Windows Analysis Report
http://go.microsoft.com/fwlink/?LinkId=787651.

Overview

General Information

Sample URL: http://go.microsoft.com/fwlink/?LinkId=787651.
Analysis ID: 1432287
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Stores files to the Windows start menu directory

Classification

Source: https://www.bing.com/secure/Passport.aspx?popup=1&ssl=1 HTTP Parser: No favicon
Source: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1 HTTP Parser: No favicon
Source: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1 HTTP Parser: No favicon
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_ChpboAn7HyXj89A22M8mzg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /instrument/cookieenabled HTTP/1.1Host: 3pcookiecheck.azureedge.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1 HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/www-player.css HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/www-embed-player.vflset/www-embed-player.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/base.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /iframe_api HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/www-widgetapi.vflset/www-widgetapi.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /pagead/id HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.youtube.comX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /instream/ad_status.js HTTP/1.1Host: static.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ytc/AIdro_kwFxfJF-fQml8fUIvrd36ZstE2RO-C-IwDB-0qxQoc3Q=s68-c-k-c0x00ffffff-no-rj HTTP/1.1Host: yt3.ggpht.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /pagead/id?slf_rd=1 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.youtube.comX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ytc/AIdro_kwFxfJF-fQml8fUIvrd36ZstE2RO-C-IwDB-0qxQoc3Q=s68-c-k-c0x00ffffff-no-rj HTTP/1.1Host: yt3.ggpht.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /pagead/id?slf_rd=1 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /js/th/suXtyypHr-kmcDv8BLab_zSS-cnpn4GzxWV-_PefaIU.js HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/embed.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /api/stats/playback?ns=yt&el=embedded&cpn=woe7lOTrahhyYWcq&ver=2&cmt=0.011&fmt=397&fs=0&rt=2.555&euri=https%3A%2F%2Fwww.bing.com%2F&lact=2853&cl=627399198&mos=1&volume=100&cbr=Chrome&cbrver=117.0.0.0&c=WEB_EMBEDDED_PLAYER&cver=1.20240423.01.00&cplayer=UNIPLAYER&cos=Windows&cosver=10.0&cplatform=DESKTOP&autoplay=1&epm=1&hl=en_US&cr=US&len=1243.561&fexp=v1%2C23983296%2C21348%2C76094%2C54572%2C73455%2C230596%2C84737%2C36318%2C6271%2C129196%2C26314352%2C7111%2C31786%2C4557%2C9673%2C281%2C1192%2C8253%2C18243%2C6966%2C2%2C6689%2C2007%2C9072%2C8153%2C11921%2C9078%2C530%2C223%2C1443%2C8970%2C1025%2C1104%2C21%2C4444%2C2488%2C152%2C2607%2C54%2C496%2C142%2C6%2C3%2C40%2C3%2C289%2C1%2C78%2C584%2C4032%2C476%2C6&rtn=7&afmt=251&size=780%3A439&inview=1&muted=1&au_d=en-US.4&docid=SrGENEXocJU&ei=TuQrZue5EP_lj-8PtsWc8Ac&plid=AAYXAzxr4G2NzhNf&referrer=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSrGENEXocJU%3Fautoplay%3D1%26enablejsapi%3D1%26origin%3Dhttps%3A%2F%2Fwww.bing.com%26rel%3D0%26mute%3D1&of=P0iDOXD2Nl5QW4mjR62tvQ&vm=CAEQARgEOjJBSHFpSlRLWS1pM0tYMk11ckdUREVNSlZUbGhveTYwanZpXzVmaGR3eHFVWFJWcXRrQWJwQVBta0tETGw1S2o1Y2loRmYwVlA4SFVkd2tSTEdJNjd0emRKRkdlMm5WSVByNzlITFUyQnJpUzlQT2pBME1ESzgzRUpkblB6ZDU0YzJFamU4aVg4cVNQMVVUZGllY1ZZbXJwdHJRUTZyWFk0UjJQcGgC HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"X-YouTube-Ad-Signals: dt=1714152524356&flash=0&frm=2&u_tz=120&u_his=1&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&bc=31&bih=-12245933&biw=-12245933&brdim=0%2C0%2C0%2C0%2C1280%2C0%2C1280%2C984%2C780%2C439&vis=1&wgl=true&ca_type=imagesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-YouTube-Utc-Offset: 120X-YouTube-Client-Name: 56X-YouTube-Client-Version: 1.20240423.01.00X-YouTube-Time-Zone: Europe/ZurichX-Goog-Visitor-Id: CgsyeU03cGxDTS1pRSjIyK-xBjIKCgJVUxIEGgAgbQ%3D%3Dsec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /ptracking?html5=1&video_id=SrGENEXocJU&cpn=woe7lOTrahhyYWcq&ei=TuQrZue5EP_lj-8PtsWc8Ac&ptk=youtube_single&oid=CD-KBP9o9gNmNJwVpP8DgQ&ptchn=Y1kMZp36IQSyNx_9h4mpCg&pltype=content HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"X-YouTube-Ad-Signals: dt=1714152524356&flash=0&frm=2&u_tz=120&u_his=1&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&bc=31&bih=-12245933&biw=-12245933&brdim=0%2C0%2C0%2C0%2C1280%2C0%2C1280%2C984%2C780%2C439&vis=1&wgl=true&ca_type=imagesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-YouTube-Utc-Offset: 120X-YouTube-Client-Name: 56X-YouTube-Client-Version: 1.20240423.01.00X-YouTube-Time-Zone: Europe/ZurichX-Goog-Visitor-Id: CgsyeU03cGxDTS1pRSjIyK-xBjIKCgJVUxIEGgAgbQ%3D%3Dsec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=251&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&xtags=acont%3Doriginal%3Alang%3Den-US&mime=audio%2Fwebm&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=19853708&dur=1243.561&lmt=1713977124404049&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4532434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Citag%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cxtags%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAOx3PHhGSYyHuHrEUQRBlxZwoTS8iWCiPT3sK3aDdFDaAiBpSYvuKftUyStEyrSAyCtcVcQZL6h4RaasnHjeMVdwrQ%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=0-67944&rn=2&rbuf=0&pot=Ijh7AHsDHSufTjhnCHkeVUszGEcDRC9TSnApUxFJAktWeDlqMks4ZzFWLngyRTxnOmcZUV4zPyVIRA==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=397&aitags=133%2C134%2C135%2C136%2C137%2C160%2C242%2C243%2C244%2C247%2C248%2C278%2C394%2C395%2C396%2C397%2C398%2C399&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&mime=video%2Fmp4&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=59324235&dur=1243.533&lmt=1713982367602240&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4537434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Caitags%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAJarxrOv3NbyDGSfyQW9_-BP6T3aR24LC0AlcI5szxNtAiAk8cM2wYwcMYRjxYAAH47JDpzd2dcsT5cN41U5yK1U2A%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=0-175380&rn=1&rbuf=0&pot=Ijjext7FuO06iJ2hrb-7k-71vYGmgoqV77aMlbSPp43zvpysl42doZSQi76Xg5mhn6G8l_v1muPtgg==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ytc/AIdro_kwFxfJF-fQml8fUIvrd36ZstE2RO-C-IwDB-0qxQoc3Q=s88-c-k-c0x00ffffff-no-rj HTTP/1.1Host: yt3.ggpht.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=397&aitags=133%2C134%2C135%2C136%2C137%2C160%2C242%2C243%2C244%2C247%2C248%2C278%2C394%2C395%2C396%2C397%2C398%2C399&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&mime=video%2Fmp4&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=59324235&dur=1243.533&lmt=1713982367602240&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4537434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Caitags%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAJarxrOv3NbyDGSfyQW9_-BP6T3aR24LC0AlcI5szxNtAiAk8cM2wYwcMYRjxYAAH47JDpzd2dcsT5cN41U5yK1U2A%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=175381-347185&rn=3&rbuf=3310&pot=IjjZKdkvvwI9ZppOqlC8fOkaum6hbY166FmLerNgoGL0UZtDkGKaTpN_jFGQbJ5OmE67ePwanQzqbQ==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=251&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&xtags=acont%3Doriginal%3Alang%3Den-US&mime=audio%2Fwebm&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=19853708&dur=1243.561&lmt=1713977124404049&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4532434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Citag%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cxtags%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAOx3PHhGSYyHuHrEUQRBlxZwoTS8iWCiPT3sK3aDdFDaAiBpSYvuKftUyStEyrSAyCtcVcQZL6h4RaasnHjeMVdwrQ%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=67945-133480&rn=4&rbuf=3473&pot=IjgJwQnHb-rtjkqmerhslDnyaoZxhV2SOLFbkmOIcIokuUurQIpKpkOXXLlAhE6mSKZrkCzyTeQ6hQ==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/remote.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/captions.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=397&aitags=133%2C134%2C135%2C136%2C137%2C160%2C242%2C243%2C244%2C247%2C248%2C278%2C394%2C395%2C396%2C397%2C398%2C399&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&mime=video%2Fmp4&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=59324235&dur=1243.533&lmt=1713982367602240&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4537434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Caitags%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAJarxrOv3NbyDGSfyQW9_-BP6T3aR24LC0AlcI5szxNtAiAk8cM2wYwcMYRjxYAAH47JDpzd2dcsT5cN41U5yK1U2A%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=347186-747744&rn=5&rbuf=5274&pot=Ijh5YXlnH0qdMToGChgcNElSGiYBJS0ySBErMhMoACpUGTsLMCo6BjM3LBkwJD4GOAYbMFxSPURKJQ==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=251&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&xtags=acont%3Doriginal%3Alang%3Den-US&mime=audio%2Fwebm&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=19853708&dur=1243.561&lmt=1713977124404049&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4532434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Citag%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cxtags%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAOx3PHhGSYyHuHrEUQRBlxZwoTS8iWCiPT3sK3aDdFDaAiBpSYvuKftUyStEyrSAyCtcVcQZL6h4RaasnHjeMVdwrQ%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=133481-250315&rn=6&rbuf=6158&pot=IjiJQ4lF72htE8ok-jrsFrlw6gTxB90QuDPbEOMK8AikO8spwAjKJMMV3DvABs4kyCTrEqxwzWa6Bw==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/endscreen.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /s/player/652ba3a2/player_ias.vflset/en_US/annotations_module.js HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /generate_204?GXl_0g HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: global traffic HTTP traffic detected: GET /ytc/AIdro_kwFxfJF-fQml8fUIvrd36ZstE2RO-C-IwDB-0qxQoc3Q=s88-c-k-c0x00ffffff-no-rj HTTP/1.1Host: yt3.ggpht.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=251&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&xtags=acont%3Doriginal%3Alang%3Den-US&mime=audio%2Fwebm&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=19853708&dur=1243.561&lmt=1713977124404049&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4532434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Citag%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cxtags%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAOx3PHhGSYyHuHrEUQRBlxZwoTS8iWCiPT3sK3aDdFDaAiBpSYvuKftUyStEyrSAyCtcVcQZL6h4RaasnHjeMVdwrQ%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=250316-497783&rn=7&rbuf=13044&pot=MnRVVKfOp--0vFVsBFIn80fWOrC9EvrFrVYVt9LRgj77sMMTKVoISha0_4F40ttV96ts_rOFFWs-s24hpXCGazx0vNT0U34AMGPyhm_IjFmfvpL3yNp4GCp-JnS2ofN5zUJaMn1daD_L8IcnYVCSoMYQEhjMIg==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /vi_webp/QpwJEYGCngI/maxresdefault.webp HTTP/1.1Host: i.ytimg.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.youtube.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /videoplayback?expire=1714174126&ei=TuQrZue5EP_lj-8PtsWc8Ac&ip=102.129.152.220&id=o-ACZr22YdrAQ_inOONETQYNrRJwBroNlZpzD7mdDTKmCP&itag=397&aitags=133%2C134%2C135%2C136%2C137%2C160%2C242%2C243%2C244%2C247%2C248%2C278%2C394%2C395%2C396%2C397%2C398%2C399&source=youtube&requiressl=yes&xpc=EgVo2aDSNQ%3D%3D&mh=sm&mm=31%2C29&mn=sn-vgqsrnlz%2Csn-q4fl6nsd&ms=au%2Crdu&mv=m&mvi=5&pl=24&initcwndbps=1867500&bui=AWRWj2Q2zS8mz5Uh0KlyQOrod6F6bEzS2XnJHhZlU6Ntu7fCvhH5-T75JOFqu4mMwtauhVWRV5miuOW-&spc=UWF9f939Blnnh_RAwzI1DBAlBE2f-st8ZdSFq6z7kSl9bfkJ9rBH0l_WaQ&vprv=1&svpuc=1&mime=video%2Fmp4&ns=qo8r2h6XJp0ot083mpLdawoQ&gir=yes&clen=59324235&dur=1243.533&lmt=1713982367602240&mt=1714152073&fvip=2&keepalive=yes&c=WEB_EMBEDDED_PLAYER&sefc=1&txp=4537434&n=QhIWIC2GpJTQ0w&sparams=expire%2Cei%2Cip%2Cid%2Caitags%2Csource%2Crequiressl%2Cxpc%2Cbui%2Cspc%2Cvprv%2Csvpuc%2Cmime%2Cns%2Cgir%2Cclen%2Cdur%2Clmt&sig=AJfQdSswRQIhAJarxrOv3NbyDGSfyQW9_-BP6T3aR24LC0AlcI5szxNtAiAk8cM2wYwcMYRjxYAAH47JDpzd2dcsT5cN41U5yK1U2A%3D%3D&lsparams=mh%2Cmm%2Cmn%2Cms%2Cmv%2Cmvi%2Cpl%2Cinitcwndbps&lsig=AHWaYeowRQIhALnqvLKMfB2mzPpBsEhecj18LGYALJN64TKjK5gb7lptAiBH_iDeJ53p9gog7_FMIr1dh6iibcNIRcDKCSc-q6f6nA%3D%3D&alr=yes&cpn=woe7lOTrahhyYWcq&cver=1.20240423.01.00&range=747745-1781034&rn=8&rbuf=13315&pot=MnRVVKfOp--0vFVsBFIn80fWOrC9EvrFrVYVt9LRgj77sMMTKVoISha0_4F40ttV96ts_rOFFWs-s24hpXCGazx0vNT0U34AMGPyhm_IjFmfvpL3yNp4GCp-JnS2ofN5zUJaMn1daD_L8IcnYVCSoMYQEhjMIg==&ump=1&srfvp=1 HTTP/1.1Host: rr5---sn-vgqsrnlz.googlevideo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /vi_webp/QpwJEYGCngI/maxresdefault.webp HTTP/1.1Host: i.ytimg.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /api/stats/watchtime?ns=yt&el=embedded&cpn=woe7lOTrahhyYWcq&ver=2&cmt=4.422&fmt=397&fs=0&rt=7.005&euri=https%3A%2F%2Fwww.bing.com%2F&lact=7303&cl=627399198&state=playing&volume=100&cbr=Chrome&cbrver=117.0.0.0&c=WEB_EMBEDDED_PLAYER&cver=1.20240423.01.00&cplayer=UNIPLAYER&cos=Windows&cosver=10.0&cplatform=DESKTOP&autoplay=1&hl=en_US&cr=US&len=1244&rtn=17&afmt=251&idpj=-6&ldpj=-35&rti=7&size=780%3A439&inview=1&st=0&et=4.422&muted=1&au=en-US.4&docid=SrGENEXocJU&ei=TuQrZue5EP_lj-8PtsWc8Ac&plid=AAYXAzxr4G2NzhNf&referrer=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSrGENEXocJU%3Fautoplay%3D1%26enablejsapi%3D1%26origin%3Dhttps%3A%2F%2Fwww.bing.com%26rel%3D0%26mute%3D1&of=P0iDOXD2Nl5QW4mjR62tvQ&vm=CAEQARgEOjJBSHFpSlRLWS1pM0tYMk11ckdUREVNSlZUbGhveTYwanZpXzVmaGR3eHFVWFJWcXRrQWJwQVBta0tETGw1S2o1Y2loRmYwVlA4SFVkd2tSTEdJNjd0emRKRkdlMm5WSVByNzlITFUyQnJpUzlQT2pBME1ESzgzRUpkblB6ZDU0YzJFamU4aVg4cVNQMVVUZGllY1ZZbXJwdHJRUTZyWFk0UjJQcGgC HTTP/1.1Host: www.youtube.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"X-YouTube-Ad-Signals: dt=1714152524356&flash=0&frm=2&u_tz=120&u_his=1&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&bc=31&bih=-12245933&biw=-12245933&brdim=0%2C0%2C0%2C0%2C1280%2C0%2C1280%2C984%2C780%2C439&vis=1&wgl=true&ca_type=imagesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-YouTube-Utc-Offset: 120X-YouTube-Client-Name: 56X-YouTube-Client-Version: 1.20240423.01.00X-YouTube-Time-Zone: Europe/ZurichX-Goog-Visitor-Id: CgsyeU03cGxDTS1pRSjIyK-xBjIKCgJVUxIEGgAgbQ%3D%3Dsec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.youtube.com/embed/SrGENEXocJU?autoplay=1&enablejsapi=1&origin=https://www.bing.com&rel=0&mute=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: YSC=87xkIprz8yI; VISITOR_INFO1_LIVE=2yM7plCM-iE; VISITOR_PRIVACY_METADATA=CgJVUxIEGgAgbQ%3D%3D
Source: chromecache_908.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.facebook.com (Facebook)
Source: chromecache_387.2.dr, chromecache_908.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.linkedin.com (Linkedin)
Source: chromecache_387.2.dr, chromecache_908.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.twitter.com (Twitter)
Source: chromecache_890.2.dr String found in binary or memory: (g.zp(c,"redirector.googlevideo.com"),d=c.toString()):c.j.match("rr?[1-9].*\\.c\\.youtube\\.com$")?(g.zp(c,"www.youtube.com"),d=c.toString()):(c=xBa(d),zJ(c)&&(d=c));c=new g.zP(d);c.set("cmo=pf","1");e&&c.set("cmo=td","a1.googlevideo.com");return c}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: YQa=function(a,b){if(!a.j["0"]){var c=new CK("0","fakesb",{video:new yK(0,0,0,void 0,void 0,"auto")});a.j["0"]=b?new CQ(new g.zP("http://www.youtube.com/videoplayback"),c,"fake"):new NQ(new g.zP("http://www.youtube.com/videoplayback"),c,new mQ(0,0),new mQ(0,0))}}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: a))):this.Ld(g.NV(a.errorMessage)):this.Ld(PV(this,"HTML5_NO_AVAILABLE_FORMATS_FALLBACK_WITH_LINK_SHORT","//www.youtube.com/supported_browsers")):(a=d.hostLanguage,c="//support.google.com/youtube/?p=player_error1",a&&(c=g.Mn(c,{hl:a})),this.Ld(PV(this,"GENERIC_WITH_LINK_AND_CPN",c,!0)),d.pc&&!d.D&&QYa(this,function(e){if(g.tU(e,b.api,!WR(b.api.U()))){e={as3:!1,html5:!0,player:!0,cpn:b.api.getVideoData().clientPlaybackNonce};var f=b.api;f.wc("onFeedbackArticleRequest",{articleId:3037019,helpContext:"player_error", equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: a.BASE_YT_URL)||"")||oBa(this.Bf)||this.protocol+"://www.youtube.com/";h=b?b.eventLabel:a.el;d="detailpage";"adunit"===h?d=this.D?"embedded":"detailpage":"embedded"===h||this.N?d=XB(d,h,ZRa):h&&(d="embedded");this.La=d;Xta();h=null;d=b?b.playerStyle:a.ps;f=g.Fb($Ra,d);!d||f&&!this.N||(h=d);this.playerStyle=h;this.qa=(this.K=g.Fb($Ra,this.playerStyle))&&"play"!==this.playerStyle&&"jamboard"!==this.playerStyle;this.To=!this.qa;this.Ra=WB(!1,a.disableplaybackui);this.disablePaidContentOverlay=WB(!1, equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: a.severity,e,nK(a.details),f)}else this.oa.publish("nonfatalerror",a),d=/^pp/.test(this.videoData.clientPlaybackNonce),this.ue(a.errorCode,a.details),d&&"manifest.net.connect"===a.errorCode&&(a="https://www.youtube.com/generate_204?cpn="+this.videoData.clientPlaybackNonce+"&t="+(0,g.$C)(),FX(a,"manifest",function(h){b.G=!0;b.ma("pathprobe",h)},function(h){b.ue(h.errorCode,h.details)}))}}; equals www.youtube.com (Youtube)
Source: chromecache_559.2.dr String found in binary or memory: function Hr(a,b,c){this.o=this.g=this.h=null;this.i=0;this.G=!1;this.u=[];this.l=null;this.O={};if(!a)throw Error("YouTube player element ID required.");this.id=Ra(this);this.K=c;c=document;if(a="string"===typeof a?c.getElementById(a):a)if(c="iframe"===a.tagName.toLowerCase(),b.host||(b.host=c?ec(a.src):"https://www.youtube.com"),this.h=new Br(b),c||(b=Ir(this,a),this.o=a,(c=a.parentNode)&&c.replaceChild(b,a),a=b),this.g=a,this.g.id||(this.g.id="widget"+Ra(this.g)),vr[this.g.id]=this,window.postMessage){this.l= equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: g.UR=function(a){a=SR(a.Ga);return"www.youtube-nocookie.com"===a?"www.youtube.com":a}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: g.Va("Goog_AdSense_Lidar_getUrlSignalsList",wjb);var gBa=pa(["//tpc.googlesyndication.com/sodar/",""]);var cNa={F5a:0,C5a:1,z5a:2,A5a:3,B5a:4,E5a:5,D5a:6};var npa=(new Date).getTime();var Pka="://secure-...imrworldwide.com/ ://cdn.imrworldwide.com/ ://aksecure.imrworldwide.com/ ://[^.]*.moatads.com ://youtube[0-9]+.moatpixel.com ://pm.adsafeprotected.com/youtube ://pm.test-adsafeprotected.com/youtube ://e[0-9]+.yt.srs.doubleverify.com www.google.com/pagead/xsul www.youtube.com/pagead/slav".split(" "),Qka=/\bocr\b/;var Ska=/(?:\[|%5B)([a-zA-Z0-9_]+)(?:\]|%5D)/g;g.y(Yu,g.Dd);Yu.prototype.dispose=function(){window.removeEventListener("offline",this.C);window.removeEventListener("online",this.C);this.Qn.Mj(this.G);delete Yu.instance}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: g.fS=function(a){var b=g.UR(a);oSa.includes(b)&&(b="www.youtube.com");return a.protocol+"://"+b}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: g.k.getVideoUrl=function(a,b,c,d,e,f){b={list:b};c&&(e?b.time_continue=c:b.t=c);c=g.UR(this);e="www.youtube.com"===c;!f&&d&&e?f="https://youtu.be/"+a:g.OR(this)?(f="https://"+c+"/fire",b.v=a):(f&&e?(f=this.protocol+"://"+c+"/shorts/"+a,d&&(b.feature="share")):(f=this.protocol+"://"+c+"/watch",b.v=a),pD&&(a=cpa())&&(b.ebc=a));return g.Mn(f,b)}; equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: r;this.jj=b?b.hl||"en_US":ZB("en_US",a.hl);this.region=b?b.contentRegion||"US":ZB("US",a.cr);this.hostLanguage=b?b.hostLanguage||"en":ZB("en",a.host_language);this.No=!this.Dc&&Math.random()<g.YI(this.experiments,"web_player_api_logging_fraction");this.bb=!this.Dc;this.enabledEngageTypes=new Set;this.deviceIsAudioOnly=!(null==b||!b.deviceIsAudioOnly);this.Jd=YB(this.Jd,a.ismb);this.To?(r=a.vss_host||"s.youtube.com","s.youtube.com"===r&&(r=SR(this.Ga)||"www.youtube.com")):r="video.google.com";this.Wm= equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: this.W.Ba&&(a.authuser=this.W.Ba);this.W.pageId&&(a.pageid=this.W.pageId);isNaN(this.cryptoPeriodIndex)||(a.cpi=this.cryptoPeriodIndex.toString());var e=(e=/_(TV|STB|GAME|OTT|ATV|BDP)_/.exec(g.pc()))?e[1]:"";"ATV"===e&&(a.cdt=e);this.G=a;this.G.session_id=d;this.qa=!0;"widevine"===this.B.flavor&&(this.G.hdr="1");"playready"===this.B.flavor&&(b=Number(pR(b.experiments,"playready_first_play_expiration")),!isNaN(b)&&0<=b&&(this.G.mfpe=""+b),this.qa=!1);b="";g.iR(this.B)?hR(this.B)?(d=c.B)&&(b="https://www.youtube.com/api/drm/fps?ek="+ equals www.youtube.com (Youtube)
Source: chromecache_890.2.dr String found in binary or memory: var G3={};var Cfb=/[&\?]action_proxy=1/,Bfb=/[&\?]token=([\w-]*)/,Dfb=/[&\?]video_id=([\w-]*)/,Efb=/[&\?]index=([\d-]*)/,Ffb=/[&\?]m_pos_ms=([\d-]*)/,Hfb=/[&\?]vvt=([\w-]*)/,tfb="ca_type dt el flash u_tz u_his u_h u_w u_ah u_aw u_cd u_nplug u_nmime frm u_java bc bih biw brdim vis wgl".split(" "),Gfb="www.youtube-nocookie.com youtube-nocookie.com www.youtube-nocookie.com:443 youtube.googleapis.com www.youtubeedu.com www.youtubeeducation.com video.google.com redirector.gvt1.com".split(" "),wfb={android:"ANDROID", equals www.youtube.com (Youtube)
Source: chromecache_546.2.dr String found in binary or memory: var VideoCanvasForEmbeddedYTPlayer;(function(n){function o(i){var h,b=i===null||i===void 0?void 0:i[0],f,o;if(b&&(u||b!=(t===null||t===void 0?void 0:t.EmbedPlayer_ComponentUpdate))&&(!u||b!=(t===null||t===void 0?void 0:t.EmbedPlayer_Init))){if(!r&&i&&i.length>1){if(f=i[1],(f===null||f===void 0?void 0:f.playerKey)&&f.playerKey==n._playerKey)return;n._playerKey=f.playerKey;o=(h=f.playerConfig)===null||h===void 0?void 0:h.ytpc;o&&(r=o.ytpi,a=o.lpi,u=o.epiocu);typeof({}===null||{}===void 0?void 0:{}.trace)===y&&f}if(!r&&e&&e.ytp&&e.ytpid&&(r=e.ytpid),pMMUtils&&r&&_ge(r))if(_w.onYouTubeIframeAPIReady=s,c){if(u){w(i);return}a||s(i)}else l||(l=!0,ct(),sj_be(_w,"unload",p),it())}}function h(){lt();i&&i.getIframe()&&i.destroy();YT=undefined}function p(){h();sj_ue(_w,"unload",p)}function it(){var t=document.createElement("script"),n;t.src="https://www.youtube.com/iframe_api";n=document.getElementsByTagName("script")[0];n.parentNode.insertBefore(t,n)}function s(n){c=!0;w(n)}function w(t){if(t&&t.length>1){var u=t[1];if((u===null||u===void 0?void 0:u.playerKey)&&u.playerKey==n._playerKey)return;n._playerKey=u.playerKey}typeof YT!="undefined"&&typeof YT.Player!="undefined"&&(i=new YT.Player(r,{events:{onReady:ut,onStateChange:ft,onError:et}}),typeof({}===null||{}===void 0?void 0:{}.trace)===y&&i,sj_be(_w,"message",rt))}function rt(n){var u,f=(u=i===null||i===void 0?void 0:i.getIframe())===null||u===void 0?void 0:u.contentWindow,r;if(n&&f&&(n===null||n===void 0?void 0:n.source)===f&&typeof(n===null||n===void 0?void 0:n.data)=="string")try{r=JSON.parse(n.data);r&&r.event==="infoDelivery"&&r.info&&sj_evt.fire(t===null||t===void 0?void 0:t.VideoPlayer_InfoUpdate,r.info)}catch(e){}}function ut(n){f=!0;var i={videoDuration:ot()};i.videoDuration&&i.videoDuration!=-1||(i.videoDuration=st(n));sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoPlayerReady,i)}function ft(n){var i=YT===null||YT===void 0?void 0:YT.PlayerState;if(i&&n)switch(n.data){case i.UNSTARTED:sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoUnStarted);break;case i.ENDED:sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoEnded);break;case i.PLAYING:sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoPlaying);break;case i.PAUSED:sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoStopped);break;case i.BUFFERING:sj_evt.fire(t===null||t===void 0?void 0:t.VideoCanvas_VideoStopped)}}function et(n){tt.isTest()&&console&&console.log("YT.Player Error: "+n.data);sj_evt.fire("VideoCanvas.VideoPlayerError",n.data)}function b(n){if(n&&!(n.length<2)&&n[1]){var t=n[1],i=t.seekTime,r=t.enableSeekAhead,u=t.enableSeekBack;typeof i=="number"&&i>=0&&d(i,r,u)}}function k(n){if(typeof i!="undefined"&&n&&!(n.length<2)){var t=n[1];t==!0?typeof(i===null||i===void 0?void 0:i.mute)=="function"&&i.mute():typeof(i===null||i===void 0?void 0:i.unMute)=="function"&&i.unMute()}}function d(n,t,r){var u=g();return(n>u&&t||n<u&&r)&&i&&f&&typeof i.seekTo!="undefined"?(i.seekTo(n,!0),!0):!1}functi
Source: chromecache_369.2.dr String found in binary or memory: var scriptUrl = 'https:\/\/www.youtube.com\/s\/player\/652ba3a2\/www-widgetapi.vflset\/www-widgetapi.js';window['yt_embedsEnableIframeDefaultReferrerPolicy'] = true ;try{var ttPolicy=window.trustedTypes.createPolicy("youtube-widget-api",{createScriptURL:function(x){return x}});scriptUrl=ttPolicy.createScriptURL(scriptUrl)}catch(e){}var YT;if(!window["YT"])YT={loading:0,loaded:0};var YTConfig;if(!window["YTConfig"])YTConfig={"host":"https://www.youtube.com"}; equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: aefd.nelreports.net
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: assets.msn.com
Source: global traffic DNS traffic detected: DNS query: www.msn.com
Source: global traffic DNS traffic detected: DNS query: services.bingapis.com
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: browser.events.data.msn.com
Source: global traffic DNS traffic detected: DNS query: c.msn.com
Source: global traffic DNS traffic detected: DNS query: tse4.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: tse3.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: tse1.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: tse2.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: www.youtube.com
Source: global traffic DNS traffic detected: DNS query: i.ytimg.com
Source: global traffic DNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: static.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: yt3.ggpht.com
Source: global traffic DNS traffic detected: DNS query: rr5---sn-vgqsrnlz.googlevideo.com
Source: unknown HTTP traffic detected: POST /report/ESTS-UX-All HTTP/1.1Host: csp.microsoft.comConnection: keep-aliveContent-Length: 2412sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/csp-reportAccept: */*Origin: https://login.microsoftonline.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: reportReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_488.2.dr String found in binary or memory: http://adaptivecards.io/schemas/adaptive-card.json
Source: chromecache_513.2.dr, chromecache_405.2.dr String found in binary or memory: http://feross.org
Source: chromecache_869.2.dr String found in binary or memory: http://knockoutjs.com/
Source: chromecache_890.2.dr, chromecache_559.2.dr, chromecache_371.2.dr String found in binary or memory: http://tools.ietf.org/html/rfc1950
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: http://www.foreca.com
Source: chromecache_869.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_890.2.dr String found in binary or memory: http://www.youtube.com/videoplayback
Source: chromecache_890.2.dr String found in binary or memory: http://youtube.com/drm/2012/10/10
Source: chromecache_890.2.dr String found in binary or memory: http://youtube.com/streaming/metadata/segment/102015
Source: chromecache_890.2.dr String found in binary or memory: http://youtube.com/streaming/otf/durations/112015
Source: chromecache_890.2.dr String found in binary or memory: http://youtube.com/yt/2012/10/10
Source: chromecache_890.2.dr String found in binary or memory: https://admin.youtube.com
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/background/v2.0/jpg/
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/LFlOFwA=/Condition/
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/taskbar_v10/
Source: chromecache_641.2.dr String found in binary or memory: https://bugs.chromium.org/p/v8/issues/detail?id=3056
Source: chromecache_641.2.dr String found in binary or memory: https://bugs.chromium.org/p/v8/issues/detail?id=4118
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://cafemom.com/parenting/224132-baby-names-parents-will-never-regret
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://cafemom.com/parenting/225158-man-names-baby-same-thing-as-brother
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://cafemom.com/parenting/tiktok-experts-controversial-hot-take-on-baby-names
Source: chromecache_404.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gKhb
Source: chromecache_404.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gKhb-dark
Source: chromecache_404.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13glq6
Source: chromecache_404.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13glq6-dark
Source: chromecache_559.2.dr String found in binary or memory: https://developers.google.com/youtube/iframe_api_reference#Events
Source: chromecache_890.2.dr String found in binary or memory: https://docs.google.com/get_video_info
Source: chromecache_718.2.dr String found in binary or memory: https://edition.cnn.com/2024/02/26/food/outback-steakhouse-closures/index.html
Source: chromecache_804.2.dr String found in binary or memory: https://fb.me/react-polyfills
Source: chromecache_869.2.dr String found in binary or memory: https://github.com/douglascrockford/JSON-js
Source: chromecache_890.2.dr, chromecache_559.2.dr, chromecache_371.2.dr String found in binary or memory: https://github.com/madler/zlib/blob/master/zlib.h
Source: chromecache_579.2.dr String found in binary or memory: https://highlightjs.org/
Source: chromecache_890.2.dr String found in binary or memory: https://i.ytimg.com/vi/
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA13slaS.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA188qIE.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nIuZ6.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nmhpC.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nmhpz.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnOZD.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnRrv.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnU4F.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nvuDZ.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nvx84.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nvzHv.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nxkGh.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nxnkX.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nxnl2.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAwgl5h.img
Source: chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1e6XdQ.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1ihPB9.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1ihWxd.img
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1ii3Ik.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1lLZQH.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1lLZRq.img
Source: chromecache_718.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1lM4lU.img
Source: chromecache_890.2.dr String found in binary or memory: https://jnn-pa.googleapis.com
Source: chromecache_871.2.dr, chromecache_728.2.dr String found in binary or memory: https://login.chinacloudapi.cn
Source: chromecache_944.2.dr String found in binary or memory: https://login.live.com/login.srf?wa=wsignin1.0
Source: chromecache_871.2.dr, chromecache_728.2.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_871.2.dr, chromecache_728.2.dr String found in binary or memory: https://login.microsoftonline.de
Source: chromecache_871.2.dr, chromecache_728.2.dr String found in binary or memory: https://login.microsoftonline.us
Source: chromecache_871.2.dr, chromecache_728.2.dr String found in binary or memory: https://login.windows-ppe.net
Source: chromecache_488.2.dr String found in binary or memory: https://msasg.visualstudio.com/Bing_Ads/_workitems/edit/3905327
Source: chromecache_488.2.dr String found in binary or memory: https://msasg.visualstudio.com/ContentServices/_workitems/edit/3620803
Source: chromecache_371.2.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://prod-streaming-video-msn-com.akamaized.net/59a18f1a-e762-490c-a8d0-e89a3d8111e9/3770951d-c67
Source: chromecache_404.2.dr String found in binary or memory: https://prod-streaming-video-msn-com.akamaized.net/c93a164f-41e5-4c79-9169-c10768462ad4/3770951d-c67
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://prod-video-cms-amp-microsoft-com.akamaized.net/tenant/amp/entityid/AA1nFMp1?blobrefkey=close
Source: chromecache_804.2.dr String found in binary or memory: https://reactjs.org/docs/error-decoder.html?invariant=
Source: chromecache_890.2.dr String found in binary or memory: https://redux.js.org/api/store#subscribelistener
Source: chromecache_890.2.dr String found in binary or memory: https://redux.js.org/tutorials/fundamentals/part-4-store#creating-a-store-with-enhancers
Source: chromecache_890.2.dr String found in binary or memory: https://redux.js.org/tutorials/fundamentals/part-4-store#middleware
Source: chromecache_890.2.dr String found in binary or memory: https://redux.js.org/tutorials/fundamentals/part-6-async-logic#using-the-redux-thunk-middleware
Source: chromecache_404.2.dr String found in binary or memory: https://stacker.com/
Source: chromecache_944.2.dr String found in binary or memory: https://storage.live.com/users/0x
Source: chromecache_890.2.dr String found in binary or memory: https://support.google.com/youtube/?p=missing_quality
Source: chromecache_890.2.dr String found in binary or memory: https://support.google.com/youtube/?p=noaudio
Source: chromecache_890.2.dr String found in binary or memory: https://support.google.com/youtube/?p=report_playback
Source: chromecache_890.2.dr String found in binary or memory: https://support.google.com/youtube/answer/6276924
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://today.yougov.com/ratings/food/popularity/dining-brands/all
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://today.yougov.com/ratings/overview/popularity(popup:ratings/faq)
Source: chromecache_890.2.dr String found in binary or memory: https://viacon.corp.google.com
Source: chromecache_404.2.dr String found in binary or memory: https://www.bangordailynews.com/2022/09/12/politics/heating-oil-prices-maine-elections-joam40zk0w/
Source: chromecache_404.2.dr String found in binary or memory: https://www.coli.org/about/
Source: chromecache_890.2.dr String found in binary or memory: https://www.googleapis.com/certificateprovisioning/v1/devicecertificates/create?key=AIzaSyB-5OLKTx2i
Source: chromecache_890.2.dr String found in binary or memory: https://www.gstatic.com/ytlr/img/sign_in_avatar_default.png?rn=
Source: chromecache_488.2.dr String found in binary or memory: https://www.lotteryusa.com/mega-millions/
Source: chromecache_488.2.dr String found in binary or memory: https://www.lotteryusa.com/powerball/
Source: chromecache_404.2.dr String found in binary or memory: https://www.mainepublic.org/business-and-economy/2022-09-13/maines-minimum-wage-to-boost-to-1
Source: chromecache_488.2.dr String found in binary or memory: https://www.msn.com/$
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/foodanddrink/foodnews/the-1-restaurant-chain-in-america-according-to-diner
Source: chromecache_718.2.dr String found in binary or memory: https://www.msn.com/en-us/foodanddrink/foodnews/the-only-way-you-should-store-hot-sauce-according-to
Source: chromecache_718.2.dr String found in binary or memory: https://www.msn.com/en-us/money/careersandeducation/a-psychology-expert-shares-5-toxic-phrases-highl
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/money/realestate/here-is-the-true-value-of-having-a-fully-paid-off-home-in
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/movies/news/megan-fox-signs-with-uta/ar-AA1nB9M0
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/opinion/carbine-vs-rifle-what-exactly-is-the-difference/ar-AA1kNwFb
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/politics/a-big-mistake-ex-trump-white-house-lawyer-reacts-to-trump-s-
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/politics/mitch-mcconnell-breaks-with-trump-on-absolute-presidential-i
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/technology/scientists-discover-gigantic-structure-under-the-surface-o
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/us/nypd-chief-hits-back-at-aoc-over-columbia-anti-israel-protests-sel
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/us/the-movement-will-persist-advocates-stress-weinstein-reversal-does
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/us/united-methodists-vote-to-restructure-worldwide-church/ar-AA1nFTLp
Source: chromecache_718.2.dr String found in binary or memory: https://www.msn.com/en-us/news/world/10-foot-tall-people-discovered-by-archaeologists-in-nevada-cave
Source: chromecache_404.2.dr String found in binary or memory: https://www.msn.com/en-us/news/world/saudi-arabia-spent-500b-to-build-a-futuristic-city-in-the-deser
Source: chromecache_718.2.dr String found in binary or memory: https://www.nrn.com/casual-dining/outback-steakhouse-parent-bloomin-brands-closing-41-restaurants
Source: chromecache_404.2.dr String found in binary or memory: https://www.nytimes.com/2022/09/06/business/energy-environment/winter-home-heating.html
Source: chromecache_718.2.dr, chromecache_404.2.dr String found in binary or memory: https://www.pollensense.com/
Source: chromecache_776.2.dr String found in binary or memory: https://www.suno.ai/legal/privacy
Source: chromecache_776.2.dr String found in binary or memory: https://www.suno.ai/legal/terms
Source: chromecache_723.2.dr String found in binary or memory: https://www.suno.ai/privacy)
Source: chromecache_723.2.dr String found in binary or memory: https://www.suno.ai/terms)
Source: chromecache_404.2.dr String found in binary or memory: https://www.theatlantic.com/business/archive/2012/03/why-some-countries-and-cities-are-so-much-more-
Source: chromecache_404.2.dr String found in binary or memory: https://www.wbur.org/news/2022/08/29/northeast-diesel-heating-oil-supplies-below-average
Source: chromecache_369.2.dr, chromecache_559.2.dr String found in binary or memory: https://www.youtube.com
Source: chromecache_890.2.dr String found in binary or memory: https://www.youtube.com/api/drm/fps?ek=
Source: chromecache_890.2.dr String found in binary or memory: https://www.youtube.com/generate_204?cpn=
Source: chromecache_546.2.dr String found in binary or memory: https://www.youtube.com/iframe_api
Source: chromecache_890.2.dr String found in binary or memory: https://youtu.be/
Source: chromecache_890.2.dr String found in binary or memory: https://youtube.com/api/drm/fps?ek=uninitialized
Source: chromecache_890.2.dr String found in binary or memory: https://youtubei.googleapis.com/youtubei/
Source: chromecache_890.2.dr String found in binary or memory: https://yurt.corp.google.com
Source: unknown Network traffic detected: HTTP traffic on port 50684 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50578
Source: unknown Network traffic detected: HTTP traffic on port 50678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50523 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50694
Source: unknown Network traffic detected: HTTP traffic on port 50632 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50695
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50698
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50697
Source: unknown Network traffic detected: HTTP traffic on port 50706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50626 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50625
Source: unknown Network traffic detected: HTTP traffic on port 50578 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50627
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50626
Source: unknown Network traffic detected: HTTP traffic on port 50687 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50583
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50587
Source: unknown Network traffic detected: HTTP traffic on port 50673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50537 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50118
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50637
Source: unknown Network traffic detected: HTTP traffic on port 50682 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50632
Source: unknown Network traffic detected: HTTP traffic on port 50676 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50538 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50643 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50523
Source: unknown Network traffic detected: HTTP traffic on port 50637 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50549 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50685 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50640
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50643
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50522
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50642
Source: unknown Network traffic detected: HTTP traffic on port 50541 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50566 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50583 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 50640 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50537
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50536
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50538
Source: unknown Network traffic detected: HTTP traffic on port 50688 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50536 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50565 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50697 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50666
Source: unknown Network traffic detected: HTTP traffic on port 50683 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50549
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50705
Source: unknown Network traffic detected: HTTP traffic on port 50702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50522 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50024
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50541
Source: unknown Network traffic detected: HTTP traffic on port 50707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50694 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50642 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50707
Source: unknown Network traffic detected: HTTP traffic on port 50680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50625 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50678
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50677
Source: unknown Network traffic detected: HTTP traffic on port 50281 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50672
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50673
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50676
Source: unknown Network traffic detected: HTTP traffic on port 50050 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50281
Source: unknown Network traffic detected: HTTP traffic on port 50024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50695 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50666 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50688
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50680
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50683
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50682
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50685
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50684
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50566
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50687
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50565
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50686
Source: unknown Network traffic detected: HTTP traffic on port 50587 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50050
Source: unknown Network traffic detected: HTTP traffic on port 50627 -> 443
Source: classification engine Classification label: clean0.win@32/991@70/16
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://go.microsoft.com/fwlink/?LinkId=787651."
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5868 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5784 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5868 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5784 --field-trial-handle=1980,i,6518399980718777175,8631270052608312574,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs