Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.texascrafted.com

Overview

General Information

Sample URL:http://www.texascrafted.com
Analysis ID:1632458
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

  • System is w10x64
  • chrome.exe (PID: 1844 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,4885381413271482254,15023505610315391031,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2044 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.texascrafted.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.texascrafted.comAvira URL Cloud: detection malicious, Label: malware
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJKhywEInP7MAQiFoM0BCOipzgEIvtXOAQiB1s4BCMjczgEIiuDOAQiu5M4BCIvlzgE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.texascrafted.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.texascrafted.com
Source: chromecache_42.3.drString found in binary or memory: https://www.google-analytics.com/collect
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir1844_1741142307Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir1844_1741142307Jump to behavior
Source: classification engineClassification label: mal48.win@21/4@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,4885381413271482254,15023505610315391031,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2044 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.texascrafted.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,4885381413271482254,15023505610315391031,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2044 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.texascrafted.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
unavailable.hearstnp.com
18.234.30.239
truefalse
    unknown
    www.google.com
    142.250.186.68
    truefalse
      high
      www.texascrafted.com
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
          high
          http://www.texascrafted.com/true
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.186.68
            www.google.comUnited States
            15169GOOGLEUSfalse
            18.234.30.239
            unavailable.hearstnp.comUnited States
            14618AMAZON-AESUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1632458
            Start date and time:2025-03-08 00:04:51 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 4s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://www.texascrafted.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:19
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@21/4@6/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.174, 142.250.184.195, 64.233.184.84, 216.58.212.142, 172.217.16.206, 142.250.186.78, 142.250.186.110, 199.232.210.172, 216.239.32.178, 216.239.36.178, 216.239.34.178, 216.239.38.178, 142.250.186.142, 216.58.206.78, 142.250.185.174, 142.250.185.110, 142.250.185.227, 142.250.184.238, 142.250.185.195, 23.60.203.209
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, www-alv.google-analytics.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, www.google-analytics.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: http://www.texascrafted.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):4517
            Entropy (8bit):5.82882762905198
            Encrypted:false
            SSDEEP:96:VcTaYUO16cLGd76zUOn4d2dondTcATQf6YxP7/WwSixiP6H1ukA:VsMiGd7Yt4dNd4w2z/7K6H12
            MD5:9ABA92B5E05674C9FC2F375E899186F7
            SHA1:C0E13CFCD4F7EBCCDA274F1BBD7AD23EB58497B1
            SHA-256:4657373C2F2C6190A91B2A3D6594A3B79E2EDA8BC061323797048E5FBD9415DC
            SHA-512:C57493586D1ECA8C64D5C3F2D8DD4EF96EFA09B6BB3B77AD80F5DCD36C8EE34CC1E5D0CFB5BA617225F19884AE87781F787B84D270FC20DB987B1F14DC13B6E0
            Malicious:false
            Reputation:low
            URL:http://www.texascrafted.com/
            Preview:<html lang="en" class="no-js">.<head>..<meta charset="UTF-8">..<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">..<title>Blocked for legal reasons</title>..<meta name="description" content="Sorry, this content is not available in your region.">..<meta name="viewport" content="width=device-width,user-scalable=no,initial-scale=1">..<meta name="error" content="451">..<link rel="shortcut icon"type="image/x-icon" href="data:image/x-icon;,">..<style>..html, body {...border: 0;...margin: 0;...padding: 0;..}..body {...background-color: white;...min-width: 320px;..}..body * {...font-family: Arial, "Helvetica Neue", Helvetica, sans-serif;...font-size: 18px;..}..h1 {...font-size: 32px;...color: white;...margin-bottom: 32px;...color: black;..}..p {...line-height: 1.38em;...margin-bottom: 0.6em;..}..#content {...width: 90%;...max-width: 720px;...margin: 15vh auto;..}..@media only screen and (max-width: 620px) {...#content {....margin-top: 1em;...}...p {....margin-top: auto;...}..}..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (883)
            Category:downloaded
            Size (bytes):888
            Entropy (8bit):5.161488088400176
            Encrypted:false
            SSDEEP:24:YEuHhOWndGBHslgT1d1uawBATODuoBN2t2t2t2t2t2t2tomffffffo:ABxsKlgJXwBAIuSNYYYYYYYomffffffo
            MD5:D311443BB8F624FD03AFED3EA76AA05F
            SHA1:4952D44B3E6C42D40B10890542861E0C432DFDF7
            SHA-256:25DA9CB27D001A4AE3532B35D98E18B506EDE5FD250FCCFEB22C35F7CD2B2B39
            SHA-512:AF26ACD8A5E37E2A0379B6514147712238B1F72BAB3FD0D633834E2B2D39870D9EA730E9C2C8E21E76FC33F88C544DBADB8722A801C0DA375276C60E0BFE28E4
            Malicious:false
            Reputation:low
            URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
            Preview:)]}'.["",["apple iphone 17 pro max","daily horoscopes aquarius","mlb baseball news","interstate 10 new mexico closure","red robin restaurants closing","big bear bald eagles nest","washington county maine meteorite fall","invincible season 3 episode 7"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggesteventid":"5555667055251310771","google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 8, 2025 00:05:49.763665915 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:50.071156025 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:50.680522919 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:51.976948977 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:54.430649042 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:57.408054113 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:57.408139944 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:57.408613920 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:57.408615112 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:57.408746004 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:58.430794954 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:05:58.742783070 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:05:59.179191113 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.179655075 CET4972780192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.184278965 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:05:59.184343100 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.184736013 CET804972718.234.30.239192.168.2.4
            Mar 8, 2025 00:05:59.184825897 CET4972780192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.250443935 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:05:59.265932083 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.265980005 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:05:59.266047001 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.266328096 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:05:59.266340971 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:05:59.352204084 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:05:59.788659096 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:59.789119959 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:59.789161921 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:59.790607929 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:59.790669918 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:59.791858912 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:59.791951895 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:59.838027000 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:05:59.838057041 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:05:59.885245085 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:00.563846111 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:06:01.872919083 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.878258944 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.912646055 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.913043022 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.913069963 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.915165901 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.915278912 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.920520067 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.920815945 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.964658976 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.964679956 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980328083 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980375051 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980411053 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980444908 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980479956 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:01.980478048 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:01.980537891 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:02.010694027 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:02.029683113 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:02.444860935 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:02.488370895 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:02.978615046 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:06:03.335561037 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:03.335824966 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:03.335937977 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:03.392352104 CET49724443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:03.392400980 CET44349724142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:03.736244917 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.737811089 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.737847090 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.742101908 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.743772984 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.743787050 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.844480991 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.844559908 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.846220970 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.851373911 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.945103884 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:03.945183039 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.953140974 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:03.958127022 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:04.061323881 CET44349709131.253.33.254192.168.2.4
            Mar 8, 2025 00:06:04.061404943 CET49709443192.168.2.4131.253.33.254
            Mar 8, 2025 00:06:04.064512968 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:04.064933062 CET49732443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:04.064989090 CET44349732204.79.197.222192.168.2.4
            Mar 8, 2025 00:06:04.065084934 CET49732443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:04.065522909 CET49732443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:04.065558910 CET44349732204.79.197.222192.168.2.4
            Mar 8, 2025 00:06:04.368796110 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:04.979295969 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:06.180241108 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:06.985722065 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:06.985840082 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:07.338915110 CET4972680192.168.2.418.234.30.239
            Mar 8, 2025 00:06:07.347618103 CET804972618.234.30.239192.168.2.4
            Mar 8, 2025 00:06:07.789921045 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:06:08.301578999 CET44349732204.79.197.222192.168.2.4
            Mar 8, 2025 00:06:08.301666021 CET49732443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:08.586596966 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:08.852936983 CET49671443192.168.2.4204.79.197.203
            Mar 8, 2025 00:06:13.389347076 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:17.402445078 CET49678443192.168.2.420.189.173.27
            Mar 8, 2025 00:06:22.991847038 CET49680443192.168.2.4204.79.197.222
            Mar 8, 2025 00:06:44.195106983 CET4972780192.168.2.418.234.30.239
            Mar 8, 2025 00:06:44.200635910 CET804972718.234.30.239192.168.2.4
            Mar 8, 2025 00:06:46.977158070 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:06:46.977174997 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:06:57.465334892 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:57.465369940 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:57.467535973 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:57.468542099 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:57.468556881 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:59.337781906 CET4972780192.168.2.418.234.30.239
            Mar 8, 2025 00:06:59.343203068 CET804972718.234.30.239192.168.2.4
            Mar 8, 2025 00:06:59.343297005 CET4972780192.168.2.418.234.30.239
            Mar 8, 2025 00:06:59.692863941 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:59.693234921 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:59.693255901 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:59.693736076 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:59.694523096 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:06:59.694605112 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:06:59.742382050 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:07:03.325151920 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:07:03.325290918 CET4434972818.234.30.239192.168.2.4
            Mar 8, 2025 00:07:03.325383902 CET49728443192.168.2.418.234.30.239
            Mar 8, 2025 00:07:09.277295113 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:07:09.277364016 CET44349738142.250.186.68192.168.2.4
            Mar 8, 2025 00:07:09.277415037 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:07:09.338109016 CET49738443192.168.2.4142.250.186.68
            Mar 8, 2025 00:07:09.338129044 CET44349738142.250.186.68192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Mar 8, 2025 00:05:53.098128080 CET53625481.1.1.1192.168.2.4
            Mar 8, 2025 00:05:53.120707989 CET53611471.1.1.1192.168.2.4
            Mar 8, 2025 00:05:57.033976078 CET53616441.1.1.1192.168.2.4
            Mar 8, 2025 00:05:57.057611942 CET53545291.1.1.1192.168.2.4
            Mar 8, 2025 00:05:57.399910927 CET5006953192.168.2.41.1.1.1
            Mar 8, 2025 00:05:57.399910927 CET6529553192.168.2.41.1.1.1
            Mar 8, 2025 00:05:57.407234907 CET53500691.1.1.1192.168.2.4
            Mar 8, 2025 00:05:57.407253027 CET53652951.1.1.1192.168.2.4
            Mar 8, 2025 00:05:58.864628077 CET5314153192.168.2.41.1.1.1
            Mar 8, 2025 00:05:58.864686966 CET5324253192.168.2.41.1.1.1
            Mar 8, 2025 00:05:58.878175020 CET5769953192.168.2.41.1.1.1
            Mar 8, 2025 00:05:58.878175020 CET5111853192.168.2.41.1.1.1
            Mar 8, 2025 00:05:59.176568985 CET53532421.1.1.1192.168.2.4
            Mar 8, 2025 00:05:59.178380966 CET53531411.1.1.1192.168.2.4
            Mar 8, 2025 00:05:59.209314108 CET53576991.1.1.1192.168.2.4
            Mar 8, 2025 00:05:59.291250944 CET53511181.1.1.1192.168.2.4
            Mar 8, 2025 00:06:02.045495033 CET53517301.1.1.1192.168.2.4
            Mar 8, 2025 00:06:05.112126112 CET53632991.1.1.1192.168.2.4
            Mar 8, 2025 00:06:14.080292940 CET53592861.1.1.1192.168.2.4
            Mar 8, 2025 00:06:32.892359018 CET53641441.1.1.1192.168.2.4
            Mar 8, 2025 00:06:52.849756002 CET53533031.1.1.1192.168.2.4
            Mar 8, 2025 00:06:55.360369921 CET53544051.1.1.1192.168.2.4
            Mar 8, 2025 00:06:57.872914076 CET138138192.168.2.4192.168.2.255
            Mar 8, 2025 00:06:58.438283920 CET53587621.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Mar 8, 2025 00:05:59.291337013 CET192.168.2.41.1.1.1c23d(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 8, 2025 00:05:57.399910927 CET192.168.2.41.1.1.10xdbf4Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:57.399910927 CET192.168.2.41.1.1.10x6bfcStandard query (0)www.google.com65IN (0x0001)false
            Mar 8, 2025 00:05:58.864628077 CET192.168.2.41.1.1.10x272aStandard query (0)www.texascrafted.comA (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:58.864686966 CET192.168.2.41.1.1.10xc24eStandard query (0)www.texascrafted.com65IN (0x0001)false
            Mar 8, 2025 00:05:58.878175020 CET192.168.2.41.1.1.10x57c4Standard query (0)www.texascrafted.comA (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:58.878175020 CET192.168.2.41.1.1.10x4ec4Standard query (0)www.texascrafted.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 8, 2025 00:05:57.407234907 CET1.1.1.1192.168.2.40xdbf4No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:57.407253027 CET1.1.1.1192.168.2.40x6bfcNo error (0)www.google.com65IN (0x0001)false
            Mar 8, 2025 00:05:59.176568985 CET1.1.1.1192.168.2.40xc24eNo error (0)www.texascrafted.comunavailable.hearstnp.comCNAME (Canonical name)IN (0x0001)false
            Mar 8, 2025 00:05:59.178380966 CET1.1.1.1192.168.2.40x272aNo error (0)www.texascrafted.comunavailable.hearstnp.comCNAME (Canonical name)IN (0x0001)false
            Mar 8, 2025 00:05:59.178380966 CET1.1.1.1192.168.2.40x272aNo error (0)unavailable.hearstnp.com18.234.30.239A (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:59.209314108 CET1.1.1.1192.168.2.40x57c4No error (0)www.texascrafted.comunavailable.hearstnp.comCNAME (Canonical name)IN (0x0001)false
            Mar 8, 2025 00:05:59.209314108 CET1.1.1.1192.168.2.40x57c4No error (0)unavailable.hearstnp.com18.234.30.239A (IP address)IN (0x0001)false
            Mar 8, 2025 00:05:59.291250944 CET1.1.1.1192.168.2.40x4ec4No error (0)www.texascrafted.comunavailable.hearstnp.comCNAME (Canonical name)IN (0x0001)false
            • www.google.com
            • www.texascrafted.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44972618.234.30.239804380C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 8, 2025 00:06:01.872919083 CET435OUTGET / HTTP/1.1
            Host: www.texascrafted.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Mar 8, 2025 00:06:01.980328083 CET1236INHTTP/1.1 451 Unavailable For Legal Reasons
            Date: Fri, 07 Mar 2025 23:06:01 GMT
            Server: Apache/2.4.52 (Ubuntu)
            Last-Modified: Wed, 04 Aug 2021 07:00:02 GMT
            ETag: "11a5-5c8b659f7a482"
            Accept-Ranges: bytes
            Content-Length: 4517
            Keep-Alive: timeout=5, max=100
            Connection: Keep-Alive
            Content-Type: text/html
            Data Raw: 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 0a 3c 68 65 61 64 3e 0a 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 09 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 3e 0a 09 3c 74 69 74 6c 65 3e 42 6c 6f 63 6b 65 64 20 66 6f 72 20 6c 65 67 61 6c 20 72 65 61 73 6f 6e 73 3c 2f 74 69 74 6c 65 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 53 6f 72 72 79 2c 20 74 68 69 73 20 63 6f 6e 74 65 6e 74 20 69 73 20 6e 6f 74 20 61 76 61 69 6c 61 62 6c 65 20 69 6e 20 79 6f 75 72 20 72 65 67 69 6f 6e 2e 22 3e 0a 09 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c [TRUNCATED]
            Data Ascii: <html lang="en" class="no-js"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"><title>Blocked for legal reasons</title><meta name="description" content="Sorry, this content is not available in your region."><meta name="viewport" content="width=device-width,user-scalable=no,initial-scale=1"><meta name="error" content="451"><link rel="shortcut icon"type="image/x-icon" href="data:image/x-icon;,"><style>html, body {border: 0;margin: 0;padding: 0;}body {background-color: white;min-width: 320px;}body * {font-family: Arial, "Helvetica Neue", Helvetica, sans-serif;font-size: 18px;}h1 {font-size: 32px;color: white;margin-bottom: 32px;color: black;}p {line-height: 1.38em;margin-bottom: 0.6em;}#content {width: 90%;max-width: 720px;margin: 15vh auto;}@media only screen and (max-width: 620p
            Mar 8, 2025 00:06:01.980375051 CET1236INData Raw: 78 29 20 20 7b 0a 09 09 23 63 6f 6e 74 65 6e 74 20 7b 0a 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 31 65 6d 3b 0a 09 09 7d 0a 09 09 70 20 7b 0a 09 09 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 61 75 74 6f 3b 0a 09 09 7d 0a 09 7d 0a 09 3c 2f 73 74
            Data Ascii: x) {#content {margin-top: 1em;}p {margin-top: auto;}}</style></head><body id="blocked"><section id="content"> <div class="wrap"><p style='color: #aaa'>451 Unavailable For Legal Reasons</p><h1 style='font
            Mar 8, 2025 00:06:01.980411053 CET448INData Raw: 33 38 68 6f 46 4d 68 48 44 4e 2f 46 6e 2b 33 6f 38 41 4b 2f 43 4e 35 34 59 41 4d 58 6e 42 78 41 70 50 6a 59 42 64 6b 4b 4b 6a 35 30 51 4c 30 4f 4b 6a 35 63 68 44 6b 51 55 48 77 63 69 48 49 6f 70 50 67 37 46 5c 0a 09 09 09 4f 42 6b 78 66 4a 79 4d
            Data Ascii: 38hoFMhHDN/Fn+3o8AK/CN54YAMXnBxApPjYBdkKKj50QL0OKj5chDkQUHwciHIopPg7F\OBkxfJyM8NXAcBp8C9Ix2JAQfLghwdNUKD7ekuFNKcfHm1K8Lef4cFuODyYkHx5M8NGM5IOjGT6cesPxTQSHUzRTR+P4poNDJ7\ygIPkeXFAAW9F8M69f/ZYn+HXhxtw9wA9j5eFm8nywtMDVW6L42AD4xKPN96vvl0WX
            Mar 8, 2025 00:06:01.980444908 CET1236INData Raw: 33 2b 2b 6b 33 50 4d 37 76 36 41 45 62 48 76 56 62 50 75 75 58 6c 5c 0a 09 09 09 6b 38 58 4e 6a 65 39 76 76 58 57 2f 39 55 48 75 7a 61 65 54 4a 6b 74 54 64 4d 41 41 41 41 41 53 55 56 4f 52 4b 35 43 59 49 49 3d 22 3b 0a 09 09 09 76 61 72 20 6c 69
            Data Ascii: 3++k3PM7v6AEbHvVbPuuXl\k8XNje9vvXW/9UHuzaeTJktTdMAAAAASUVORK5CYII=";var link = document.createElement('link');link.rel = 'shortcut icon';link.type = 'image/x-icon';link.href = 'data:image/png;base64,' + icon;document.
            Mar 8, 2025 00:06:01.980479956 CET675INData Raw: 65 6c 79 20 69 64 65 6e 74 69 66 79 20 61 20 76 69 73 69 74 6f 72 2e 0a 09 09 2a 2f 0a 09 09 09 76 61 72 20 74 69 64 20 3d 20 27 55 41 2d 38 34 38 36 30 30 33 34 2d 38 27 3b 0a 09 09 09 76 61 72 20 63 69 64 20 20 3d 20 27 78 78 78 78 78 78 78 78
            Data Ascii: ely identify a visitor.*/var tid = 'UA-84860034-8';var cid = 'xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx'.replace(/[xy]/g, function(c) {var r = Math.random() * 16|0;var v = c == 'x' ? r : (r&0x3|0x8);return v.toString(16);


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44972718.234.30.239804380C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 8, 2025 00:06:44.195106983 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449724142.250.186.684434380C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-07 23:06:02 UTC587OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
            Host: www.google.com
            Connection: keep-alive
            X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJKhywEInP7MAQiFoM0BCOipzgEIvtXOAQiB1s4BCMjczgEIiuDOAQiu5M4BCIvlzgE=
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: empty
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-07 23:06:03 UTC1303INHTTP/1.1 200 OK
            Date: Fri, 07 Mar 2025 23:06:02 GMT
            Pragma: no-cache
            Expires: -1
            Cache-Control: no-cache, must-revalidate
            Content-Type: text/javascript; charset=UTF-8
            Strict-Transport-Security: max-age=31536000
            Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce--iwhJpTXu0naeB9ACDwjww' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
            Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
            Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
            Accept-CH: Sec-CH-Prefers-Color-Scheme
            Accept-CH: Downlink
            Accept-CH: RTT
            Accept-CH: Sec-CH-UA-Form-Factors
            Accept-CH: Sec-CH-UA-Platform
            Accept-CH: Sec-CH-UA-Platform-Version
            Accept-CH: Sec-CH-UA-Full-Version
            Accept-CH: Sec-CH-UA-Arch
            Accept-CH: Sec-CH-UA-Model
            Accept-CH: Sec-CH-UA-Bitness
            Accept-CH: Sec-CH-UA-Full-Version-List
            Accept-CH: Sec-CH-UA-WoW64
            Permissions-Policy: unload=()
            Content-Disposition: attachment; filename="f.txt"
            Server: gws
            X-XSS-Protection: 0
            X-Frame-Options: SAMEORIGIN
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Accept-Ranges: none
            Vary: Accept-Encoding
            Connection: close
            Transfer-Encoding: chunked
            2025-03-07 23:06:03 UTC75INData Raw: 33 37 38 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 61 70 70 6c 65 20 69 70 68 6f 6e 65 20 31 37 20 70 72 6f 20 6d 61 78 22 2c 22 64 61 69 6c 79 20 68 6f 72 6f 73 63 6f 70 65 73 20 61 71 75 61 72 69 75 73 22 2c 22 6d 6c 62 20 62
            Data Ascii: 378)]}'["",["apple iphone 17 pro max","daily horoscopes aquarius","mlb b
            2025-03-07 23:06:03 UTC820INData Raw: 61 73 65 62 61 6c 6c 20 6e 65 77 73 22 2c 22 69 6e 74 65 72 73 74 61 74 65 20 31 30 20 6e 65 77 20 6d 65 78 69 63 6f 20 63 6c 6f 73 75 72 65 22 2c 22 72 65 64 20 72 6f 62 69 6e 20 72 65 73 74 61 75 72 61 6e 74 73 20 63 6c 6f 73 69 6e 67 22 2c 22 62 69 67 20 62 65 61 72 20 62 61 6c 64 20 65 61 67 6c 65 73 20 6e 65 73 74 22 2c 22 77 61 73 68 69 6e 67 74 6f 6e 20 63 6f 75 6e 74 79 20 6d 61 69 6e 65 20 6d 65 74 65 6f 72 69 74 65 20 66 61 6c 6c 22 2c 22 69 6e 76 69 6e 63 69 62 6c 65 20 73 65 61 73 6f 6e 20 33 20 65 70 69 73 6f 64 65 20 37 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c
            Data Ascii: aseball news","interstate 10 new mexico closure","red robin restaurants closing","big bear bald eagles nest","washington county maine meteorite fall","invincible season 3 episode 7"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":fal
            2025-03-07 23:06:03 UTC5INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:1
            Start time:18:05:47
            Start date:07/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:18:05:51
            Start date:07/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2036,i,4885381413271482254,15023505610315391031,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2044 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:8
            Start time:18:05:57
            Start date:07/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.texascrafted.com"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly