Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://xn--r1a.website/s/ogorodru

Overview

General Information

Sample URL:http://xn--r1a.website/s/ogorodru
Analysis ID:1514812
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Connects to several IPs in different countries
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 4900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1880 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1720,i,7126892294250420465,11752881237129370253,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6356 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://xn--r1a.website/s/ogorodru" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://xn--r1a.website/s/ogorodruAvira URL Cloud: detection malicious, Label: phishing
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49752 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49768 version: TLS 1.2
Source: unknownNetwork traffic detected: IP country count 11
Source: global trafficTCP traffic: 192.168.2.4:64983 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 167.235.7.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 195.201.108.196
Source: unknownTCP traffic detected without corresponding DNS query: 195.201.108.196
Source: unknownTCP traffic detected without corresponding DNS query: 195.201.108.196
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: unknownTCP traffic detected without corresponding DNS query: 193.232.150.148
Source: global trafficHTTP traffic detected: GET /file/BDoevstmwc-LH-sbj-OyBhlAr9f_8REM5GylyjUbzp0C14JNGE0luefvosada74HY1heslHYjIFTJqYowqHZW2U0Ud55ISGdzPYMuUbsvK0U7jqDYY-QLs3IPVb2zbi0EMPrw82DmDiXtGfIl_nXcDU-a02mI72VHUBwEsB8wPyHqiKczgkPdhtL1n1sOO-1c3RWSQMS52k5nV_uHDjd1h8NFSl9LNRD-BGQdwhHx5IRdErI4RlKKXdjeDtsd-MzL846KS9mGB6U7PDlMoKR93EFw9CuEkhZl3NsVJvFI6ObKpJ6EdDOS9ZZBfCfFHU7de_YfmsbShE42TJI1yJqEA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/J5IrM8TywMmqx4ZfsUIWmzOHXcIjMdle0j0Zye8AO8h7bW7lhRtHf3rwMLDqu1isIJ0dw4EPOjBNlHAyHkNkqgqqjh8bR4nUqiAq6P_Ej9AZoBXBJeew5Cc4vlPcPkF_wYV80A7hegzAshbhSvXqCnDH5V6aOOf7JlRhjqTNYlbVwc86WiQGXK-PYmGGLWbETscY3DjcM5yPhiNFExJeNB4Vmje0RXBoV0ZTy6_9TRw07Sxw2e1uNLWxPedOdw1hodtMeSZKBpnDOCWgw8at3icavvKT6l06C2LJfPQsvc5AA8D84CylCQg4KJNRiSPyY75fex2yWcr7nk-SqIErpQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/TTkkD8vhw02tx6_lfOH_DCMJAewkY3MM9tiBVlKvkpzhsmMyB-J7bK0oKXpRQAccMp4OsJZMDFmm77EQ8GXduS6izr7JT1sss2JT2zIYl3jTiqOmnwx6SSAW_sNUDqovktr6YzgXP5gad40Yl5ZDNcelYrbftB8jlkqU6fDclHTdBlT8ExxMNtKw1g0UgGpSAe5GFmS8qZgjDz83K9GeJaNmzqAYCvxMdvGKo5_ZiDVfwBW4QAsJ_hKx5Kj4ABcDlMYEX4OdhB4Ym9BKT2MWrwZZtxDk0EJJSX4aUmOFMGae7G3ZIuSvgOaKT7JW9bQO_NQCTsVAxXSflL8MYYmy7Q.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/mXNwO8DVSXSRafJGfW3LoeUmuU7fidfGqSIAOB8lQIWxs_fxBvKHG0GSvd55EDulEM7uLm8GNgtQG3Wlwc8F2i-Z3d1LlZ4ymAUsAMGc6EYEL8dhxVM3aWiifE5vTAupsOw_VDcNkrzbe3dlIJ2Q7OPwK8nO0ht-SBE_F9i58duZcVAzbCmXRvBqz2-PN6RZaEIy3iFnnzTILo40fVObac7AyFeYjc1G1Hv6LtBLAFiUrGDE-geNNOWqpCIVaGwrQTf2Nbrn5eRUTk8C_k6r88VkZjxHOEAKXEBdkkF2XtsElsfAfvOemPQ7gBDKXPx72NEce3eyKrUOcjvnlQORkg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/FmiN1jd6kyJcAeWZgqW4F1M6SO2Eq2RyWTZW_blsnSEOdaGcnsZyCyUn7iIiSZTDSWAItP34AXMi8zvOoqM-IcdUp3TUVCz0MhcVRIWT4BXCt3eTxwYPub8hQGapqCMCUQQ656ysDa7TxKg2_iJgkXF8jnWEsubIs0Q7ol6Ma4rq1Tj21ueeiPUmscCaomkBd2JrnI_qU6CxtVAC7Dn7w-z6QsmN4TePjVK8NNkb7liOQWKnbxGEfgDyDriRvwLWSnaFj8kfRICBMhevGgqVyW0k0KWygDnfKeiWFwAmnmNtvGOtou8h7HZNKTgQEuX-Z2IvurSOcnyALF6aJtSGUg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/system/header-bidding.js HTTP/1.1Host: yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/MRaZr89OCD5Qq9z9INWqGZsk0QSCS36uQSIbQJrq-YdzjVbiaMkbpeXSl1tcB8ZOu5KUs8WzGcfEXddbIVY78z_o8V0IxYibiI4BQsVCubSLMz_lP7idln0bE9i4LU0cr-irveRblfIb2UsB_mN-LI087zClUs3TsB41pQ-pQjAuG9DOmSM9WJDISYjfHg-P2VQOWNeOzARqN_JEa9FzI3lf0xVBuRxjgqwm2ZSf-JgZE5vXLDKKYw2nq41qEvh3ltHN9c_9kF9mUtaVqBhU01z7Ipud_44CPBNBH4BMYOWsZzxLMtqUmCN_GfmitAifPzbWiYtNo8envAOO5HmUUg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/JitwEocrGUIsjF7lIVjj81yr99dSOamCXttyW3h-_YJH6F1KYV6qX3iEpHS1nPcEz03nUgOqM9XNa9FbMUsIldglc_Qd9dDVe-Eh9K4cJMOY0AQB78C7CvcLX1boV-UWvh7bEYn87eEeCJM74wYIecz1VUC0dvUSsobArVa0tGYZWpy6eQLxELg5heZS6J_caSMAPmS2xCwwdiCblU0NbmbXanM9fi1RYPQOksZVCklr1QcQz-YHEHNnN8xA7JwcZjCbsWxPZenPnNKQCr5Om6muF5s6PeHKRz7rFNa_Y9N0a6V2-o9ap0ve1s0WFFa_W2TKh266_aX8cFNo1ovPNA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/rkk8WbtOH5kDN2Bvh89DE_-q7p6ydKIypCA8qrMoOqnzWuwss2N-4z7JZG8Isbr6ditAmqyfNXwvxeK_2KrdtV6D3-ex5jk64o7V6OPM94oIlbQGJ7hvbexd-6T-UWP_dZI9laui89-InBxC8i1BOjgwXy9o-5877cfMOYnFuqWMSrcLEmuUnE-TUnbvwybZDVJFUsjpvdmaWH7v4hkhcVImSq8bKofyeoaPhl9gH5O28uw9fFlcuMNxWsFOV4ulnqwIQ4coLZR2jr13R24M23Qp1EOW699OASic2AiATScyldwQ1RogzDMI-mCJVh2Rm3qGwbrQFNHwHIqvVaUqgQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/MSpszLg7U46su23KMCgH8A98mn1j0p2-6wBkxrguTs8yEhVA-oaBykeBGHnbmDgMIfkKoJwjFD22bkLCfzLXC_nZkOpn_IvNZWrn4lKleup8F9gallYy7JfpvqYPTDBOfKk_NhPPOXvBte8UjBr8p6BNiekhw_wgidfU07LtxhQxhg-yfs8gODhc8KhI3B2tedOpJt4s3gCKcD8iwg0mvt8ypGShZW-IqnTMdSM6viCBG3d1niNKp-WAIbJqf_Nqt8CF3bJxTZyy07G2fU3oAZBZC0t3aiIqapI8FAZf_TqIt9ENGUPFJdG1adRWyp65Tdcs7sWd9lUAw3udNMgwxA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/system/context.js HTTP/1.1Host: yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=GmNVkS+1q5EG+QZWaZequSAdEsZAYIQJqYkSXqpBiBW8RHxpVAeNYZqWeWLxv59vOg/zx7VfGq3GoEcsNjaaQUQpdjA=; yandexuid=1141320511726872524; yashr=6680397161726872524; receive-cookie-deprecation=1; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYMz3t7cGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
Source: global trafficHTTP traffic detected: GET /js/xn--r1a.website.js?ts=1726872521522 HTTP/1.1Host: ads.digitalcaramel.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /getcookie HTTP/1.1Host: matchid.adfox.yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=GmNVkS+1q5EG+QZWaZequSAdEsZAYIQJqYkSXqpBiBW8RHxpVAeNYZqWeWLxv59vOg/zx7VfGq3GoEcsNjaaQUQpdjA=; yandexuid=1141320511726872524; yashr=6680397161726872524; receive-cookie-deprecation=1; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYMz3t7cGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /file/oEMIEzb1yTVBpW6MCUIUeeC2t40SZSMsbVRJJjyKs9mRAbrW--7Ue4_Iy0eBbvSSVVgELurmU-qaGFOiQ0xeEH7ltY329lR7ZMlNTABIskg4fS4M776FzjOm8YQ04V5PpLyo-CQ8nHlJX89Wfm1QVx11GmkY_Ad4rcDaVpCQzNsS-ekKPYDT2fTzWQEeW3CrPjYyxQIeSmLtqGrHHC1v6bQatqQywbR_L1XBI8Er-l7eY-TxX83PtrKirkybMrEckzy4qbQueRWGTXQFwknveFmdzqSFguOPtnexomnO6sH5mxBl33ouBAAOzyU6hHNkkcbpoKbkHVycq-fpqjLgCQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/ELzs1UgArxHStzcD91QUa9uaL2ddyRSFVOb32HZ5Q7SZLZI9SN8-CvHqkdeSTXz-1FJOHYLyaLzDpUXHrn-3RXYO_4I8oBD9yzwbCHmFeXODLfgUkIjYaugi2NfHyyx86_OZkKL2-vj668ki5vH1mtUCpu871TMMon8057k3jLN1Ba5qNzugM2DrntzGDSlJ045JcFoOh8aLOX3xkDOc0zE2t5O1lQOe8IC-8rtsvjePL8Yyh3HfF-P4WjILj0PfQgv1i7-JHb-jW_hkPmRAB42Uq2-m9whBNQYgypUynBNyLqkApbiUN7qdshWXE3jjbrm5i1asFn_Nd1GtMbAZpA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/UFNhm7mbEFhB4QrlFgeburrHC3qsTU_P4QzBqpQl7FLGcglXyHwWnn38h1ag9ExV45hNk6v_-VbYoQ2dWzNlG-3HYnELtf553wjaYxDUy2T-b3mxSNS1VcUcsBF0KBR0wC7tzEoFaaFc2-PVjgMhDGUWoBZ1wf0AdPaK-ioNRsa6Hz67S3ThrSQdwaBG2LGo-xHuFMnqvj1nlD-9cNYR9P2pbjuMAxNgIcMtrxJtqgo_YYaI2R_CE0NkOZ9bFw1h-bl__7xhxn0d5NS7SSNjaV91vsGff9xShp_k-qFgfLp7-_9fbSGyA0tWrLMwZK-rdRTLJ_BB2vDmw2YDk2quZg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/FmiN1jd6kyJcAeWZgqW4F1M6SO2Eq2RyWTZW_blsnSEOdaGcnsZyCyUn7iIiSZTDSWAItP34AXMi8zvOoqM-IcdUp3TUVCz0MhcVRIWT4BXCt3eTxwYPub8hQGapqCMCUQQ656ysDa7TxKg2_iJgkXF8jnWEsubIs0Q7ol6Ma4rq1Tj21ueeiPUmscCaomkBd2JrnI_qU6CxtVAC7Dn7w-z6QsmN4TePjVK8NNkb7liOQWKnbxGEfgDyDriRvwLWSnaFj8kfRICBMhevGgqVyW0k0KWygDnfKeiWFwAmnmNtvGOtou8h7HZNKTgQEuX-Z2IvurSOcnyALF6aJtSGUg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/J5IrM8TywMmqx4ZfsUIWmzOHXcIjMdle0j0Zye8AO8h7bW7lhRtHf3rwMLDqu1isIJ0dw4EPOjBNlHAyHkNkqgqqjh8bR4nUqiAq6P_Ej9AZoBXBJeew5Cc4vlPcPkF_wYV80A7hegzAshbhSvXqCnDH5V6aOOf7JlRhjqTNYlbVwc86WiQGXK-PYmGGLWbETscY3DjcM5yPhiNFExJeNB4Vmje0RXBoV0ZTy6_9TRw07Sxw2e1uNLWxPedOdw1hodtMeSZKBpnDOCWgw8at3icavvKT6l06C2LJfPQsvc5AA8D84CylCQg4KJNRiSPyY75fex2yWcr7nk-SqIErpQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/BDoevstmwc-LH-sbj-OyBhlAr9f_8REM5GylyjUbzp0C14JNGE0luefvosada74HY1heslHYjIFTJqYowqHZW2U0Ud55ISGdzPYMuUbsvK0U7jqDYY-QLs3IPVb2zbi0EMPrw82DmDiXtGfIl_nXcDU-a02mI72VHUBwEsB8wPyHqiKczgkPdhtL1n1sOO-1c3RWSQMS52k5nV_uHDjd1h8NFSl9LNRD-BGQdwhHx5IRdErI4RlKKXdjeDtsd-MzL846KS9mGB6U7PDlMoKR93EFw9CuEkhZl3NsVJvFI6ObKpJ6EdDOS9ZZBfCfFHU7de_YfmsbShE42TJI1yJqEA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/TTkkD8vhw02tx6_lfOH_DCMJAewkY3MM9tiBVlKvkpzhsmMyB-J7bK0oKXpRQAccMp4OsJZMDFmm77EQ8GXduS6izr7JT1sss2JT2zIYl3jTiqOmnwx6SSAW_sNUDqovktr6YzgXP5gad40Yl5ZDNcelYrbftB8jlkqU6fDclHTdBlT8ExxMNtKw1g0UgGpSAe5GFmS8qZgjDz83K9GeJaNmzqAYCvxMdvGKo5_ZiDVfwBW4QAsJ_hKx5Kj4ABcDlMYEX4OdhB4Ym9BKT2MWrwZZtxDk0EJJSX4aUmOFMGae7G3ZIuSvgOaKT7JW9bQO_NQCTsVAxXSflL8MYYmy7Q.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/mXNwO8DVSXSRafJGfW3LoeUmuU7fidfGqSIAOB8lQIWxs_fxBvKHG0GSvd55EDulEM7uLm8GNgtQG3Wlwc8F2i-Z3d1LlZ4ymAUsAMGc6EYEL8dhxVM3aWiifE5vTAupsOw_VDcNkrzbe3dlIJ2Q7OPwK8nO0ht-SBE_F9i58duZcVAzbCmXRvBqz2-PN6RZaEIy3iFnnzTILo40fVObac7AyFeYjc1G1Hv6LtBLAFiUrGDE-geNNOWqpCIVaGwrQTf2Nbrn5eRUTk8C_k6r88VkZjxHOEAKXEBdkkF2XtsElsfAfvOemPQ7gBDKXPx72NEce3eyKrUOcjvnlQORkg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/MRaZr89OCD5Qq9z9INWqGZsk0QSCS36uQSIbQJrq-YdzjVbiaMkbpeXSl1tcB8ZOu5KUs8WzGcfEXddbIVY78z_o8V0IxYibiI4BQsVCubSLMz_lP7idln0bE9i4LU0cr-irveRblfIb2UsB_mN-LI087zClUs3TsB41pQ-pQjAuG9DOmSM9WJDISYjfHg-P2VQOWNeOzARqN_JEa9FzI3lf0xVBuRxjgqwm2ZSf-JgZE5vXLDKKYw2nq41qEvh3ltHN9c_9kF9mUtaVqBhU01z7Ipud_44CPBNBH4BMYOWsZzxLMtqUmCN_GfmitAifPzbWiYtNo8envAOO5HmUUg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/xn--r1a.website.js?ts=1726872521522 HTTP/1.1Host: ads.digitalcaramel.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/system/header-bidding.js HTTP/1.1Host: yandex.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=GmNVkS+1q5EG+QZWaZequSAdEsZAYIQJqYkSXqpBiBW8RHxpVAeNYZqWeWLxv59vOg/zx7VfGq3GoEcsNjaaQUQpdjA=; yandexuid=1141320511726872524; yashr=6680397161726872524; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYMz3t7cGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
Source: global trafficHTTP traffic detected: GET /getcookie HTTP/1.1Host: matchid.adfox.yandex.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=GmNVkS+1q5EG+QZWaZequSAdEsZAYIQJqYkSXqpBiBW8RHxpVAeNYZqWeWLxv59vOg/zx7VfGq3GoEcsNjaaQUQpdjA=; yandexuid=1141320511726872524; yashr=6680397161726872524; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYMz3t7cGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=
Source: global trafficHTTP traffic detected: GET /s3/home/fonts/ys/3/text-variable-full.woff2 HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/JitwEocrGUIsjF7lIVjj81yr99dSOamCXttyW3h-_YJH6F1KYV6qX3iEpHS1nPcEz03nUgOqM9XNa9FbMUsIldglc_Qd9dDVe-Eh9K4cJMOY0AQB78C7CvcLX1boV-UWvh7bEYn87eEeCJM74wYIecz1VUC0dvUSsobArVa0tGYZWpy6eQLxELg5heZS6J_caSMAPmS2xCwwdiCblU0NbmbXanM9fi1RYPQOksZVCklr1QcQz-YHEHNnN8xA7JwcZjCbsWxPZenPnNKQCr5Om6muF5s6PeHKRz7rFNa_Y9N0a6V2-o9ap0ve1s0WFFa_W2TKh266_aX8cFNo1ovPNA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/rkk8WbtOH5kDN2Bvh89DE_-q7p6ydKIypCA8qrMoOqnzWuwss2N-4z7JZG8Isbr6ditAmqyfNXwvxeK_2KrdtV6D3-ex5jk64o7V6OPM94oIlbQGJ7hvbexd-6T-UWP_dZI9laui89-InBxC8i1BOjgwXy9o-5877cfMOYnFuqWMSrcLEmuUnE-TUnbvwybZDVJFUsjpvdmaWH7v4hkhcVImSq8bKofyeoaPhl9gH5O28uw9fFlcuMNxWsFOV4ulnqwIQ4coLZR2jr13R24M23Qp1EOW699OASic2AiATScyldwQ1RogzDMI-mCJVh2Rm3qGwbrQFNHwHIqvVaUqgQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/MSpszLg7U46su23KMCgH8A98mn1j0p2-6wBkxrguTs8yEhVA-oaBykeBGHnbmDgMIfkKoJwjFD22bkLCfzLXC_nZkOpn_IvNZWrn4lKleup8F9gallYy7JfpvqYPTDBOfKk_NhPPOXvBte8UjBr8p6BNiekhw_wgidfU07LtxhQxhg-yfs8gODhc8KhI3B2tedOpJt4s3gCKcD8iwg0mvt8ypGShZW-IqnTMdSM6viCBG3d1niNKp-WAIbJqf_Nqt8CF3bJxTZyy07G2fU3oAZBZC0t3aiIqapI8FAZf_TqIt9ENGUPFJdG1adRWyp65Tdcs7sWd9lUAw3udNMgwxA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/PRwF4HU2mz8_cqvTXNsa-Kd7jb5s5SrzZiFiOQ3g51eziuzlaGps_s9nO7xGuuagpHrfRXLlHMg5UOeNtTVCbEg-9_HuJStxzLyka7v1AY_XcXJRRoFuO9luY7Lb6KNL9m6aqlxvKnZVq28apWcBebnGFw5mlxhpFxFTR9ftopmrxZaw-xUj7RyzwsXF7ha3GPJcrE7ZHbpPll23Bh3e7TEwqIrEWOQ4CVszx4S6PZXa3x7jXL39680brmWiBdMyJy-Uo_WlsTHaUwr5o16C4qVpoM7GewqNWT1OQIDsftojAVmD_amBa7y9mNOCHNjsk2FcO4zZFJoo87-1vpbkxA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/cgF49kKyIze3mCwToG0WWiz2_xQnBNuWR_rlBEEue-BbbFKp-D16ZJxo1gXjON9HRn26_5OxvuQ0WFHhgFELWpAcxOvTxjA1zbE0-2qIM4vxV7olCGiWbKtJ-RUiihXZS4WaX5t6YPs0IXwAkKLIQmwcg6JS9eLoznoFv1yiJD-T55rZblWRR7qJjs7l6ao5Ed-Mxx2FKa2UkrV0NmIno4sICuU56SIoF7acrMzRXeHiDhMUbYcalAGL80oBQDK_3kxaSwVb103nBTxKDGitTID0G1Qdu4-ny0bZooQZhTZroc1RNXyBBQ_G7l6RhN7iTi03qQqIooeMOPvON8UAMw.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/UFNhm7mbEFhB4QrlFgeburrHC3qsTU_P4QzBqpQl7FLGcglXyHwWnn38h1ag9ExV45hNk6v_-VbYoQ2dWzNlG-3HYnELtf553wjaYxDUy2T-b3mxSNS1VcUcsBF0KBR0wC7tzEoFaaFc2-PVjgMhDGUWoBZ1wf0AdPaK-ioNRsa6Hz67S3ThrSQdwaBG2LGo-xHuFMnqvj1nlD-9cNYR9P2pbjuMAxNgIcMtrxJtqgo_YYaI2R_CE0NkOZ9bFw1h-bl__7xhxn0d5NS7SSNjaV91vsGff9xShp_k-qFgfLp7-_9fbSGyA0tWrLMwZK-rdRTLJ_BB2vDmw2YDk2quZg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/oEMIEzb1yTVBpW6MCUIUeeC2t40SZSMsbVRJJjyKs9mRAbrW--7Ue4_Iy0eBbvSSVVgELurmU-qaGFOiQ0xeEH7ltY329lR7ZMlNTABIskg4fS4M776FzjOm8YQ04V5PpLyo-CQ8nHlJX89Wfm1QVx11GmkY_Ad4rcDaVpCQzNsS-ekKPYDT2fTzWQEeW3CrPjYyxQIeSmLtqGrHHC1v6bQatqQywbR_L1XBI8Er-l7eY-TxX83PtrKirkybMrEckzy4qbQueRWGTXQFwknveFmdzqSFguOPtnexomnO6sH5mxBl33ouBAAOzyU6hHNkkcbpoKbkHVycq-fpqjLgCQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/ELzs1UgArxHStzcD91QUa9uaL2ddyRSFVOb32HZ5Q7SZLZI9SN8-CvHqkdeSTXz-1FJOHYLyaLzDpUXHrn-3RXYO_4I8oBD9yzwbCHmFeXODLfgUkIjYaugi2NfHyyx86_OZkKL2-vj668ki5vH1mtUCpu871TMMon8057k3jLN1Ba5qNzugM2DrntzGDSlJ045JcFoOh8aLOX3xkDOc0zE2t5O1lQOe8IC-8rtsvjePL8Yyh3HfF-P4WjILj0PfQgv1i7-JHb-jW_hkPmRAB42Uq2-m9whBNQYgypUynBNyLqkApbiUN7qdshWXE3jjbrm5i1asFn_Nd1GtMbAZpA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/adfox/332443/getBulk/v2?pr=2302063733&pr1=3849475745&dl=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&prr=&extid_loader=&extid_tag_loader=xn--r1a.website&fa=&date=2024-09-20T18%3A48%3A47.259-04%3A00&pd=20&pw=5&pv=18&pdw=1280&pdh=1024&ylv=0.1117086&ybv=0.1117086&ytt=509073883660293&is-turbo=0&skip-token=&ad-session-id=8249541726872527269&layout-config=%7B%22win_width%22%3A1280%2C%22win_height%22%3A907%2C%22pixel_ratio%22%3A1%2C%22bandwidth%22%3A1.35%2C%22isInIframe%22%3Afalse%2C%22w%22%3A1278%2C%22h%22%3A98%2C%22width%22%3A1278%2C%22height%22%3A98%2C%22visible%22%3A1%2C%22fullscreenHeaderHeight%22%3A80%2C%22left%22%3A1%2C%22top%22%3A9422%2C%22req_no%22%3A0%2C%22ad_no%22%3A0%7D&pcode-version=1117086&yaru=true&p1=ddhej&p2=iqvg&slotNumber=1&bids=W3siYmlkZGVyTmFtZSI6ImJldHdlZW5kaWdpdGFsIiwiY2FtcGFpZ25faWQiOjEzNjYwNzQsInJlc3BvbnNlX3RpbWUiOjE1MTUsImVycm9yIjp7ImNvZGUiOjN9LCJwbGFjZW1lbnRfaWQiOiI0NzgwMDcxIn0seyJiaWRkZXJOYW1lIjoib3RtIiwiY2FtcGFpZ25faWQiOjE1MzYxNDMsInJlc3BvbnNlX3RpbWUiOjE1MTUsImVycm9yIjp7ImNvZGUiOjN9LCJwbGFjZW1lbnRfaWQiOiI2NjMzMCJ9LHsiYmlkZGVyTmFtZSI6ImdldGludGVudCIsImNhbXBhaWduX2lkIjoxMzY2MDc4LCJyZXNwb25zZV90aW1lIjoxNTE1LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiNjZfOTcweDkwX2FsZmFkYXJ0In0seyJiaWRkZXJOYW1lIjoibXl0YXJnZXQiLCJjYW1wYWlnbl9pZCI6MTM2NjA3MiwicmVzcG9uc2VfdGltZSI6MTUxNSwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjE2ODIwMzYifSx7ImJpZGRlck5hbWUiOiJiaWR2b2wiLCJjYW1wYWlnbl9pZCI6MTQ0NTcyNywicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjQ2MzI2In0seyJiaWRkZXJOYW1lIjoic2FwZSIsImNhbXBhaWduX2lkIjoxNjcyNjk5LCJyZXNwb25zZV90aW1lIjoxNTE2LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiODk3NzA3In0seyJiaWRkZXJOYW1lIjoiYnV6em9vbGEiLCJjYW1wYWlnbl9pZCI6MTM5NDExOSwicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjEyNzIyNDcifSx7ImJpZGRlck5hbWUiOiJoeWJyaWQiLCJjYW1wYWlnbl9pZCI6MTg3OTc2MywicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjY2OWY2M2ZjNGQ1MDZlNjAxMDg5MWQ4ZCJ9LHsiYmlkZGVyTmFtZSI6ImFkcml2ZXIiLCJjYW1wYWlnbl9pZCI6MTM2NjA3NiwicmVzcG9uc2VfdGltZSI6MTUxNywiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjU3OnhuLS1yMWEud2Vic2l0ZV9mbG9vcmFkX2Rlc2sifSx7ImJpZGRlck5hbWUiOiJzb2x0YSIsImNhbXBhaWduX2lkIjoyNDY4MjYxLCJyZXNwb25zZV90aW1lIjoxNTI4LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiNDktWW45WnMifSx7ImJpZGRlck5hbWUiOiJhbGZhc2Vuc2UiLCJjYW1wYWlnbl9pZCI6MTM2NjA3NSwicmVzcG9uc2VfdGltZSI6MTUyOCwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjI0MzQwIn1d&utf8=%E2%9C%93&pcode-test-ids=1094010%2C0%2C47%3B1114587%2C0%2C2%3B1108910%2C0%2C20%3B1106679%2C0%2C64%3B1094980%2C0%2C56%3B1116181%2C0%2C90%3B1112582%2C0%2C19%3B1035460%2C0%2C17%3B1097919%2C0%2C35%3B1107286%2C0%2C13%3B1116503%2C0%2C5%3B1110875%2C0%2C85%3B1111360%2C0%2C66%3B1110879%2C0%2C45%3B1110883%2C0%2C54%3B1085919%2C0%2C25%3B1116506%2C0%2C77%3B1110866%2C0%2C63%3B1111927%2C0%2C82%3B1117949%2C0%2C55%3B1088274%2C0%2C25%3B1091654%2C0%2C13&pcode-flags-map=eJy1WVlz2kgX%2FS88h4z2JW%2BN1IgutE2rBWamUl1kzCSecexU7GTyJZX%2F%2Fp2WGoEA
Source: global trafficHTTP traffic detected: GET /ads/system/context.js HTTP/1.1Host: yandex.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: i=GmNVkS+1q5EG+QZWaZequSAdEsZAYIQJqYkSXqpBiBW8RHxpVAeNYZqWeWLxv59vOg/zx7VfGq3GoEcsNjaaQUQpdjA=; yandexuid=1141320511726872524; yashr=6680397161726872524; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3MiYMz3t7cGah7cyuH/CJLYobEDn8/h6gP7+vDnDev//fYPutfOhwg=; receive-cookie-deprecation=1
Source: global trafficHTTP traffic detected: GET /file/uiPk3Z5ix6sgFrblrDtl45mDlgniH66ntxVBMte3HxcZ5SpLdIuud7S2vkgnyF343Sqy2_YNmNvuobjq3MZ9txmE1ATrRYNkCYRnlds8uTp-FeBCf_HLUp3uq2uV23I_spdjzyXYn0xlbO5jIidI1gArQadXXtB2wcvV615k9n07gC9_YNwmJZYJ4m8eMIIrvLWpuiNpzwACEK8K0f1g3H1oX3bRf3Z5WfRb4wySb4QeL6uWQOKkxZp4v0rp4eGJpR31QJqi7QIqZ9iCuxc7An3-U9t84qkxi1hDBOAHUxbfLtO8DezjrktvyMUA0M4A5BoSjekXVL9IW9pRRAkpZQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/uPQ5ind25iS73kme6wYzUIw_tJvT7exWmnuWZYHK1cp_1YCh0rRaPOrArn3HBpQ1pWFcVrbWmFnV4J3My4Fk-2aXdWP5T20Q8zVMUDDALJUelJBFFCfTc1syEChrXoLCqk8YxngD5JNjYRTvD9tcmIhIAlOJ_xBnEU_OLhUaz86mnvJws3L602OOtsJENHuXjjI46SQWNter7T4FgELHcCGaPiXzMFkZJDqRx4xBMSkDmLJn19G39GH_gQFci9BN6OwP5jazsqGnFdRrIXTrwmYFU-DbhCGS-ruojPASHQyw5CUrV8lJ-wv6xo5lfHaZCwo6XG5R8ih8Heb_xNU_bA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/QK60TZJk0YMhme0DiIpkWeQhvy1qOXmF5dbvK-dRuAYBD-85HXLtrMXsPu4HmKh3drLvuHgWdZomPfsZCRxMB-j4Aie0-3hgh8wn1ht25lAK6xDmygEyaA7eqXQs9tXPc5bxVoSG3hPZVJ9u4rdP3PR1TexQuZVjdFpnYQk5HSQnEO5lY0kVO64nK4OwqB4kUS9kFIB-NoxwdLUX1_7AuL2o0A7UwKrVsJaMbQOmOPvaUjda0-c6GFEvKsGNUQXtHLVXfi3w9oOzo1zBxsD03RbNSNoQibtmrtoDtS8kcE6gH2P5epI3UPHrpW91LMasc6HKOih3Ya3OpoNG8DZEtQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/Ukozu20epRcRaVDvklUZ6TM2vj0mDF9eamysHAG6rX5w1yPDYfRyqAed3aJtDHE3scAVu0L9KuCcjwJJYjccsUwnjs1cCUTMvez85fCszOr7fBJEMunpA4Zae8WtFx_YCwGjD1nqHmEU1r1rfnuy6emFkIunTPy2Aq7k6FvkwRY8fydKLa6ClZhgfYLzbvZg-uw5v4qJvet_Mvy0OlMTTnhFXb1rtY2SLGwSM33GeoXd2z7Odq1TyNss3ivw41kMnpqncccJely9kKPyUCjvqYda0-kApF2v0xve_USsU6Iz7LapXzATCI_1H-Q4yh2zFvD_7qyNz72-Uh9kw7O0ag.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/vJ1qeXNLCjuVDEIRhU0Uc51fVywA0h7ZJSrOuLx4ENx93PE6tFR-ImbH6R6TH2Hq6nolVRWos6mpdVpSPGzX6p8Q0j_0ODtSqtNpysuhrykAfSdDnQ8DgGgskor3Fu8WtaJQxQri8j-hK-g2OOleHoS4KD1B0YhItDZRP0_vlqps17Ld32FQSc-vJxYs9CL8o_6Sc2cXvhUbtn_7wmvnKnWc3Ob9fJcHtXZftEkAVq7aPN2oFh3v2moUXctch7gw9VdyvDNMhGhuxQS8ZIXFjLAIuzgQpvq6SlitGvbib6Rw1hWW_W2ZTDtWGJjMPaOwDaNsLxFvXuGHDGd4VBasvQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/PRwF4HU2mz8_cqvTXNsa-Kd7jb5s5SrzZiFiOQ3g51eziuzlaGps_s9nO7xGuuagpHrfRXLlHMg5UOeNtTVCbEg-9_HuJStxzLyka7v1AY_XcXJRRoFuO9luY7Lb6KNL9m6aqlxvKnZVq28apWcBebnGFw5mlxhpFxFTR9ftopmrxZaw-xUj7RyzwsXF7ha3GPJcrE7ZHbpPll23Bh3e7TEwqIrEWOQ4CVszx4S6PZXa3x7jXL39680brmWiBdMyJy-Uo_WlsTHaUwr5o16C4qVpoM7GewqNWT1OQIDsftojAVmD_amBa7y9mNOCHNjsk2FcO4zZFJoo87-1vpbkxA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/uPQ5ind25iS73kme6wYzUIw_tJvT7exWmnuWZYHK1cp_1YCh0rRaPOrArn3HBpQ1pWFcVrbWmFnV4J3My4Fk-2aXdWP5T20Q8zVMUDDALJUelJBFFCfTc1syEChrXoLCqk8YxngD5JNjYRTvD9tcmIhIAlOJ_xBnEU_OLhUaz86mnvJws3L602OOtsJENHuXjjI46SQWNter7T4FgELHcCGaPiXzMFkZJDqRx4xBMSkDmLJn19G39GH_gQFci9BN6OwP5jazsqGnFdRrIXTrwmYFU-DbhCGS-ruojPASHQyw5CUrV8lJ-wv6xo5lfHaZCwo6XG5R8ih8Heb_xNU_bA.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/uiPk3Z5ix6sgFrblrDtl45mDlgniH66ntxVBMte3HxcZ5SpLdIuud7S2vkgnyF343Sqy2_YNmNvuobjq3MZ9txmE1ATrRYNkCYRnlds8uTp-FeBCf_HLUp3uq2uV23I_spdjzyXYn0xlbO5jIidI1gArQadXXtB2wcvV615k9n07gC9_YNwmJZYJ4m8eMIIrvLWpuiNpzwACEK8K0f1g3H1oX3bRf3Z5WfRb4wySb4QeL6uWQOKkxZp4v0rp4eGJpR31QJqi7QIqZ9iCuxc7An3-U9t84qkxi1hDBOAHUxbfLtO8DezjrktvyMUA0M4A5BoSjekXVL9IW9pRRAkpZQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/QK60TZJk0YMhme0DiIpkWeQhvy1qOXmF5dbvK-dRuAYBD-85HXLtrMXsPu4HmKh3drLvuHgWdZomPfsZCRxMB-j4Aie0-3hgh8wn1ht25lAK6xDmygEyaA7eqXQs9tXPc5bxVoSG3hPZVJ9u4rdP3PR1TexQuZVjdFpnYQk5HSQnEO5lY0kVO64nK4OwqB4kUS9kFIB-NoxwdLUX1_7AuL2o0A7UwKrVsJaMbQOmOPvaUjda0-c6GFEvKsGNUQXtHLVXfi3w9oOzo1zBxsD03RbNSNoQibtmrtoDtS8kcE6gH2P5epI3UPHrpW91LMasc6HKOih3Ya3OpoNG8DZEtQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ads/adfox/332443/getBulk/v2?pr=2302063733&pr1=3849475745&dl=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&prr=&extid_loader=&extid_tag_loader=xn--r1a.website&fa=&date=2024-09-20T18%3A48%3A47.259-04%3A00&pd=20&pw=5&pv=18&pdw=1280&pdh=1024&ylv=0.1117086&ybv=0.1117086&ytt=509073883660293&is-turbo=0&skip-token=&ad-session-id=8249541726872527269&layout-config=%7B%22win_width%22%3A1280%2C%22win_height%22%3A907%2C%22pixel_ratio%22%3A1%2C%22bandwidth%22%3A1.35%2C%22isInIframe%22%3Afalse%2C%22w%22%3A1278%2C%22h%22%3A98%2C%22width%22%3A1278%2C%22height%22%3A98%2C%22visible%22%3A1%2C%22fullscreenHeaderHeight%22%3A80%2C%22left%22%3A1%2C%22top%22%3A9422%2C%22req_no%22%3A0%2C%22ad_no%22%3A0%7D&pcode-version=1117086&yaru=true&p1=ddhej&p2=iqvg&slotNumber=1&bids=W3siYmlkZGVyTmFtZSI6ImJldHdlZW5kaWdpdGFsIiwiY2FtcGFpZ25faWQiOjEzNjYwNzQsInJlc3BvbnNlX3RpbWUiOjE1MTUsImVycm9yIjp7ImNvZGUiOjN9LCJwbGFjZW1lbnRfaWQiOiI0NzgwMDcxIn0seyJiaWRkZXJOYW1lIjoib3RtIiwiY2FtcGFpZ25faWQiOjE1MzYxNDMsInJlc3BvbnNlX3RpbWUiOjE1MTUsImVycm9yIjp7ImNvZGUiOjN9LCJwbGFjZW1lbnRfaWQiOiI2NjMzMCJ9LHsiYmlkZGVyTmFtZSI6ImdldGludGVudCIsImNhbXBhaWduX2lkIjoxMzY2MDc4LCJyZXNwb25zZV90aW1lIjoxNTE1LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiNjZfOTcweDkwX2FsZmFkYXJ0In0seyJiaWRkZXJOYW1lIjoibXl0YXJnZXQiLCJjYW1wYWlnbl9pZCI6MTM2NjA3MiwicmVzcG9uc2VfdGltZSI6MTUxNSwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjE2ODIwMzYifSx7ImJpZGRlck5hbWUiOiJiaWR2b2wiLCJjYW1wYWlnbl9pZCI6MTQ0NTcyNywicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjQ2MzI2In0seyJiaWRkZXJOYW1lIjoic2FwZSIsImNhbXBhaWduX2lkIjoxNjcyNjk5LCJyZXNwb25zZV90aW1lIjoxNTE2LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiODk3NzA3In0seyJiaWRkZXJOYW1lIjoiYnV6em9vbGEiLCJjYW1wYWlnbl9pZCI6MTM5NDExOSwicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjEyNzIyNDcifSx7ImJpZGRlck5hbWUiOiJoeWJyaWQiLCJjYW1wYWlnbl9pZCI6MTg3OTc2MywicmVzcG9uc2VfdGltZSI6MTUxNiwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjY2OWY2M2ZjNGQ1MDZlNjAxMDg5MWQ4ZCJ9LHsiYmlkZGVyTmFtZSI6ImFkcml2ZXIiLCJjYW1wYWlnbl9pZCI6MTM2NjA3NiwicmVzcG9uc2VfdGltZSI6MTUxNywiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjU3OnhuLS1yMWEud2Vic2l0ZV9mbG9vcmFkX2Rlc2sifSx7ImJpZGRlck5hbWUiOiJzb2x0YSIsImNhbXBhaWduX2lkIjoyNDY4MjYxLCJyZXNwb25zZV90aW1lIjoxNTI4LCJlcnJvciI6eyJjb2RlIjozfSwicGxhY2VtZW50X2lkIjoiNDktWW45WnMifSx7ImJpZGRlck5hbWUiOiJhbGZhc2Vuc2UiLCJjYW1wYWlnbl9pZCI6MTM2NjA3NSwicmVzcG9uc2VfdGltZSI6MTUyOCwiZXJyb3IiOnsiY29kZSI6M30sInBsYWNlbWVudF9pZCI6IjI0MzQwIn1d&utf8=%E2%9C%93&pcode-test-ids=1094010%2C0%2C47%3B1114587%2C0%2C2%3B1108910%2C0%2C20%3B1106679%2C0%2C64%3B1094980%2C0%2C56%3B1116181%2C0%2C90%3B1112582%2C0%2C19%3B1035460%2C0%2C17%3B1097919%2C0%2C35%3B1107286%2C0%2C13%3B1116503%2C0%2C5%3B1110875%2C0%2C85%3B1111360%2C0%2C66%3B1110879%2C0%2C45%3B1110883%2C0%2C54%3B1085919%2C0%2C25%3B1116506%2C0%2C77%3B1110866%2C0%2C63%3B1111927%2C0%2C82%3B1117949%2C0%2C55%3B1088274%2C0%2C25%3B1091654%2C0%2C13&pcode-flags-map=eJy1WVlz2kgX%2FS88h4z2JW%2BN1IgutE2rBWamUl1kzCSecexU7GTyJZX%2F%2Fp2WGoEA
Source: global trafficHTTP traffic detected: GET /file/cgF49kKyIze3mCwToG0WWiz2_xQnBNuWR_rlBEEue-BbbFKp-D16ZJxo1gXjON9HRn26_5OxvuQ0WFHhgFELWpAcxOvTxjA1zbE0-2qIM4vxV7olCGiWbKtJ-RUiihXZS4WaX5t6YPs0IXwAkKLIQmwcg6JS9eLoznoFv1yiJD-T55rZblWRR7qJjs7l6ao5Ed-Mxx2FKa2UkrV0NmIno4sICuU56SIoF7acrMzRXeHiDhMUbYcalAGL80oBQDK_3kxaSwVb103nBTxKDGitTID0G1Qdu4-ny0bZooQZhTZroc1RNXyBBQ_G7l6RhN7iTi03qQqIooeMOPvON8UAMw.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/17fb885b38886c06b632.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/f7c4024c86a402702d20.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/77b050485636874c5aed.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/8191d15d1fd1e4c04fa3.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/28ced93adc464997b048.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /safeframe-bundles/0.83/host.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/vJ1qeXNLCjuVDEIRhU0Uc51fVywA0h7ZJSrOuLx4ENx93PE6tFR-ImbH6R6TH2Hq6nolVRWos6mpdVpSPGzX6p8Q0j_0ODtSqtNpysuhrykAfSdDnQ8DgGgskor3Fu8WtaJQxQri8j-hK-g2OOleHoS4KD1B0YhItDZRP0_vlqps17Ld32FQSc-vJxYs9CL8o_6Sc2cXvhUbtn_7wmvnKnWc3Ob9fJcHtXZftEkAVq7aPN2oFh3v2moUXctch7gw9VdyvDNMhGhuxQS8ZIXFjLAIuzgQpvq6SlitGvbib6Rw1hWW_W2ZTDtWGJjMPaOwDaNsLxFvXuGHDGd4VBasvQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/Ukozu20epRcRaVDvklUZ6TM2vj0mDF9eamysHAG6rX5w1yPDYfRyqAed3aJtDHE3scAVu0L9KuCcjwJJYjccsUwnjs1cCUTMvez85fCszOr7fBJEMunpA4Zae8WtFx_YCwGjD1nqHmEU1r1rfnuy6emFkIunTPy2Aq7k6FvkwRY8fydKLa6ClZhgfYLzbvZg-uw5v4qJvet_Mvy0OlMTTnhFXb1rtY2SLGwSM33GeoXd2z7Odq1TyNss3ivw41kMnpqncccJely9kKPyUCjvqYda0-kApF2v0xve_USsU6Iz7LapXzATCI_1H-Q4yh2zFvD_7qyNz72-Uh9kw7O0ag.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/40014e7ae9852a9faa7b.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/17fb885b38886c06b632.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/ee55314d29f5e472edba.js HTTP/1.1Host: yastatic.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: http://xn--r1a.websitesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/8191d15d1fd1e4c04fa3.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/77b050485636874c5aed.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/f7c4024c86a402702d20.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /safeframe-bundles/0.83/host.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /332443/event?hash=3bbdadfaa3a01a78&pm=cyz&p5=bbrmjh&rand=gfxyz&sj=Ww0lRghMdjUh3MThXRHpLTbKrHJlAJJCuqcnRIGxynjGaVxzZaY8gMpQh-32_A%3D%3D&ad-session-id=8249541726872527269&lts=fpixtef&ytt=509073883660293&ybv=0.1117086&ylv=0.1117086&dl=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&pr=hltprsv&p1=ddhej&rqs=zOdYXPXI1g_R--1mPkdNX3Ht8SMOhx0q&p2=iqvg&bundle=banner.transfer HTTP/1.1Host: ads.adfox.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/28ced93adc464997b048.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/40014e7ae9852a9faa7b.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /partner-code-bundles/1117086/ee55314d29f5e472edba.js HTTP/1.1Host: yastatic.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib/alfadart.lib.min.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/ad_13097.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib/alfadart.lib.min.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib_test/config.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib/prebid.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/ad_13097.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ext/weboctxrun.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bigsea/contextual/v1/weboctx.min.js HTTP/1.1Host: cstatic.weborama.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pixeljs HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rtb/direct_banner?bid_id=4e4e00bb31f5f6&pid=66&tid=970x90_alfadart&known=1&is_video=false&resp_type=JSON&provider=direct.prebidjs&size=970x90&floor=0.1&cur=RUB HTTP/1.1Host: px.adhigh.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /collect?ctx=1&touchpoint=1090&url=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru HTTP/1.1Host: dx.frontend.weborama.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/json.cgi?sid=1&ad=719473&bt=55&pid=3198680&bid=7189165&bn=7189165&tuid=1&cfa=1&cid=null HTTP/1.1Host: ad.adriver.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib_test/config.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ext/weboctxrun.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /id.json?p=5 HTTP/1.1Host: const.unoConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lib/prebid.js HTTP/1.1Host: cdn.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /pixeljs HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /bigsea/contextual/v1/weboctx.min.js HTTP/1.1Host: cstatic.weborama.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?tz=240&w=970&h=90&domain=xn--r1a.website&l=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&s=38014&cur=RUB&bidid=27eb92cbf416fc&transactionid=&auctionid=&bidfloor=0 HTTP/1.1Host: ssp.otm-r.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rtb/direct_banner?bid_id=4e4e00bb31f5f6&pid=66&tid=970x90_alfadart&known=1&is_video=false&resp_type=JSON&provider=direct.prebidjs&size=970x90&floor=0.1&cur=RUB&bounced=1 HTTP/1.1Host: px.adhigh.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gi_u=ujPJCLnjOrl.AikABlGSEZ_GxQ
Source: global trafficHTTP traffic detected: GET /cgi-bin/json.cgi?sid=1&ad=719473&bt=55&pid=3198680&bid=7189165&bn=7189165&tuid=1&cfa=1&cid=null HTTP/1.1Host: ad.adriver.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?src=asense&uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.bumlam.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cmatch/?dp=14&pi=1647232&skip_it=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rmatch?dp=185&euid=5322f90c-68ee-4d33-bc6f-6140cef1f878&r=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dsp%26uid%3D%24%7BUSER_ID%7D HTTP/1.1Host: www.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?source=alfasense&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: s.suprion.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /set?partner_id=a45901af-fbca-4cab-b3b8-0e6b6ec957e8&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.rambler.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /id.json?p=5 HTTP/1.1Host: const.unoConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /usersync?dspcsid=135&redirect=1&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: ssp.bidvol.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync?ssp=42&uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: a.videohead.techConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rmatch?r=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dsp%26uid%3D$%7BUSER_ID%7D&dp=185&tc=1&euid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: www.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0
Source: global trafficHTTP traffic detected: GET /?src=asense&s_data=CAIQARja97e3BmIkNTMyMmY5MGMtNjhlZS00ZDMzLWJjNmYtNjE0MGNlZjFmODc4ogEQhcaPWneiEe-G4AAlkMBkfA** HTTP/1.1Host: sync.bumlam.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: suuid3=IiQ4NWM2OGY1YS03N2EyLTExZWYtODZlMC0wMDI1OTBjMDY0N2M*
Source: global trafficHTTP traffic detected: GET /rmatch/?r=https%3A%2F%2Facint.net%2Frmatch%3Fdp%3D14%26euid%3D%24%7BUSER_ID%7D%26r%3Dhttps%253A%252F%252Fmc.acint.net%252Fcmatch%253Fdp%253D14 HTTP/1.1Host: ssp-rtb.sape.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: sspuid=CkIDO2bt+9gdigElhj4hAgAeX/aXQX7XgCV1hJ87JTfMrnFy
Source: global trafficHTTP traffic detected: GET /p?ssp=bv&uid=lfihjef9ln HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /alfasense?uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.adspend.spaceConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/sync/alfadart?skipme=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: ssp.al-adtech.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?source=alfasense&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: s.suprion.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: KsId=5IGiW2jKnMllFA
Source: global trafficHTTP traffic detected: GET /set?partner_id=a45901af-fbca-4cab-b3b8-0e6b6ec957e8&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.rambler.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=al&uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: cs.agency2.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=ai&skipme=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: cs.agency2.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rtb/sync/alfasense?u=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: kimberlite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: u=Zu372NYn4og~ApTXE7XyWiS79ldKFQbaW0Z7ybQ
Source: global trafficHTTP traffic detected: GET /rmatch?dp=14&euid=3B03420AD8FBED6625018A1D02213E86&r=https%3A%2F%2Fmc.acint.net%2Fcmatch%3Fdp%3D14 HTTP/1.1Host: acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539
Source: global trafficHTTP traffic detected: GET /rmatch?r=https%3A%2F%2Facint.net%2Frmatch%3Fdp%3D14%26euid%3D$%7BUSER_ID%7D%26r%3Dhttps%253A%252F%252Fcs.alfasense.com%252Fp%253Fssp%253Dsp%2526uid%253D$%257BUSER_ID%257D&dp=14 HTTP/1.1Host: ssp-rtb.sape.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: sspuid=CkIDO2bt+9gdigElhj4hAgAeX/aXQX7XgCV1hJ87JTfMrnFy
Source: global trafficHTTP traffic detected: GET /?src=asense&s_data=CAIQARja97e3BmIkNTMyMmY5MGMtNjhlZS00ZDMzLWJjNmYtNjE0MGNlZjFmODc4ogEQhcaPWneiEe-G4AAlkMBkfA** HTTP/1.1Host: sync.bumlam.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: suuid3=IiQ4NWM2OGY1YS03N2EyLTExZWYtODZlMC0wMDI1OTBjMDY0N2M*
Source: global trafficHTTP traffic detected: GET /p?ssp=al&id=9291fa75-8358-4079-b4ea-83f0b6e026ab HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /sync?ssp=12&skip=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: a.adiam.techConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=a2&uid=1df50709-a9fb-4e05-86f5-02be4cab6108 HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /0.gif?pid=7140034&id=00b68fd6-fa94-4da3-8aec-cadd88b69733 HTTP/1.1Host: x01.aidata.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync?uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: alfasense-sync.rutarget.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cmatch?dp=14 HTTP/1.1Host: mc.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539
Source: global trafficHTTP traffic detected: GET /rmatch?dp=14&euid=3B03420AD8FBED6625018A1D02213E86&r=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dsp%26uid%3D$%7BUSER_ID%7D HTTP/1.1Host: acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539
Source: global trafficHTTP traffic detected: GET /p?ssp=toptraffic&id=Zu372NYn4og HTTP/1.1Host: sm.rtb.mts.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync?ssp=716&skipme=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: a.utraff.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=al&id=9291fa75-8358-4079-b4ea-83f0b6e026ab HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /cgi-bin/rle.cgi?sid=1&ad=608223&bt=21&pid=2551979&bid=8918732&bn=8918732&skip=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: ev.adriver.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cid=A-jDGZJ2XDp6ijgtGMM-BdQ
Source: global trafficHTTP traffic detected: GET /0.gif?pid=7140034&id=00b68fd6-fa94-4da3-8aec-cadd88b69733&bounce=1 HTTP/1.1Host: x01.aidata.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __upin=Am7kf69LIcgvanWqC1BQ1A; __upints=1726872541
Source: global trafficHTTP traffic detected: GET /p?ssp=sg&uid=JcwMBctHpuCG HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /cm?ssp=alfas&skip=5322f90c-68ee-4d33-bc6f-6140cef1f878&redirect_url=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dob%26id%3D%7Buid%7D HTTP/1.1Host: match.ohmy.bidConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=sp&uid=0200007FDAFBED662016D5010203BC90 HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /match/second?ssp=59&exu=Zu372NYn4og HTTP/1.1Host: vma.mts.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dspid=2d186298-c967-43b7-9ce5-9f669932114c
Source: global trafficHTTP traffic detected: GET /p?ssp=a2&uid=1df50709-a9fb-4e05-86f5-02be4cab6108 HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /p/cm/sape?u=0200007FDAFBED662016D5010203BC90 HTTP/1.1Host: px.adhigh.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gi_u=ujPJCLnjOrl.AikABlGSEZ_GxQ
Source: global trafficHTTP traffic detected: GET /ogorodru/14045?single HTTP/1.1Host: tttttt.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=ar&id=A-jDGZJ2XDp6ijgtGMM-BdQ HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /cookiesync/redirect?skip2=5322f90c-68ee-4d33-bc6f-6140cef1f878&redirect_url=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dbz%26uid%3D%24%7BUUID%7D HTTP/1.1Host: exchange.buzzoola.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=07423726-b659-4bb0-6cef-0dbb74544185
Source: global trafficHTTP traffic detected: GET /match/1215/?remote_uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: s.uuidksinc.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cm/tech?flowId=c128a652-29c1-46c5-aece-22212bde700f&measurement_id=MTS_DSP_web&dsp_uid=2d186298-c967-43b7-9ce5-9f669932114c&redirect_return_url=https%3A%2F%2Fx01.aidata.io%2F0.gif%3Fpid%3D9503528%26dest%3Dhttps%253A%252F%252Fvma.mts.ru%252Fem%253Fnext%253D59%2526em%253D2%2526ssp%253Daidata%2526id%253D%2524UID HTTP/1.1Host: cm.a.mts.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dspid=2d186298-c967-43b7-9ce5-9f669932114c
Source: global trafficHTTP traffic detected: GET /match/alfasense?id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.opendsp.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=sg&uid=JcwMBctHpuCG HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /cm?ssp=alfas&skip=5322f90c-68ee-4d33-bc6f-6140cef1f878&redirect_url=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dob%26id%3D%7Buid%7D HTTP/1.1Host: match.ohmy.bidConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uid=4d880002-8336-4b41-aa6e-dedd7ee96ac8.66edfbde.dc3fbe0b83c08b1c
Source: global trafficHTTP traffic detected: GET /rmatch?dp=17&euid=ujPJCLnjOrl.AikABlGSEZ_GxQ&r=https%3A%2F%2Fmc.acint.net%2Fcmatch%3Fdp%3D17 HTTP/1.1Host: mc.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539; cSyncDp17v2=1726872541
Source: global trafficHTTP traffic detected: GET /userbind?src=alfasense&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: match.new-programmatic.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /als/sync/?user_id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: rtb.dynotech.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /p?ssp=bz&uid=07423726-b659-4bb0-6cef-0dbb74544185 HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /cm/match?flowId=c128a652-29c1-46c5-aece-22212bde700f&measurement_id=MTS_DSP_web&dsp_uid=2d186298-c967-43b7-9ce5-9f669932114c&redirect_return_url=https://x01.aidata.io/0.gif?pid%3D9503528%26dest%3Dhttps%253A%252F%252Fvma.mts.ru%252Fem%253Fnext%253D59%2526em%253D2%2526ssp%253Daidata%2526id%253D%2524UID HTTP/1.1Host: 2348964281726872543783.cm.a.mts.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dspid=2d186298-c967-43b7-9ce5-9f669932114c; ma_last_sync=1726872543783; ma_id=2348964281726872543783
Source: global trafficHTTP traffic detected: GET /p?ssp=kd&uid=OBoQhsBgeRgmqPkpWuU5 HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /match/alfasense?id=5322f90c-68ee-4d33-bc6f-6140cef1f878&chk=1 HTTP/1.1Host: sync.opendsp.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: chk=1
Source: global trafficHTTP traffic detected: GET /cmatch?dp=17 HTTP/1.1Host: mc.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539; cSyncDp17v2=1726872541
Source: global trafficHTTP traffic detected: GET /p?ssp=tg&redir=0&id= HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /p?ssp=dt&id=1-1FZfcd2cFA-soZsnpUQFU HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /0.gif?pid=9503528&dest=https%3A%2F%2Fvma.mts.ru%2Fem%3Fnext%3D59%26em%3D2%26ssp%3Daidata%26id%3D%24UID HTTP/1.1Host: x01.aidata.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __upin=Am7kf69LIcgvanWqC1BQ1A; __upints=1726872541
Source: global trafficHTTP traffic detected: GET /match/Alfasense?id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.programmatica.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /match/alfasensor?id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.dmp.otm-r.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync?ssp=3368 HTTP/1.1Host: a.utraff.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: preutid=1
Source: global trafficHTTP traffic detected: GET /css/font-roboto.css?1 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/bootstrap.min.css?3 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/telegram.css?240 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgwallpaper.min.js?3 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync HTTP/1.1Host: sape-sync.rutarget.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: userId=JcwMBctHpuCG
Source: global trafficHTTP traffic detected: GET /em?next=59&em=2&ssp=aidata&id=Am7kf69LIcgvanWqC1BQ1A HTTP/1.1Host: vma.mts.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dspid=2d186298-c967-43b7-9ce5-9f669932114c; ma_last_sync=1726872543783; ma_id=2348964281726872543783
Source: global trafficHTTP traffic detected: GET /match/Alfasense?id=5322f90c-68ee-4d33-bc6f-6140cef1f878&chk=1 HTTP/1.1Host: sync.programmatica.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: chk=1
Source: global trafficHTTP traffic detected: GET /match/alfasensor?id=5322f90c-68ee-4d33-bc6f-6140cef1f878&otcm_check=1726872545 HTTP/1.1Host: sync.dmp.otm-r.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mpid=NjZlZGZiZTEwMTIxZTQwNw==
Source: global trafficHTTP traffic detected: GET /userbind?src=alfasense&id=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: match.qtarget.techConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgwallpaper.min.js?3 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sync?ssp=2 HTTP/1.1Host: a.videohead.techConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: prevhead=1
Source: global trafficHTTP traffic detected: GET /alfadart/sync?uid=5322f90c-68ee-4d33-bc6f-6140cef1f878 HTTP/1.1Host: sync.upravel.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/tgme/pattern.svg?1 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://telegram.org/css/telegram.css?240Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOlCnqEu92Fr1MmWUlfBBc4AMP6lQ.woff2 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://tttttt.mesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOmCnqEu92Fr1Mu4mxKKTU1Kg.woff2 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://tttttt.mesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /match?dp=104&euid=JcwMBctHpuCG HTTP/1.1Host: www.acint.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539; cSyncDp17v2=1726872541; cSyncDp104v2=1726872545
Source: global trafficHTTP traffic detected: GET /p?ssp=ot&id=NjZlZGZiZTEwMTIxZTQwNw%3D%3D HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /rtb/sync/mts?u=2d186298-c967-43b7-9ce5-9f669932114c HTTP/1.1Host: kimberlite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: f=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dst%26id%3DZu372NYn4og; n=1; da=KLqvcgAAAAE; u=Zu372NYn4og~ApTXE7XyWiS79ldKFQbaW0Z7ybQ
Source: global trafficHTTP traffic detected: GET /alfadart/sync?uid=5322f90c-68ee-4d33-bc6f-6140cef1f878&session_tpt=eyJoZWFkZXJzIjp7InJlZmVyZXIiOlsiaHR0cDovL3huLS1yMWEud2Vic2l0ZS8iXX19 HTTP/1.1Host: sync.upravel.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: session_tptc=1726872547815
Source: global trafficHTTP traffic detected: GET /match/videohead?id=159a8e1d-408b-4725-b19f-a152c6da5aea HTTP/1.1Host: sync.gonet-ads.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?dmpkit_cid=9064fc6c-76fe-4a6d-aea6-92ef3f343257&dmpkit_evid=8vhicaia6d0gnvnhrxxom892oalkpb77&user_prg=NWFmOTc5NmUyOTU5MmY5Nw HTTP/1.1Host: dmp.sbermarketing.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sspmatch HTTP/1.1Host: ads.betweendigital.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dc=lux1; tuuid=934fd479-13e4-5209-ba1b-9425dcf66ff5; ut=Zu370AAAIyh89YMwyDb-xs_V4HAMjqxjMWk7dA==; ss=1; unm=1
Source: global trafficHTTP traffic detected: GET /match?dp=104&euid=JcwMBctHpuCG HTTP/1.1Host: www.acint.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cSyncDp14v6=1726872538; test_cookie=CheckForPermission; aid=fwAAAmbt+9oB1RYgkLwDAnZ8FKZyxlz382e+nMOc/E0BTrn0; cSyncDp14v4=1726872539; cSyncDp17v2=1726872541; cSyncDp104v2=1726872545
Source: global trafficHTTP traffic detected: GET /sync HTTP/1.1Host: solta-sync.rutarget.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: userId=JcwMBctHpuCG
Source: global trafficHTTP traffic detected: GET /match/videohead?id=159a8e1d-408b-4725-b19f-a152c6da5aea&chk=1 HTTP/1.1Host: sync.gonet-ads.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: chk=1
Source: global trafficHTTP traffic detected: GET /img/tgme/pattern.svg?1 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /alfadart/sync?uid=5322f90c-68ee-4d33-bc6f-6140cef1f878&ud_tpt=eyJoZWFkZXJzIjp7InJlZmVyZXIiOlsiaHR0cDovL3huLS1yMWEud2Vic2l0ZS8iLCJodHRwOi8veG4tLXIxYS53ZWJzaXRlLyJdfX0 HTTP/1.1Host: 1a499899-1e99-4cfb-8b72-6faaa7f572f3.sync.upravel.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: session_tptc=1726872547815; user_id=1a499899-1e99-4cfb-8b72-6faaa7f572f3
Source: global trafficHTTP traffic detected: GET /sync?ssp=between HTTP/1.1Host: x.bidswitch.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?dmpkit_cid=9064fc6c-76fe-4a6d-aea6-92ef3f343257&dmpkit_evid=8vhicaia6d0gnvnhrxxom892oalkpb77&user_prg=NWFmOTc5NmUyOTU5MmY5Nw HTTP/1.1Host: dmp.sbermarketing.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dmpuid=L75BS5vkQKCeo3UHIXPb7A
Source: global trafficHTTP traffic detected: GET /p?ssp=ot&id=NjZlZGZiZTEwMTIxZTQwNw%3D%3D HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /match?bidder_id=4098&external_user_id=NGRkZDA3N2FiZTI0ZmI4ZA HTTP/1.1Host: ads.betweendigital.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dc=lux1; tuuid=934fd479-13e4-5209-ba1b-9425dcf66ff5; ut=Zu370AAAIyh89YMwyDb-xs_V4HAMjqxjMWk7dA==; ss=1; unm=1
Source: global trafficHTTP traffic detected: GET /p?ssp=up&id=1a499899-1e99-4cfb-8b72-6faaa7f572f3 HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /sync?ssp=between HTTP/1.1Host: x.bidswitch.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rtb/sync/segmento?u=JcwMBctHpuCG HTTP/1.1Host: kimberlite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: f=https%3A%2F%2Fcs.alfasense.com%2Fp%3Fssp%3Dst%26id%3DZu372NYn4og; n=2; as=OFrH4Wbt--U; da=SeOR3QAAAAE; u=Zu372NYn4og~ApTXE7XyWiS79ldKFQbaW0Z7ybQ
Source: global trafficHTTP traffic detected: GET /p?ssp=up&id=1a499899-1e99-4cfb-8b72-6faaa7f572f3 HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /p?ssp=st&id=Zu372NYn4og HTTP/1.1Host: cs.alfasense.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /match?bidder_id=4098&external_user_id=NGRkZDA3N2FiZTI0ZmI4ZA HTTP/1.1Host: ads.betweendigital.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dc=lux1; tuuid=934fd479-13e4-5209-ba1b-9425dcf66ff5; ss=1; unm=1; ut=Zu376QAJTtCHBpVM1_OZj7-wUEWj4iWqhARVSg==
Source: global trafficHTTP traffic detected: GET /p?ssp=st&id=Zu372NYn4og HTTP/1.1Host: cs.alfasense.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: uuid=5322f90c-68ee-4d33-bc6f-6140cef1f878
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?tz=240&w=970&h=90&domain=xn--r1a.website&l=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&s=38014&cur=RUB&bidid=2001579a0ee1035&transactionid=&auctionid=&bidfloor=0 HTTP/1.1Host: ssp.otm-r.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mpid=NjZlZGZiZTEwMTIxZTQwNw==
Source: global trafficHTTP traffic detected: GET /rtb/direct_banner?bid_id=22915062ea146a6&pid=66&tid=970x90_alfadart&known=1&is_video=false&resp_type=JSON&provider=direct.prebidjs&size=970x90&floor=0.1&cur=RUB HTTP/1.1Host: px.adhigh.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gi_u=ujPJCLnjOrl.AikABlGSEZ_GxQ; sape_sync=L7Gf
Source: global trafficHTTP traffic detected: GET /adjson?t=prebid HTTP/1.1Host: ads.betweendigital.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dc=lux1; tuuid=934fd479-13e4-5209-ba1b-9425dcf66ff5; ss=1; unm=1; ut=Zu376gAKAoCOsi5wKoKrpHPCIrosSn--AUSdKg==
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?tz=240&w=970&h=90&domain=xn--r1a.website&l=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&s=38014&cur=RUB&bidid=2001579a0ee1035&transactionid=&auctionid=&bidfloor=0 HTTP/1.1Host: ssp.otm-r.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mpid=NjZlZGZiZTEwMTIxZTQwNw==
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ogorodru/14044?single HTTP/1.1Host: tttttt.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: stel_ssid=39622c525e4fb041eb_17928877124735159298
Source: global trafficHTTP traffic detected: GET /ogorodru/14046?single HTTP/1.1Host: tttttt.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: stel_ssid=39622c525e4fb041eb_17928877124735159298
Source: global trafficHTTP traffic detected: GET /rtb/direct_banner?bid_id=400476d86e2e03&pid=66&tid=970x90_alfadart&known=1&is_video=false&resp_type=JSON&provider=direct.prebidjs&size=970x90&floor=0.1&cur=RUB HTTP/1.1Host: px.adhigh.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gi_u=ujPJCLnjOrl.AikABlGSEZ_GxQ; sape_sync=L7Gf
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?tz=240&w=970&h=90&domain=xn--r1a.website&l=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&s=38014&cur=RUB&bidid=3441016f98750b2&transactionid=&auctionid=&bidfloor=0 HTTP/1.1Host: ssp.otm-r.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36content-type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mpid=NjZlZGZiZTEwMTIxZTQwNw==
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?t=prebid HTTP/1.1Host: ads.betweendigital.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dc=lux1; tuuid=934fd479-13e4-5209-ba1b-9425dcf66ff5; ss=1; unm=1; ut=Zu376gAKAoCOsi5wKoKrpHPCIrosSn--AUSdKg==
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&e=r&t=p HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adjson?tz=240&w=970&h=90&domain=xn--r1a.website&l=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&s=38014&cur=RUB&bidid=3441016f98750b2&transactionid=&auctionid=&bidfloor=0 HTTP/1.1Host: ssp.otm-r.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: mpid=NjZlZGZiZTEwMTIxZTQwNw==
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&e=r&t=p HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /events/1x1.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: s.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stats/2x2.png?s=129242&a=fallback&k1=1&k2=1&e=i&t=p&c=0 HTTP/1.1Host: v.alfasrv.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/telegram-widget.js?22 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/telegram-widget.js?22 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ogorodru/14046?embed=1&mode=tme&single=1 HTTP/1.1Host: t.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://tttttt.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/FmiN1jd6kyJcAeWZgqW4F1M6SO2Eq2RyWTZW_blsnSEOdaGcnsZyCyUn7iIiSZTDSWAItP34AXMi8zvOoqM-IcdUp3TUVCz0MhcVRIWT4BXCt3eTxwYPub8hQGapqCMCUQQ656ysDa7TxKg2_iJgkXF8jnWEsubIs0Q7ol6Ma4rq1Tj21ueeiPUmscCaomkBd2JrnI_qU6CxtVAC7Dn7w-z6QsmN4TePjVK8NNkb7liOQWKnbxGEfgDyDriRvwLWSnaFj8kfRICBMhevGgqVyW0k0KWygDnfKeiWFwAmnmNtvGOtou8h7HZNKTgQEuX-Z2IvurSOcnyALF6aJtSGUg.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/font-roboto.css?1 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/widget-frame.css?67 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/telegram-widget.js?22 HTTP/1.1Host: oauth.tg.devConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/widget-frame.js?62 HTTP/1.1Host: telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/J5IrM8TywMmqx4ZfsUIWmzOHXcIjMdle0j0Zye8AO8h7bW7lhRtHf3rwMLDqu1isIJ0dw4EPOjBNlHAyHkNkqgqqjh8bR4nUqiAq6P_Ej9AZoBXBJeew5Cc4vlPcPkF_wYV80A7hegzAshbhSvXqCnDH5V6aOOf7JlRhjqTNYlbVwc86WiQGXK-PYmGGLWbETscY3DjcM5yPhiNFExJeNB4Vmje0RXBoV0ZTy6_9TRw07Sxw2e1uNLWxPedOdw1hodtMeSZKBpnDOCWgw8at3icavvKT6l06C2LJfPQsvc5AA8D84CylCQg4KJNRiSPyY75fex2yWcr7nk-SqIErpQ.jpg HTTP/1.1Host: cdn4.cdn-telegram.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://t.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/?views=eyJjIjotMTA2ODMyMjQ2MSwicCI6MTQwNDYsInQiOjE3MjY4NzI1OTQsImgiOiIyOTM2YjBiNTEyNjQ3M2ZiYjkifQ HTTP/1.1Host: t.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"X-Requested-With: XMLHttpRequestsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://t.me/ogorodru/14046?embed=1&mode=tme&single=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: stel_ssid=d71a78d4cf8953adbd_10054374645480682488; stel_on=1; stel_dt=240
Source: global trafficHTTP traffic detected: GET /js/telegram-widget.js?22 HTTP/1.1Host: oauth.tg.devConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/widget-frame.js?62 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/?views=eyJjIjotMTA2ODMyMjQ2MSwicCI6MTQwNDYsInQiOjE3MjY4NzI1OTQsImgiOiIyOTM2YjBiNTEyNjQ3M2ZiYjkifQ HTTP/1.1Host: t.meConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: stel_ssid=d71a78d4cf8953adbd_10054374645480682488; stel_on=1; stel_dt=240
Source: global trafficHTTP traffic detected: GET /ogorodru/14046?embed=1&mode=tme&single=1 HTTP/1.1Host: t.meConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: stel_ssid=d71a78d4cf8953adbd_10054374645480682488; stel_on=1; stel_dt=240
Source: global trafficHTTP traffic detected: GET /s/ogorodru HTTP/1.1Host: xn--r1a.websiteConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/font-roboto.css?1 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/widget-frame.css?67 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/telegram-web.css?37 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/jquery.min.js HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/jquery-ui.min.js HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgwallpaper.min.js?3 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgsticker.js?31 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/widget-frame.js?62 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/telegram-web.js?14 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOmCnqEu92Fr1Mu4mxKKTU1Kg.woff2 HTTP/1.1Host: telegram.orgConnection: keep-aliveOrigin: http://xn--r1a.websiteUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/tgme/pattern.svg?1 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://telegram.org/css/telegram-web.css?37Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOlCnqEu92Fr1MmEU9fABc4AMP6lbBP.woff2 HTTP/1.1Host: telegram.orgConnection: keep-aliveOrigin: http://xn--r1a.websiteUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOlCnqEu92Fr1MmEU9fBBc4AMP6lQ.woff2 HTTP/1.1Host: telegram.orgConnection: keep-aliveOrigin: http://xn--r1a.websiteUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fonts/Roboto/KFOmCnqEu92Fr1Mu5mxKKTU1Kvnz.woff2 HTTP/1.1Host: telegram.orgConnection: keep-aliveOrigin: http://xn--r1a.websiteUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://telegram.org/css/font-roboto.css?1Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8D92.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/jquery.min.js HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgwallpaper.min.js?3 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/jquery-ui.min.js HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/tgsticker.js?31 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/widget-frame.js?62 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js/telegram-web.js?14 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/ HTTP/1.1Host: xn--r1a.websiteConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/tgme/pattern.svg?1 HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8D92.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/E29DA4.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F988A.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CBA.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/E29DA4.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F988A.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CBA.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CB8.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CBC.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F94B8.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CB8.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F8CBC.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/emoji/40/F09F94B8.png HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/ HTTP/1.1Host: xn--r1a.websiteConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/favicon.ico HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/favicon.ico HTTP/1.1Host: telegram.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/asyncjs.php HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/asyncspc.php?zones=8&prefix=revive-0-&xcampaigns=%3A%3Abetween%3A%3Agetintent%3A%3Avox%3A%3Aotm%3A%3Aalfasense%3A%3Artbsape%3A%3Adefault-stub%3A%3Akimberlite%3A%3A&xsite=13097&xsitename=xn--r1a.website&loc=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Origin: http://xn--r1a.websiteReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/asyncjs.php HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/asyncspc.php?zones=8&prefix=revive-0-&xcampaigns=%3A%3Abetween%3A%3Agetintent%3A%3Avox%3A%3Aotm%3A%3Aalfasense%3A%3Artbsape%3A%3Adefault-stub%3A%3Akimberlite%3A%3A&xsite=13097&xsitename=xn--r1a.website&loc=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/images/93e6032137695635299ea12513020a22.jpg HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/lg.php?bannerid=104&campaignid=15&zoneid=8&loc=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&cb=5956ea5e46&zones=8&xcampaigns=::between::getintent::vox::otm::alfasense::rtbsape::default-stub::kimberlite::&xsite=13097&xsitename=xn--r1a.website HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://xn--r1a.website/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adserver/www/images/93e6032137695635299ea12513020a22.jpg HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: SRVGROUP=common
Source: global trafficHTTP traffic detected: GET /adserver/www/delivery/lg.php?bannerid=104&campaignid=15&zoneid=8&loc=http%3A%2F%2Fxn--r1a.website%2Fs%2Fogorodru&cb=5956ea5e46&zones=8&xcampaigns=::between::getintent::vox::otm::alfasense::rtbsape::default-stub::kimberlite::&xsite=13097&xsitename=xn--r1a.website HTTP/1.1Host: ads.alfasense.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: SRVGROUP=common
Source: global trafficDNS traffic detected: DNS query: xn--r1a.website
Source: global trafficDNS traffic detected: DNS query: telegram.org
Source: global trafficDNS traffic detected: DNS query: cdn4.cdn-telegram.org
Source: global trafficDNS traffic detected: DNS query: yandex.ru
Source: global trafficDNS traffic detected: DNS query: tttttt.me
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: matchid.adfox.yandex.ru
Source: global trafficDNS traffic detected: DNS query: ads.digitalcaramel.com
Source: global trafficDNS traffic detected: DNS query: ads.betweendigital.com
Source: global trafficDNS traffic detected: DNS query: yhb.p.otm-r.com
Source: global trafficDNS traffic detected: DNS query: px.adhigh.net
Source: global trafficDNS traffic detected: DNS query: ad.mail.ru
Source: global trafficDNS traffic detected: DNS query: ssp.bidvol.com
Source: global trafficDNS traffic detected: DNS query: ssp-rtb.sape.ru
Source: global trafficDNS traffic detected: DNS query: exchange.buzzoola.com
Source: global trafficDNS traffic detected: DNS query: ssp.hybrid.ai
Source: global trafficDNS traffic detected: DNS query: pb.adriver.ru
Source: global trafficDNS traffic detected: DNS query: kimberlite.io
Source: global trafficDNS traffic detected: DNS query: pbs.alfasense.com
Source: global trafficDNS traffic detected: DNS query: yastatic.net
Source: global trafficDNS traffic detected: DNS query: avatars.mds.yandex.net
Source: global trafficDNS traffic detected: DNS query: mc.yandex.ru
Source: global trafficDNS traffic detected: DNS query: ads.adfox.ru
Source: global trafficDNS traffic detected: DNS query: cdn.alfasense.net
Source: global trafficDNS traffic detected: DNS query: cs.alfasense.com
Source: global trafficDNS traffic detected: DNS query: cstatic.weborama.com
Source: global trafficDNS traffic detected: DNS query: ad.adriver.ru
Source: global trafficDNS traffic detected: DNS query: const.uno
Source: global trafficDNS traffic detected: DNS query: v.alfasrv.com
Source: global trafficDNS traffic detected: DNS query: dx.frontend.weborama.com
Source: global trafficDNS traffic detected: DNS query: ssp.otm-r.com
Source: global trafficDNS traffic detected: DNS query: s.alfasrv.com
Source: global trafficDNS traffic detected: DNS query: acint.net
Source: global trafficDNS traffic detected: DNS query: a.videohead.tech
Source: global trafficDNS traffic detected: DNS query: s.suprion.ru
Source: global trafficDNS traffic detected: DNS query: sync.bumlam.com
Source: global trafficDNS traffic detected: DNS query: sync.rambler.ru
Source: global trafficDNS traffic detected: DNS query: www.acint.net
Source: global trafficDNS traffic detected: DNS query: cs.agency2.ru
Source: global trafficDNS traffic detected: DNS query: ssp.al-adtech.com
Source: global trafficDNS traffic detected: DNS query: sync.adspend.space
Source: global trafficDNS traffic detected: DNS query: a.adiam.tech
Source: global trafficDNS traffic detected: DNS query: x01.aidata.io
Source: global trafficDNS traffic detected: DNS query: alfasense-sync.rutarget.ru
Source: global trafficDNS traffic detected: DNS query: mc.acint.net
Source: global trafficDNS traffic detected: DNS query: sm.rtb.mts.ru
Source: global trafficDNS traffic detected: DNS query: a.utraff.com
Source: global trafficDNS traffic detected: DNS query: ev.adriver.ru
Source: global trafficDNS traffic detected: DNS query: match.ohmy.bid
Source: global trafficDNS traffic detected: DNS query: vma.mts.ru
Source: global trafficDNS traffic detected: DNS query: rtb.segmel.io
Source: global trafficDNS traffic detected: DNS query: sync.opendsp.ru
Source: global trafficDNS traffic detected: DNS query: s.uuidksinc.net
Source: global trafficDNS traffic detected: DNS query: cm.a.mts.ru
Source: global trafficDNS traffic detected: DNS query: match.new-programmatic.com
Source: global trafficDNS traffic detected: DNS query: rtb.dynotech.io
Source: global trafficDNS traffic detected: DNS query: 2348964281726872543783.cm.a.mts.ru
Source: global trafficDNS traffic detected: DNS query: sync.dmp.otm-r.com
Source: global trafficDNS traffic detected: DNS query: sync.programmatica.com
Source: global trafficDNS traffic detected: DNS query: sape-sync.rutarget.ru
Source: global trafficDNS traffic detected: DNS query: match.qtarget.tech
Source: global trafficDNS traffic detected: DNS query: sync.upravel.com
Source: global trafficDNS traffic detected: DNS query: ads.alfasense.net
Source: global trafficDNS traffic detected: DNS query: dmp.sbermarketing.ru
Source: global trafficDNS traffic detected: DNS query: sync.gonet-ads.com
Source: global trafficDNS traffic detected: DNS query: solta-sync.rutarget.ru
Source: global trafficDNS traffic detected: DNS query: 1a499899-1e99-4cfb-8b72-6faaa7f572f3.sync.upravel.com
Source: global trafficDNS traffic detected: DNS query: x.bidswitch.net
Source: global trafficDNS traffic detected: DNS query: t.me
Source: global trafficDNS traffic detected: DNS query: oauth.tg.dev
Source: unknownHTTP traffic detected: POST /adfoxhb HTTP/1.1Host: ssp.hybrid.aiConnection: keep-aliveContent-Length: 368sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: text/plainAccept: */*Origin: http://xn--r1a.websiteSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://xn--r1a.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.14.1Date: Fri, 20 Sep 2024 22:49:21 GMTContent-Type: text/htmlContent-Length: 571Connection: close
Source: chromecache_200.2.dr, chromecache_330.2.drString found in binary or memory: http://ads.alfasense.net/adserver/www/delivery/asyncspc.php
Source: chromecache_255.2.drString found in binary or memory: http://getbootstrap.com)
Source: chromecache_255.2.drString found in binary or memory: http://getbootstrap.com/customize/?id=92d2ac1b31978642b6b6)
Source: chromecache_190.2.dr, chromecache_240.2.drString found in binary or memory: http://my.opera.com/emoller/blog/2011/12/20/requestanimationframe-for-smart-er-animating
Source: chromecache_190.2.dr, chromecache_240.2.drString found in binary or memory: http://paulirish.com/2011/requestanimationframe-for-smart-animating/
Source: chromecache_200.2.dr, chromecache_330.2.drString found in binary or memory: https://ads.alfasense.net/adserver/www/delivery/asyncspc.php
Source: chromecache_244.2.dr, chromecache_306.2.drString found in binary or memory: https://ctx.weborama.com/api/profile
Source: chromecache_244.2.dr, chromecache_306.2.drString found in binary or memory: https://dx.frontend.weborama.com/collect
Source: chromecache_244.2.dr, chromecache_306.2.drString found in binary or memory: https://dx.frontend.weborama.com/videos
Source: chromecache_255.2.drString found in binary or memory: https://gist.github.com/92d2ac1b31978642b6b6
Source: chromecache_255.2.drString found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
Source: chromecache_209.2.drString found in binary or memory: https://oauth.telegram.org
Source: chromecache_209.2.drString found in binary or memory: https://oauth.tg.dev
Source: chromecache_321.2.drString found in binary or memory: https://osx.telegram.org/updates/site/artboard.png)
Source: chromecache_321.2.drString found in binary or memory: https://osx.telegram.org/updates/site/artboard_2x.png);
Source: chromecache_218.2.dr, chromecache_248.2.dr, chromecache_326.2.dr, chromecache_209.2.drString found in binary or memory: https://post.tg.dev
Source: chromecache_218.2.dr, chromecache_248.2.dr, chromecache_326.2.dr, chromecache_209.2.drString found in binary or memory: https://t.me
Source: chromecache_218.2.dr, chromecache_248.2.dr, chromecache_326.2.dr, chromecache_209.2.drString found in binary or memory: https://telegram-js.azureedge.net
Source: chromecache_218.2.dr, chromecache_248.2.dr, chromecache_326.2.dr, chromecache_209.2.drString found in binary or memory: https://telegram.org
Source: chromecache_218.2.dr, chromecache_248.2.dr, chromecache_326.2.dr, chromecache_209.2.drString found in binary or memory: https://tg.dev
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65002 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65083 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65014 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 65095 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65117 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65060 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65025 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65128 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 65036 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65061 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65094 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65049 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65129 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65106 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64984 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65024 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65072 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 65013 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 64995 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65073
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65074
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65071
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65072
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65077
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65078
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65076
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 65096 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65070
Source: unknownNetwork traffic detected: HTTP traffic on port 65050 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65073 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65035 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65104 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65069
Source: unknownNetwork traffic detected: HTTP traffic on port 65012 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65127 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64994 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65084
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65085
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65082
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65083
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65088
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
Source: unknownNetwork traffic detected: HTTP traffic on port 65085 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65089
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65086
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65087
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 65001 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65080
Source: unknownNetwork traffic detected: HTTP traffic on port 65138 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65081
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65084 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65079
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65095
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65096
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65093
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65094
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65099
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65097
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65098
Source: unknownNetwork traffic detected: HTTP traffic on port 65023 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65091
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65092
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65000 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65090
Source: unknownNetwork traffic detected: HTTP traffic on port 65116 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 65062 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65034 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65105 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65040 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65086 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65063 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65114 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65137 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64998 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64990
Source: unknownNetwork traffic detected: HTTP traffic on port 65022 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64986 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64989
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64988
Source: unknownNetwork traffic detected: HTTP traffic on port 65074 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65011 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64985
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64984
Source: unknownNetwork traffic detected: HTTP traffic on port 65103 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64986
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64999
Source: unknownNetwork traffic detected: HTTP traffic on port 65052 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64992
Source: unknownNetwork traffic detected: HTTP traffic on port 65010 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64991
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64994
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64993
Source: unknownNetwork traffic detected: HTTP traffic on port 65033 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64996
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64995
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64998
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64997
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 65041 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 65097 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65115 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65126 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65009 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65021 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64985 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65064 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65113 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65053 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65099 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65032 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64997 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65124 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65042 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65065 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65098 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65102 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64996 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65087 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65020 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65076 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65136 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64989 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65019 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65134 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65077 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65111 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65054 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65031 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64990 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65089 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65043 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65008 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65088 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65007 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65135 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65123 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65066 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65112 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65030 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65055 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65044 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65121 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65018 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65091 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65078 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65110 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65029 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65017 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65090 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65079 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65056 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65045 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65006 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65133 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64988 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64999 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65122 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65030
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65033
Source: unknownNetwork traffic detected: HTTP traffic on port 65092 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65034
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65031
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65032
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65028 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65005 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65026
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65027
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65024
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65025
Source: unknownNetwork traffic detected: HTTP traffic on port 65108 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65028
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65029
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65040
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65041
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65044
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65045
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65042
Source: unknownNetwork traffic detected: HTTP traffic on port 65039 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65043
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65131 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65080 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65057 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65037
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65038
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65035
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65036
Source: unknownNetwork traffic detected: HTTP traffic on port 64993 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65120 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65039
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65052
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65050
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65055
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65056
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65053
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65054
Source: unknownNetwork traffic detected: HTTP traffic on port 65046 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65132 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65081 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65048
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65049
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65046
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65047
Source: unknownNetwork traffic detected: HTTP traffic on port 64992 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65062
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65063
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65060
Source: unknownNetwork traffic detected: HTTP traffic on port 65016 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65061
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65066
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65064
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65065
Source: unknownNetwork traffic detected: HTTP traffic on port 65058 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65027 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65059
Source: unknownNetwork traffic detected: HTTP traffic on port 65069 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65057
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65058
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65109 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 64991 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65015 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65110
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65111
Source: unknownNetwork traffic detected: HTTP traffic on port 65038 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65130 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65118 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65109
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 65047 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65103
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65104
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65102
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65107
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65108
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65105
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65106
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65000
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65121
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65001
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65122
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65120
Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 65004 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65114
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 65070 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65115
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65112
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65113
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49752 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49768 version: TLS 1.2
Source: classification engineClassification label: mal48.win@28/232@202/72
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1720,i,7126892294250420465,11752881237129370253,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://xn--r1a.website/s/ogorodru"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1720,i,7126892294250420465,11752881237129370253,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.