.763443947 CEST4927053192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:09.893321991 CEST53594571.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:09.893368006 CEST53492701.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:10.459275007 CEST53493381.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:27.792881966 CEST53605601.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:30.041471004 CEST138138192.168.2.4192.168.2.255
                    Apr 26, 2024 18:04:37.926969051 CEST5878953192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:37.927259922 CEST5001953192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:38.054936886 CEST53500191.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:38.055913925 CEST53587891.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:38.064629078 CEST6207853192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:38.220242977 CEST53620781.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:38.262659073 CEST4955553192.168.2.48.8.8.8
                    Apr 26, 2024 18:04:38.263264894 CEST5472653192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:38.400573015 CEST53547261.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:38.432254076 CEST53495558.8.8.8192.168.2.4
                    Apr 26, 2024 18:04:39.272944927 CEST5923753192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:39.273145914 CEST5790253192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:39.398809910 CEST53592371.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:39.399002075 CEST53579021.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:44.415967941 CEST5263353192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:44.416269064 CEST5482953192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:44.543504953 CEST53526331.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:44.545564890 CEST53548291.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:45.897212029 CEST6550353192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:45.897569895 CEST4956453192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:45.900413990 CEST5800553192.168.2.41.1.1.1
                    Apr 26, 2024 18:04:46.025304079 CEST53495641.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:46.025336981 CEST53655031.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:46.029710054 CEST53580051.1.1.1192.168.2.4
                    Apr 26, 2024 18:04:47.205959082 CEST53603681.1.1.1192.168.2.4
                    TimestampSource IPDest IPChecksumCodeType
                    Apr 26, 2024 18:04:46.025381088 CEST192.168.2.41.1.1.1c222(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 26, 2024 18:04:09.763268948 CEST192.168.2.41.1.1.10x639dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:09.763443947 CEST192.168.2.41.1.1.10xff64Standard query (0)www.google.com65IN (0x0001)false
                    Apr 26, 2024 18:04:37.926969051 CEST192.168.2.41.1.1.10x3c45Standard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:37.927259922 CEST192.168.2.41.1.1.10x9f3Standard query (0)leonel.hopto.org65IN (0x0001)false
                    Apr 26, 2024 18:04:38.064629078 CEST192.168.2.41.1.1.10xa73aStandard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.262659073 CEST192.168.2.48.8.8.80x3932Standard query (0)google.comA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.263264894 CEST192.168.2.41.1.1.10x17beStandard query (0)google.comA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:39.272944927 CEST192.168.2.41.1.1.10x1459Standard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:39.273145914 CEST192.168.2.41.1.1.10x9b61Standard query (0)leonel.hopto.org65IN (0x0001)false
                    Apr 26, 2024 18:04:44.415967941 CEST192.168.2.41.1.1.10x8b1aStandard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:44.416269064 CEST192.168.2.41.1.1.10x768Standard query (0)leonel.hopto.org65IN (0x0001)false
                    Apr 26, 2024 18:04:45.897212029 CEST192.168.2.41.1.1.10xcdf4Standard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:45.897569895 CEST192.168.2.41.1.1.10x4e13Standard query (0)leonel.hopto.org65IN (0x0001)false
                    Apr 26, 2024 18:04:45.900413990 CEST192.168.2.41.1.1.10x3e4aStandard query (0)leonel.hopto.orgA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 26, 2024 18:04:09.893321991 CEST1.1.1.1192.168.2.40x639dNo error (0)www.google.com142.250.217.164A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:09.893368006 CEST1.1.1.1192.168.2.40xff64No error (0)www.google.com65IN (0x0001)false
                    Apr 26, 2024 18:04:23.388299942 CEST1.1.1.1192.168.2.40xf7adNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 26, 2024 18:04:23.388299942 CEST1.1.1.1192.168.2.40xf7adNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:37.528680086 CEST1.1.1.1192.168.2.40xefa7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 26, 2024 18:04:37.528680086 CEST1.1.1.1192.168.2.40xefa7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.400573015 CEST1.1.1.1192.168.2.40x17beNo error (0)google.com192.178.50.46A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.138A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.102A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.139A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.100A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.113A (IP address)IN (0x0001)false
                    Apr 26, 2024 18:04:38.432254076 CEST8.8.8.8192.168.2.40x3932No error (0)google.com142.250.113.101A (IP address)IN (0x0001)false
                    • www.google.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449734142.250.217.1644432784C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-26 16:04:10 UTC615OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-26 16:04:10 UTC1703INHTTP/1.1 200 OK
                    Date: Fri, 26 Apr 2024 16:04:10 GMT
                    Pragma: no-cache
                    Expires: -1
                    Cache-Control: no-cache, must-revalidate
                    Content-Type: text/javascript; charset=UTF-8
                    Strict-Transport-Security: max-age=31536000
                    Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-qj1MyQ69lWW9ykTEwKTxEA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                    Accept-CH: Sec-CH-UA-Platform
                    Accept-CH: Sec-CH-UA-Platform-Version
                    Accept-CH: Sec-CH-UA-Full-Version
                    Accept-CH: Sec-CH-UA-Arch
                    Accept-CH: Sec-CH-UA-Model
                    Accept-CH: Sec-CH-UA-Bitness
                    Accept-CH: Sec-CH-UA-Full-Version-List
                    Accept-CH: Sec-CH-UA-WoW64
                    Permissions-Policy: unload=()
                    Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                    Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                    Content-Disposition: attachment; filename="f.txt"
                    Server: gws
                    X-XSS-Protection: 0
                    X-Frame-Options: SAMEORIGIN
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-04-26 16:04:10 UTC806INData Raw: 33 31 66 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 6d 61 6a 6f 72 20 6c 65 61 67 75 65 20 73 6f 63 63 65 72 20 69 6e 64 69 61 6e 61 70 6f 6c 69 73 22 2c 22 70 68 69 6c 6c 79 20 70 72 65 74 7a 65 6c 20 66 61 63 74 6f 72 79 20 66 72 65 65 20 70 72 65 74 7a 65 6c 20 64 61 79 22 2c 22 6e 79 74 20 63 6f 6e 6e 65 63 74 69 6f 6e 73 20 68 69 6e 74 73 20 61 70 72 69 6c 20 32 36 22 2c 22 61 70 70 6c 65 20 69 70 68 6f 6e 65 20 31 36 20 70 72 6f 20 6d 61 78 22 2c 22 6e 61 73 61 20 6d 61 72 73 20 73 70 69 64 65 72 73 22 2c 22 73 74 61 6e 6c 65 79 20 63 75 70 20 70 6c 61 79 6f 66 66 73 20 62 72 61 63 6b 65 74 22 2c 22 72 65 64 64 69 74 20 6f 75 74 61 67 65 22 2c 22 6e 65 77 20 73 6d 79 72 6e 61 20 62 65 61 63 68 20 66 6c 6f 72 69 64 61 20 65 78 70 6c 6f 73 69 6f 6e 22 5d
                    Data Ascii: 31f)]}'["",["major league soccer indianapolis","philly pretzel factory free pretzel day","nyt connections hints april 26","apple iphone 16 pro max","nasa mars spiders","stanley cup playoffs bracket","reddit outage","new smyrna beach florida explosion"]
                    2024-04-26 16:04:10 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449733142.250.217.1644432784C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-26 16:04:10 UTC518OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-26 16:04:11 UTC1843INHTTP/1.1 302 Found
                    Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGPqgr7EGIjCZIYU-ZGJMudpGz-F5WpmZ_ULl49xF6bXf07v_UMi_tIY27zH__o_BHu3k_2jrfIQyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                    x-hallmonitor-challenge: CgwI-qCvsQYQ1IX0wQMSBGaBmNw
                    Content-Type: text/html; charset=UTF-8
                    Strict-Transport-Security: max-age=31536000
                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                    Permissions-Policy: unload=()
                    Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                    Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                    P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                    Date: Fri, 26 Apr 2024 16:04:10 GMT
                    Server: gws
                    Content-Length: 458
                    X-XSS-Protection: 0
                    X-Frame-Options: SAMEORIGIN
                    Set-Cookie: 1P_JAR=2024-04-26-16; expires=Sun, 26-May-2024 16:04:10 GMT; path=/; domain=.google.com; Secure; SameSite=none
                    Set-Cookie: NID=513=nkOwmosa55JK7DpoQrbMQ27K4d6WlrsDqf4I66QFr8yWCPZqJMObqhyDYvBmgJ44PBl_rrQ-pz3uJbjSw9PUKIYp7rfQyL55e18t9SLV8aPicxz8V6NCcafj8qUdo-s2uzoxACnMBbnWjhzzMfRWHb-7pZK9p-IfBWAoN_VaOwI; expires=Sat, 26-Oct-2024 16:04:10 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-04-26 16:04:11 UTC458INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 25 33 46 68
                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fh


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449735142.250.217.1644432784C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-26 16:04:10 UTC353OUTGET /async/newtab_promos HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-26 16:04:11 UTC1761INHTTP/1.1 302 Found
                    Location: https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGPqgr7EGIjA7fHiwVOlLVNA7Hz5_nTNsrKNd8-89gXJkwv88z382bRV0q9hgD5CmUYZyfbvjI7EyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
                    x-hallmonitor-challenge: CgwI-qCvsQYQ4fqbygMSBGaBmNw
                    Content-Type: text/html; charset=UTF-8
                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                    Permissions-Policy: unload=()
                    Origin-Trial: Ap+qNlnLzJDKSmEHjzM5ilaa908GuehlLqGb6ezME5lkhelj20qVzfv06zPmQ3LodoeujZuphAolrnhnPA8w4AIAAABfeyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJQZXJtaXNzaW9uc1BvbGljeVVubG9hZCIsImV4cGlyeSI6MTY4NTY2Mzk5OX0=
                    Origin-Trial: AvudrjMZqL7335p1KLV2lHo1kxdMeIN0dUI15d0CPz9dovVLCcXk8OAqjho1DX4s6NbHbA/AGobuGvcZv0drGgQAAAB9eyJvcmlnaW4iOiJodHRwczovL3d3dy5nb29nbGUuY29tOjQ0MyIsImZlYXR1cmUiOiJCYWNrRm9yd2FyZENhY2hlTm90UmVzdG9yZWRSZWFzb25zIiwiZXhwaXJ5IjoxNjkxNTM5MTk5LCJpc1N1YmRvbWFpbiI6dHJ1ZX0=
                    P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                    Date: Fri, 26 Apr 2024 16:04:10 GMT
                    Server: gws
                    Content-Length: 417
                    X-XSS-Protection: 0
                    X-Frame-Options: SAMEORIGIN
                    Set-Cookie: 1P_JAR=2024-04-26-16; expires=Sun, 26-May-2024 16:04:10 GMT; path=/; domain=.google.com; Secure; SameSite=none
                    Set-Cookie: NID=513=mv1udKdJkD3Kx-Pz1q3l6c1oywl3DLjXS63ruLUzxDlIFbHPGy1xJIWXkFfi1AGYLq9Q-U5jINQxX2pktNiyqJqTJcFRIZVSpco9JTqw86QUZr2p_NZjzlQ7GVirA0sjwAEFOmwbj7loDxHb-M4D2xrqy8FT38eU5h04fPmsBak; expires=Sat, 26-Oct-2024 16:04:10 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-04-26 16:04:11 UTC417INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 73 6f 72 72 79 2f 69 6e 64 65 78 3f 63 6f 6e 74 69 6e 75 65 3d 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 26
                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449736142.250.217.1644432784C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-26 16:04:11 UTC920OUTGET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGPqgr7EGIjCZIYU-ZGJMudpGz-F5WpmZ_ULl49xF6bXf07v_UMi_tIY27zH__o_BHu3k_2jrfIQyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCI/KzQEIucrNAQii0c0BCIrTzQEIntbNAQin2M0BCPnA1BUY9snNARi60s0BGOuNpRc=
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: 1P_JAR=2024-04-26-16; NID=513=nkOwmosa55JK7DpoQrbMQ27K4d6WlrsDqf4I66QFr8yWCPZqJMObqhyDYvBmgJ44PBl_rrQ-pz3uJbjSw9PUKIYp7rfQyL55e18t9SLV8aPicxz8V6NCcafj8qUdo-s2uzoxACnMBbnWjhzzMfRWHb-7pZK9p-IfBWAoN_VaOwI
                    2024-04-26 16:04:11 UTC356INHTTP/1.1 429 Too Many Requests
                    Date: Fri, 26 Apr 2024 16:04:11 GMT
                    Pragma: no-cache
                    Expires: Fri, 01 Jan 1990 00:00:00 GMT
                    Cache-Control: no-store, no-cache, must-revalidate
                    Content-Type: text/html
                    Server: HTTP server (unknown)
                    Content-Length: 3186
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-04-26 16:04:11 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 6f 67 62 3f 68 6c 3d 65 6e 2d 55 53 26 61 6d 70 3b 61 73 79
                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_ogb?hl=en-US&amp;asy
                    2024-04-26 16:04:11 UTC1255INData Raw: 0a 3c 73 63 72 69 70 74 3e 76 61 72 20 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 31 38 75 33 45 78 50 41 34
                    Data Ascii: <script>var submitCallback = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="18u3ExPA4
                    2024-04-26 16:04:11 UTC1032INData Raw: 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 2e 34 65 6d 3b 22 3e 0a 54 68 69 73 20 70 61 67 65 20 61 70 70 65 61 72 73 20 77 68 65 6e 20 47 6f 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74
                    Data Ascii: ; line-height:1.4em;">This page appears when Google automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly aft


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.449739142.250.217.1644432784C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-26 16:04:13 UTC738OUTGET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGPqgr7EGIjA7fHiwVOlLVNA7Hz5_nTNsrKNd8-89gXJkwv88z382bRV0q9hgD5CmUYZyfbvjI7EyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1
                    Host: www.google.com
                    Connection: keep-alive
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: 1P_JAR=2024-04-26-16; NID=513=mv1udKdJkD3Kx-Pz1q3l6c1oywl3DLjXS63ruLUzxDlIFbHPGy1xJIWXkFfi1AGYLq9Q-U5jINQxX2pktNiyqJqTJcFRIZVSpco9JTqw86QUZr2p_NZjzlQ7GVirA0sjwAEFOmwbj7loDxHb-M4D2xrqy8FT38eU5h04fPmsBak
                    2024-04-26 16:04:14 UTC356INHTTP/1.1 429 Too Many Requests
                    Date: Fri, 26 Apr 2024 16:04:14 GMT
                    Pragma: no-cache
                    Expires: Fri, 01 Jan 1990 00:00:00 GMT
                    Cache-Control: no-store, no-cache, must-revalidate
                    Content-Type: text/html
                    Server: HTTP server (unknown)
                    Content-Length: 3114
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close
                    2024-04-26 16:04:14 UTC899INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 61 73 79 6e 63 2f 6e 65 77 74 61 62 5f 70 72 6f 6d 6f 73 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64
                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"><meta name="viewport" content="initial-scale=1"><title>https://www.google.com/async/newtab_promos</title></head
                    2024-04-26 16:04:14 UTC1255INData Raw: 61 63 6b 20 3d 20 66 75 6e 63 74 69 6f 6e 28 72 65 73 70 6f 6e 73 65 29 20 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 61 70 74 63 68 61 2d 66 6f 72 6d 27 29 2e 73 75 62 6d 69 74 28 29 3b 7d 3b 3c 2f 73 63 72 69 70 74 3e 0a 3c 64 69 76 20 69 64 3d 22 72 65 63 61 70 74 63 68 61 22 20 63 6c 61 73 73 3d 22 67 2d 72 65 63 61 70 74 63 68 61 22 20 64 61 74 61 2d 73 69 74 65 6b 65 79 3d 22 36 4c 66 77 75 79 55 54 41 41 41 41 41 4f 41 6d 6f 53 30 66 64 71 69 6a 43 32 50 62 62 64 48 34 6b 6a 71 36 32 59 31 62 22 20 64 61 74 61 2d 63 61 6c 6c 62 61 63 6b 3d 22 73 75 62 6d 69 74 43 61 6c 6c 62 61 63 6b 22 20 64 61 74 61 2d 73 3d 22 42 56 33 43 4a 34 53 73 51 64 55 6b 67 69 4f 6e 44 52 50 5f 35 76 4d 4d 33 6b 6e 56 54 36 72 54 5a
                    Data Ascii: ack = function(response) {document.getElementById('captcha-form').submit();};</script><div id="recaptcha" class="g-recaptcha" data-sitekey="6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b" data-callback="submitCallback" data-s="BV3CJ4SsQdUkgiOnDRP_5vMM3knVT6rTZ
                    2024-04-26 16:04:14 UTC960INData Raw: 6f 67 6c 65 20 61 75 74 6f 6d 61 74 69 63 61 6c 6c 79 20 64 65 74 65 63 74 73 20 72 65 71 75 65 73 74 73 20 63 6f 6d 69 6e 67 20 66 72 6f 6d 20 79 6f 75 72 20 63 6f 6d 70 75 74 65 72 20 6e 65 74 77 6f 72 6b 20 77 68 69 63 68 20 61 70 70 65 61 72 20 74 6f 20 62 65 20 69 6e 20 76 69 6f 6c 61 74 69 6f 6e 20 6f 66 20 74 68 65 20 3c 61 20 68 72 65 66 3d 22 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 70 6f 6c 69 63 69 65 73 2f 74 65 72 6d 73 2f 22 3e 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 3c 2f 61 3e 2e 20 54 68 65 20 62 6c 6f 63 6b 20 77 69 6c 6c 20 65 78 70 69 72 65 20 73 68 6f 72 74 6c 79 20 61 66 74 65 72 20 74 68 6f 73 65 20 72 65 71 75 65 73 74 73 20 73 74 6f 70 2e 20 20 49 6e 20 74 68 65 20 6d 65 61 6e 74 69 6d 65 2c 20 73 6f 6c 76 69 6e
                    Data Ascii: ogle automatically detects requests coming from your computer network which appear to be in violation of the <a href="//www.google.com/policies/terms/">Terms of Service</a>. The block will expire shortly after those requests stop. In the meantime, solvin


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:18:04:02
                    Start date:26/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:18:04:08
                    Start date:26/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2024,i,9996346690695380267,11245280075574120504,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:18:04:08
                    Start date:26/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    Target ID:4
                    Start time:18:04:09
                    Start date:26/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1988,i,13045010664898347522,3139502761922582221,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    Target ID:8
                    Start time:18:04:35
                    Start date:26/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://leonel.hopto.org"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly