Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.wwwamp.com/

Overview

General Information

Sample URL:http://www.wwwamp.com/
Analysis ID:1590441
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
AI detected suspicious URL
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 3152 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2812 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1884,i,14627629829776049905,369663499561058158,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.wwwamp.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.wwwamp.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://096159.com/favicon.icoAvira URL Cloud: Label: phishing
Source: http://096159.com/?a=x&c=Avira URL Cloud: Label: phishing
Source: https://096159.com/sw/favicon.icoAvira URL Cloud: Label: phishing

Phishing

barindex
Source: URLJoe Sandbox AI: AI detected Brand spoofing attempt in URL: http://www.wwwamp.com
Source: URLJoe Sandbox AI: AI detected Typosquatting in URL: http://www.wwwamp.com
Source: https://096159.com/?a=x&c=HTTP Parser: No favicon
Source: global trafficTCP traffic: 192.168.2.4:49795 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /?a=x&c= HTTP/1.1Host: 096159.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 096159.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://096159.com/?a=x&c=Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sw/favicon.ico HTTP/1.1Host: 096159.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://096159.com/?a=x&c=Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.wwwamp.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=x&c= HTTP/1.1Host: 096159.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.wwwamp.com
Source: global trafficDNS traffic detected: DNS query: 096159.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbidden
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbidden
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: classification engineClassification label: mal60.win@17/4@11/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1884,i,14627629829776049905,369663499561058158,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.wwwamp.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1884,i,14627629829776049905,369663499561058158,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.wwwamp.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://096159.com/favicon.ico100%Avira URL Cloudphishing
http://096159.com/?a=x&c=100%Avira URL Cloudphishing
https://096159.com/sw/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.16.196
truefalse
    high
    67899.mercuriaLsoLdes.com
    112.213.110.37
    truefalse
      unknown
      cr28-site-01.cdn-ng.net
      43.251.56.196
      truefalse
        unknown
        096159.com
        unknown
        unknownfalse
          unknown
          www.wwwamp.com
          unknown
          unknowntrue
            unknown
            NameMaliciousAntivirus DetectionReputation
            http://www.wwwamp.com/true
              unknown
              https://096159.com/sw/favicon.icofalse
              • Avira URL Cloud: phishing
              unknown
              https://096159.com/?a=x&c=false
                unknown
                https://096159.com/favicon.icofalse
                • Avira URL Cloud: phishing
                unknown
                http://096159.com/?a=x&c=false
                • Avira URL Cloud: phishing
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                43.251.56.196
                cr28-site-01.cdn-ng.netTaiwan; Republic of China (ROC)
                131603WSN-TW-NET-ASWorldstarNetworkTWfalse
                103.24.55.98
                unknownunknown
                132645IDNIC-PPNS-AS-IDPoliteknikPerkapalanNegeriSurabayaIDfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                172.217.16.196
                www.google.comUnited States
                15169GOOGLEUSfalse
                112.213.110.37
                67899.mercuriaLsoLdes.comHong Kong
                38197SUNHK-DATA-AS-APSunNetworkHongKongLimited-HongKongfalse
                IP
                192.168.2.4
                192.168.2.5
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1590441
                Start date and time:2025-01-14 01:48:04 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 59s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://www.wwwamp.com/
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal60.win@17/4@11/7
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.186.46, 64.233.167.84, 142.250.185.142, 142.250.186.78, 199.232.214.172, 2.17.190.73, 216.58.212.174, 172.217.18.14, 172.217.16.206, 142.250.181.238, 142.250.185.238, 216.58.206.67, 142.251.35.174, 74.125.0.102, 184.28.90.27, 4.175.87.197, 20.109.210.53, 13.107.246.45
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: http://www.wwwamp.com/
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1417), with no line terminators
                Category:downloaded
                Size (bytes):1447
                Entropy (8bit):5.526689641675772
                Encrypted:false
                SSDEEP:24:kHVAPdRdJVXVVsmM5e57zUjffflV79ff1Kzfj2WlvnZw+lFBLc3fysr1ffa0GxR4:MkpsA5WfffHxffMzfj2WlfDFBo3/gDAt
                MD5:9D914B450FE14DB8D7267390BF3FD596
                SHA1:8AB7EF8823F0D96EC1850FD3A25C6BF113FCF9F1
                SHA-256:1839F6E0CF0285B619918D9B92B4F8EA32C6C59D17AEB14C909A349D72B70362
                SHA-512:561B9065761FB1FF54CA89118D1F1EDEF6F07B64A8912BBFD9D74E6C68E7B971C68650B2AA5E3B537040B2D32D8362ABD87AEF81599100D1C6A9BC540C45DFFF
                Malicious:false
                Reputation:low
                URL:https://096159.com/sw/favicon.ico
                Preview:<html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-color:rgb(46,46,46);font-family:Arial,sans-serif;font-size:1rem}.container{background-image:linear-gradient(180deg,rgb(239,95,95)0,rgb(149,44,44)100%);border-radius:8px;overflow:hidden;width:720px;box-shadow:0 3px 12px rgb(0,0,0)}.info-block{padding:32.21px 0 30px 24px;color:rgb(255,255,255);display:flex;align-items:flex-start;flex-direction:column}.message-block{background:rgb(255,255,255);color:rgb(153,153,153);text-align:center;padding:6px}.ip-style{font-size:2.5rem;margin-top:6px}.info-pos{position:relative}svg{position:absolute;top:0;right:0}@media screen and(max-width:768px){.container{width:85%}.info-block{font-size:1.25rem}.ip-style{font-size:1.75rem}}</style></head><body><div class="container"><div class="info-pos"><div class="f
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1417), with no line terminators
                Category:downloaded
                Size (bytes):1447
                Entropy (8bit):5.526689641675772
                Encrypted:false
                SSDEEP:24:kHVAPdRdJVXVVsmM5e57zUjffflV79ff1Kzfj2WlvnZw+lFBLc3fysr1ffa0GxR4:MkpsA5WfffHxffMzfj2WlfDFBo3/gDAt
                MD5:9D914B450FE14DB8D7267390BF3FD596
                SHA1:8AB7EF8823F0D96EC1850FD3A25C6BF113FCF9F1
                SHA-256:1839F6E0CF0285B619918D9B92B4F8EA32C6C59D17AEB14C909A349D72B70362
                SHA-512:561B9065761FB1FF54CA89118D1F1EDEF6F07B64A8912BBFD9D74E6C68E7B971C68650B2AA5E3B537040B2D32D8362ABD87AEF81599100D1C6A9BC540C45DFFF
                Malicious:false
                Reputation:low
                URL:https://096159.com/?a=x&c=
                Preview:<html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-color:rgb(46,46,46);font-family:Arial,sans-serif;font-size:1rem}.container{background-image:linear-gradient(180deg,rgb(239,95,95)0,rgb(149,44,44)100%);border-radius:8px;overflow:hidden;width:720px;box-shadow:0 3px 12px rgb(0,0,0)}.info-block{padding:32.21px 0 30px 24px;color:rgb(255,255,255);display:flex;align-items:flex-start;flex-direction:column}.message-block{background:rgb(255,255,255);color:rgb(153,153,153);text-align:center;padding:6px}.ip-style{font-size:2.5rem;margin-top:6px}.info-pos{position:relative}svg{position:absolute;top:0;right:0}@media screen and(max-width:768px){.container{width:85%}.info-block{font-size:1.25rem}.ip-style{font-size:1.75rem}}</style></head><body><div class="container"><div class="info-pos"><div class="f
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Jan 14, 2025 01:48:59.312400103 CET49675443192.168.2.4173.222.162.32
                Jan 14, 2025 01:49:05.153120041 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.153155088 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.153234959 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.153670073 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.153681040 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.808497906 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.808969021 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.808981895 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.809822083 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.809926987 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.811201096 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.811249018 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.860671997 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:05.860735893 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:05.907613993 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:07.203682899 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:07.204278946 CET4974180192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:07.208777905 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:07.208868980 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:07.209022999 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:07.209095001 CET8049741112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:07.209158897 CET4974180192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:07.213973999 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:08.082827091 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:08.124795914 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:09.783672094 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:49:09.789792061 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:49:09.789932966 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:49:09.790226936 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:49:09.796169043 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:49:10.585654974 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:49:10.625792980 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:49:11.268263102 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:11.268315077 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:11.268378973 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:11.268865108 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:11.268882990 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.216594934 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.217526913 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.217561007 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.219008923 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.219151974 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.224320889 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.224397898 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.224929094 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.224937916 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.267556906 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.780226946 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.780786991 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.780937910 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:12.783878088 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.787923098 CET49743443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:12.787954092 CET44349743103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:13.649981976 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:13.650048018 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:13.650171041 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:13.650516987 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:13.650541067 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:14.665848017 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:14.666276932 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:14.666343927 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:14.666857958 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:14.667371035 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:14.667462111 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:14.667531013 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:14.715346098 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.310776949 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.311600924 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.311693907 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:15.312074900 CET49746443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:15.312117100 CET44349746103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.314146042 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:15.314183950 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.314240932 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:15.314471960 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:15.314483881 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:15.740442038 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:15.740593910 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:15.740663052 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:16.341026068 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.341345072 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.341381073 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.341862917 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.342195988 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.342276096 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.342364073 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.383337975 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.918531895 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.918761015 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.918836117 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:16.918859959 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.918889046 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.920408010 CET49750443192.168.2.4103.24.55.98
                Jan 14, 2025 01:49:16.920430899 CET44349750103.24.55.98192.168.2.4
                Jan 14, 2025 01:49:17.454144955 CET49737443192.168.2.4172.217.16.196
                Jan 14, 2025 01:49:17.454220057 CET44349737172.217.16.196192.168.2.4
                Jan 14, 2025 01:49:52.218071938 CET4974180192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:52.222959995 CET8049741112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:53.093050003 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:49:53.098294020 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:49:55.592763901 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:49:55.599649906 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:50:00.507678986 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:00.512568951 CET53497951.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.512650013 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:00.512811899 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:00.512829065 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:00.517736912 CET53497951.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.517767906 CET53497951.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.988245010 CET53497951.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.989052057 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:00.994458914 CET53497951.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.994631052 CET4979553192.168.2.41.1.1.1
                Jan 14, 2025 01:50:05.203115940 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:05.203150988 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.203726053 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:05.203948021 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:05.203958988 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.839426994 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.839749098 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:05.839761019 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.840267897 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.840557098 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:05.840647936 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:05.888892889 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:06.030292988 CET4972380192.168.2.4199.232.210.172
                Jan 14, 2025 01:50:06.031255007 CET4972480192.168.2.4199.232.210.172
                Jan 14, 2025 01:50:06.035423040 CET8049723199.232.210.172192.168.2.4
                Jan 14, 2025 01:50:06.035697937 CET4972380192.168.2.4199.232.210.172
                Jan 14, 2025 01:50:06.036205053 CET8049724199.232.210.172192.168.2.4
                Jan 14, 2025 01:50:06.036276102 CET4972480192.168.2.4199.232.210.172
                Jan 14, 2025 01:50:07.453809977 CET4974180192.168.2.4112.213.110.37
                Jan 14, 2025 01:50:07.458899975 CET8049741112.213.110.37192.168.2.4
                Jan 14, 2025 01:50:07.458951950 CET4974180192.168.2.4112.213.110.37
                Jan 14, 2025 01:50:08.083046913 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:50:08.083204985 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:50:09.453759909 CET4974080192.168.2.4112.213.110.37
                Jan 14, 2025 01:50:09.458662987 CET8049740112.213.110.37192.168.2.4
                Jan 14, 2025 01:50:10.621841908 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:50:10.621990919 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:50:11.453511000 CET4974280192.168.2.443.251.56.196
                Jan 14, 2025 01:50:11.458435059 CET804974243.251.56.196192.168.2.4
                Jan 14, 2025 01:50:15.774152040 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:15.774328947 CET44349828172.217.16.196192.168.2.4
                Jan 14, 2025 01:50:15.774375916 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:17.454854965 CET49828443192.168.2.4172.217.16.196
                Jan 14, 2025 01:50:17.454860926 CET44349828172.217.16.196192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Jan 14, 2025 01:49:01.017353058 CET53561061.1.1.1192.168.2.4
                Jan 14, 2025 01:49:01.111787081 CET53636701.1.1.1192.168.2.4
                Jan 14, 2025 01:49:02.159647942 CET53499201.1.1.1192.168.2.4
                Jan 14, 2025 01:49:05.143619061 CET6199453192.168.2.41.1.1.1
                Jan 14, 2025 01:49:05.143857002 CET6296553192.168.2.41.1.1.1
                Jan 14, 2025 01:49:05.151757002 CET53629651.1.1.1192.168.2.4
                Jan 14, 2025 01:49:05.151779890 CET53619941.1.1.1192.168.2.4
                Jan 14, 2025 01:49:06.596690893 CET4929953192.168.2.41.1.1.1
                Jan 14, 2025 01:49:06.596771955 CET6200153192.168.2.41.1.1.1
                Jan 14, 2025 01:49:07.104162931 CET53620011.1.1.1192.168.2.4
                Jan 14, 2025 01:49:07.104852915 CET5697753192.168.2.41.1.1.1
                Jan 14, 2025 01:49:07.143170118 CET53492991.1.1.1192.168.2.4
                Jan 14, 2025 01:49:07.605969906 CET53569771.1.1.1192.168.2.4
                Jan 14, 2025 01:49:08.089615107 CET5153753192.168.2.41.1.1.1
                Jan 14, 2025 01:49:08.090004921 CET6246353192.168.2.41.1.1.1
                Jan 14, 2025 01:49:09.111330986 CET5327853192.168.2.41.1.1.1
                Jan 14, 2025 01:49:09.111742973 CET5368553192.168.2.41.1.1.1
                Jan 14, 2025 01:49:09.728815079 CET53515371.1.1.1192.168.2.4
                Jan 14, 2025 01:49:10.290349007 CET53532781.1.1.1192.168.2.4
                Jan 14, 2025 01:49:10.588257074 CET5364253192.168.2.41.1.1.1
                Jan 14, 2025 01:49:10.588393927 CET5217553192.168.2.41.1.1.1
                Jan 14, 2025 01:49:10.670892954 CET53624631.1.1.1192.168.2.4
                Jan 14, 2025 01:49:10.671528101 CET53536851.1.1.1192.168.2.4
                Jan 14, 2025 01:49:11.207982063 CET53536421.1.1.1192.168.2.4
                Jan 14, 2025 01:49:12.576805115 CET53521751.1.1.1192.168.2.4
                Jan 14, 2025 01:49:17.598539114 CET138138192.168.2.4192.168.2.255
                Jan 14, 2025 01:49:19.117121935 CET53593561.1.1.1192.168.2.4
                Jan 14, 2025 01:49:37.852652073 CET53564251.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.507347107 CET53509761.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.507855892 CET53611961.1.1.1192.168.2.4
                Jan 14, 2025 01:50:00.730457067 CET53500391.1.1.1192.168.2.4
                TimestampSource IPDest IPChecksumCodeType
                Jan 14, 2025 01:49:07.606153011 CET192.168.2.41.1.1.1c1e4(Port unreachable)Destination Unreachable
                Jan 14, 2025 01:49:10.290585041 CET192.168.2.41.1.1.1c2c5(Port unreachable)Destination Unreachable
                Jan 14, 2025 01:49:12.577002048 CET192.168.2.41.1.1.1c235(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Jan 14, 2025 01:49:05.143619061 CET192.168.2.41.1.1.10x5f8fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:05.143857002 CET192.168.2.41.1.1.10x250eStandard query (0)www.google.com65IN (0x0001)false
                Jan 14, 2025 01:49:06.596690893 CET192.168.2.41.1.1.10xeac5Standard query (0)www.wwwamp.comA (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:06.596771955 CET192.168.2.41.1.1.10xe164Standard query (0)www.wwwamp.com65IN (0x0001)false
                Jan 14, 2025 01:49:07.104852915 CET192.168.2.41.1.1.10xdf13Standard query (0)www.wwwamp.com65IN (0x0001)false
                Jan 14, 2025 01:49:08.089615107 CET192.168.2.41.1.1.10xa630Standard query (0)096159.comA (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:08.090004921 CET192.168.2.41.1.1.10x8da1Standard query (0)096159.com65IN (0x0001)false
                Jan 14, 2025 01:49:09.111330986 CET192.168.2.41.1.1.10xa996Standard query (0)096159.comA (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:09.111742973 CET192.168.2.41.1.1.10xaf23Standard query (0)096159.com65IN (0x0001)false
                Jan 14, 2025 01:49:10.588257074 CET192.168.2.41.1.1.10xd2daStandard query (0)096159.comA (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.588393927 CET192.168.2.41.1.1.10x42e3Standard query (0)096159.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Jan 14, 2025 01:49:05.151757002 CET1.1.1.1192.168.2.40x250eNo error (0)www.google.com65IN (0x0001)false
                Jan 14, 2025 01:49:05.151779890 CET1.1.1.1192.168.2.40x5f8fNo error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:07.104162931 CET1.1.1.1192.168.2.40xe164Server failure (2)www.wwwamp.comnonenone65IN (0x0001)false
                Jan 14, 2025 01:49:07.143170118 CET1.1.1.1192.168.2.40xeac5No error (0)www.wwwamp.com67899.mercuriaLsoLdes.comCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:07.143170118 CET1.1.1.1192.168.2.40xeac5No error (0)67899.mercuriaLsoLdes.com112.213.110.37A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:07.605969906 CET1.1.1.1192.168.2.40xdf13Server failure (2)www.wwwamp.comnonenone65IN (0x0001)false
                Jan 14, 2025 01:49:09.728815079 CET1.1.1.1192.168.2.40xa630No error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:09.728815079 CET1.1.1.1192.168.2.40xa630No error (0)cr28-site-01.cdn-ng.net43.251.56.196A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:09.728815079 CET1.1.1.1192.168.2.40xa630No error (0)cr28-site-01.cdn-ng.net43.251.56.82A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:09.728815079 CET1.1.1.1192.168.2.40xa630No error (0)cr28-site-01.cdn-ng.net43.251.56.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net43.251.56.196A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net43.251.56.82A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.24.55.120A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.24.55.112A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.24.55.98A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.117.134.84A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.117.134.19A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.117.134.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.117.134.90A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.24.55.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net103.24.55.52A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.290349007 CET1.1.1.1192.168.2.40xa996No error (0)cr28-site-01.cdn-ng.net43.251.56.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:10.670892954 CET1.1.1.1192.168.2.40x8da1No error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:10.671528101 CET1.1.1.1192.168.2.40xaf23No error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.24.55.98A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.117.134.84A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.117.134.19A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.117.134.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.117.134.90A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.24.55.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.24.55.52A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net43.251.56.83A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net43.251.56.196A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net43.251.56.82A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.24.55.120A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:11.207982063 CET1.1.1.1192.168.2.40xd2daNo error (0)cr28-site-01.cdn-ng.net103.24.55.112A (IP address)IN (0x0001)false
                Jan 14, 2025 01:49:12.576805115 CET1.1.1.1192.168.2.40x42e3No error (0)096159.comcr28-site-01.cdn-ng.netCNAME (Canonical name)IN (0x0001)false
                • 096159.com
                • https:
                • www.wwwamp.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449740112.213.110.37802812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Jan 14, 2025 01:49:07.209022999 CET429OUTGET / HTTP/1.1
                Host: www.wwwamp.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Jan 14, 2025 01:49:08.082827091 CET400INHTTP/1.1 301 Moved Permanently
                Server: nginx
                Date: Tue, 14 Jan 2025 00:49:07 GMT
                Content-Type: text/html
                Content-Length: 162
                Connection: keep-alive
                Location: http://096159.com/?a=x&c=
                Strict-Transport-Security: max-age=31536000
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
                Jan 14, 2025 01:49:53.093050003 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44974243.251.56.196802812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Jan 14, 2025 01:49:09.790226936 CET432OUTGET /?a=x&c= HTTP/1.1
                Host: 096159.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Jan 14, 2025 01:49:10.585654974 CET150INHTTP/1.1 301 Moved Permanently
                Server: nginx/1.20.1
                Date: Tue, 14 Jan 2025 00:49:10 GMT
                Location: https://096159.com/?a=x&c=
                Content-Length: 0
                Jan 14, 2025 01:49:55.592763901 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449741112.213.110.37802812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Jan 14, 2025 01:49:52.218071938 CET6OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449743103.24.55.984432812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-01-14 00:49:12 UTC660OUTGET /?a=x&c= HTTP/1.1
                Host: 096159.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2025-01-14 00:49:12 UTC24INHTTP/1.1 403 Forbidden
                2025-01-14 00:49:12 UTC37INData Raw: 44 61 74 65 3a 20 54 75 65 2c 20 31 34 20 4a 61 6e 20 32 30 32 35 20 30 30 3a 34 39 3a 31 32 20 47 4d 54 0d 0a
                Data Ascii: Date: Tue, 14 Jan 2025 00:49:12 GMT
                2025-01-14 00:49:12 UTC40INData Raw: 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 0d 0a
                Data Ascii: Content-Type: text/html; charset=utf-8
                2025-01-14 00:49:12 UTC64INData Raw: 53 74 72 69 63 74 2d 54 72 61 6e 73 70 6f 72 74 2d 53 65 63 75 72 69 74 79 3a 20 6d 61 78 2d 61 67 65 3d 33 31 35 33 36 30 30 30 3b 20 69 6e 63 6c 75 64 65 53 75 62 44 6f 6d 61 69 6e 73 0d 0a
                Data Ascii: Strict-Transport-Security: max-age=31536000; includeSubDomains
                2025-01-14 00:49:12 UTC38INData Raw: 58 2d 43 61 63 68 65 3a 20 4d 49 53 53 20 66 72 6f 6d 20 6d 65 67 61 67 77 2d 63 64 6e 62 35 35 2d 30 39 38 0d 0a
                Data Ascii: X-Cache: MISS from megagw-cdnb55-098
                2025-01-14 00:49:12 UTC22INData Raw: 43 6f 6e 74 65 6e 74 2d 4c 65 6e 67 74 68 3a 20 31 34 34 37 0d 0a
                Data Ascii: Content-Length: 1447
                2025-01-14 00:49:12 UTC19INData Raw: 43 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a
                Data Ascii: Connection: close
                2025-01-14 00:49:12 UTC2INData Raw: 0d 0a
                Data Ascii:
                2025-01-14 00:49:12 UTC1447INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 34 30 33 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 62 6f 64 79 2c 64 69 76 2c 68 74 6d 6c 2c 70 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 3b 62 6f 72 64 65 72 3a 30 7d 62 6f 64 79 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 68 65 69 67 68 74 3a 31 30 30 76 68 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f
                Data Ascii: <html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-co


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449746103.24.55.984432812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-01-14 00:49:14 UTC583OUTGET /favicon.ico HTTP/1.1
                Host: 096159.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://096159.com/?a=x&c=
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2025-01-14 00:49:15 UTC32INHTTP/1.1 301 Moved Permanently
                2025-01-14 00:49:15 UTC37INData Raw: 44 61 74 65 3a 20 54 75 65 2c 20 31 34 20 4a 61 6e 20 32 30 32 35 20 30 30 3a 34 39 3a 31 35 20 47 4d 54 0d 0a
                Data Ascii: Date: Tue, 14 Jan 2025 00:49:15 GMT
                2025-01-14 00:49:15 UTC45INData Raw: 4c 6f 63 61 74 69 6f 6e 3a 20 68 74 74 70 73 3a 2f 2f 30 39 36 31 35 39 2e 63 6f 6d 2f 73 77 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 0d 0a
                Data Ascii: Location: https://096159.com/sw/favicon.ico
                2025-01-14 00:49:15 UTC33INData Raw: 58 2d 52 6f 62 6f 74 73 2d 54 61 67 3a 20 6e 6f 69 6e 64 65 78 2c 20 6e 6f 66 6f 6c 6c 6f 77 0d 0a
                Data Ascii: X-Robots-Tag: noindex, nofollow
                2025-01-14 00:49:15 UTC29INData Raw: 58 2d 46 72 61 6d 65 2d 4f 70 74 69 6f 6e 73 3a 20 53 41 4d 45 4f 52 49 47 49 4e 0d 0a
                Data Ascii: X-Frame-Options: SAMEORIGIN
                2025-01-14 00:49:15 UTC33INData Raw: 58 2d 58 53 53 2d 50 72 6f 74 65 63 74 69 6f 6e 3a 20 31 3b 20 6d 6f 64 65 3d 62 6c 6f 63 6b 0d 0a
                Data Ascii: X-XSS-Protection: 1; mode=block
                2025-01-14 00:49:15 UTC73INData Raw: 53 74 72 69 63 74 2d 54 72 61 6e 73 70 6f 72 74 2d 53 65 63 75 72 69 74 79 3a 20 6d 61 78 2d 61 67 65 3d 33 31 35 33 36 30 30 30 3b 20 69 6e 63 6c 75 64 65 53 75 62 44 6f 6d 61 69 6e 73 3b 20 70 72 65 6c 6f 61 64 0d 0a
                Data Ascii: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                2025-01-14 00:49:15 UTC38INData Raw: 58 2d 43 61 63 68 65 3a 20 4d 49 53 53 20 66 72 6f 6d 20 6d 65 67 61 67 77 2d 63 64 6e 62 35 35 2d 30 39 38 0d 0a
                Data Ascii: X-Cache: MISS from megagw-cdnb55-098
                2025-01-14 00:49:15 UTC19INData Raw: 43 6f 6e 74 65 6e 74 2d 4c 65 6e 67 74 68 3a 20 30 0d 0a
                Data Ascii: Content-Length: 0
                2025-01-14 00:49:15 UTC19INData Raw: 43 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a
                Data Ascii: Connection: close
                2025-01-14 00:49:15 UTC2INData Raw: 0d 0a
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449750103.24.55.984432812C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-01-14 00:49:16 UTC586OUTGET /sw/favicon.ico HTTP/1.1
                Host: 096159.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://096159.com/?a=x&c=
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2025-01-14 00:49:16 UTC24INHTTP/1.1 403 Forbidden
                2025-01-14 00:49:16 UTC37INData Raw: 44 61 74 65 3a 20 54 75 65 2c 20 31 34 20 4a 61 6e 20 32 30 32 35 20 30 30 3a 34 39 3a 31 36 20 47 4d 54 0d 0a
                Data Ascii: Date: Tue, 14 Jan 2025 00:49:16 GMT
                2025-01-14 00:49:16 UTC28INData Raw: 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 69 6d 61 67 65 2f 78 2d 69 63 6f 6e 0d 0a
                Data Ascii: Content-Type: image/x-icon
                2025-01-14 00:49:16 UTC64INData Raw: 53 74 72 69 63 74 2d 54 72 61 6e 73 70 6f 72 74 2d 53 65 63 75 72 69 74 79 3a 20 6d 61 78 2d 61 67 65 3d 33 31 35 33 36 30 30 30 3b 20 69 6e 63 6c 75 64 65 53 75 62 44 6f 6d 61 69 6e 73 0d 0a
                Data Ascii: Strict-Transport-Security: max-age=31536000; includeSubDomains
                2025-01-14 00:49:16 UTC38INData Raw: 58 2d 43 61 63 68 65 3a 20 4d 49 53 53 20 66 72 6f 6d 20 6d 65 67 61 67 77 2d 63 64 6e 62 35 35 2d 30 39 38 0d 0a
                Data Ascii: X-Cache: MISS from megagw-cdnb55-098
                2025-01-14 00:49:16 UTC22INData Raw: 43 6f 6e 74 65 6e 74 2d 4c 65 6e 67 74 68 3a 20 31 34 34 37 0d 0a
                Data Ascii: Content-Length: 1447
                2025-01-14 00:49:16 UTC19INData Raw: 43 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a
                Data Ascii: Connection: close
                2025-01-14 00:49:16 UTC2INData Raw: 0d 0a
                Data Ascii:
                2025-01-14 00:49:16 UTC1447INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 74 69 74 6c 65 3e 34 30 33 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 62 6f 64 79 2c 64 69 76 2c 68 74 6d 6c 2c 70 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 3b 62 6f 72 64 65 72 3a 30 7d 62 6f 64 79 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 68 65 69 67 68 74 3a 31 30 30 76 68 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f
                Data Ascii: <html><head><meta charset="UTF-8"><meta name="viewport"content="width=device-width,initial-scale=1"><title>403</title><style>body,div,html,p{margin:0;padding:0;border:0}body{display:flex;justify-content:center;align-items:center;height:100vh;background-co


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:19:48:55
                Start date:13/01/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:19:48:59
                Start date:13/01/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=1884,i,14627629829776049905,369663499561058158,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:19:49:05
                Start date:13/01/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.wwwamp.com/"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly