Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.windowsdnsservicereload.icu

Overview

General Information

Sample URL:http://www.windowsdnsservicereload.icu
Analysis ID:1638480
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

  • System is w10x64
  • chrome.exe (PID: 5388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4724 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2284,i,9971183535984344018,10597027212667236915,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2416 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6784 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.windowsdnsservicereload.icu" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.windowsdnsservicereload.icuAvira URL Cloud: detection malicious, Label: malware
Source: https://www.windowsdnsservicereload.icu/favicon.icoAvira URL Cloud: Label: malware
Source: https://www.windowsdnsservicereload.icu/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 216.58.206.68:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.windowsdnsservicereload.icuConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.windowsdnsservicereload.icuConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.windowsdnsservicereload.icu/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.windowsdnsservicereload.icu
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFi HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 400Content-Type: application/reports+jsonOrigin: https://www.windowsdnsservicereload.icuUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 14 Mar 2025 11:38:06 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeHost: www.windowsdnsservicereload.icuX-Powered-By: PHP/8.4.2cf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFi"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 92037b9d9fc66a5e-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=4250&min_rtt=1587&rtt_var=5770&sent=6&recv=8&lost=0&retrans=0&sent_bytes=3058&recv_bytes=1257&delivery_rate=2685469&cwnd=216&unsent_bytes=0&cid=d0a2b6d54e965941&ts=777&x=0"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 14 Mar 2025 11:38:08 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeHost: www.windowsdnsservicereload.icuX-Powered-By: PHP/8.4.2cf-cache-status: MISSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HdcscSZT3tmArxUdMNadau%2B558qC3%2F0%2F6k5PS%2FIZ6S9O8HS9ERTJG%2FOf%2FniJCX6faGGt1W%2FE9%2Ba%2FLsY5gZdDFpxGMx86vSV%2FgTFhWIT4%2Fy3UHivvy07RCTJfzw518PNLgCZ6PqxGHjuoSeEX9cB47BBP"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 92037ba8eab68c6d-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=3740&min_rtt=2041&rtt_var=3971&sent=6&recv=7&lost=0&retrans=0&sent_bytes=3058&recv_bytes=1201&delivery_rate=2133463&cwnd=242&unsent_bytes=0&cid=c525ad7be0a4cfcf&ts=1243&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 216.58.206.68:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.4:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49731 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir5388_1887013405Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir5388_1887013405Jump to behavior
Source: classification engineClassification label: mal56.win@22/4@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2284,i,9971183535984344018,10597027212667236915,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2416 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.windowsdnsservicereload.icu"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2284,i,9971183535984344018,10597027212667236915,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2416 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.windowsdnsservicereload.icu100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.windowsdnsservicereload.icu/favicon.ico100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    www.windowsdnsservicereload.icu
    104.21.96.1
    truefalse
      high
      www.google.com
      216.58.206.68
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://www.windowsdnsservicereload.icu/false
          unknown
          https://a.nel.cloudflare.com/report/v4?s=HdcscSZT3tmArxUdMNadau%2B558qC3%2F0%2F6k5PS%2FIZ6S9O8HS9ERTJG%2FOf%2FniJCX6faGGt1W%2FE9%2Ba%2FLsY5gZdDFpxGMx86vSV%2FgTFhWIT4%2Fy3UHivvy07RCTJfzw518PNLgCZ6PqxGHjuoSeEX9cB47BBPfalse
            high
            https://a.nel.cloudflare.com/report/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFifalse
              high
              https://www.windowsdnsservicereload.icu/favicon.icofalse
              • Avira URL Cloud: malware
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              104.21.80.1
              unknownUnited States
              13335CLOUDFLARENETUSfalse
              216.58.206.68
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.17
              192.168.2.4
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1638480
              Start date and time:2025-03-14 12:37:00 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 4s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://www.windowsdnsservicereload.icu
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:21
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal56.win@22/4@8/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.185.238, 142.250.184.238, 64.233.184.84, 172.217.18.14, 142.250.181.238, 142.250.184.206, 216.58.212.174, 172.217.18.110, 142.250.185.227, 216.58.206.46, 142.250.186.174, 142.250.186.163, 142.250.185.206, 23.60.203.209, 52.149.20.212
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenFile calls found.
              • VT rate limit hit for: http://www.windowsdnsservicereload.icu
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):544
              Entropy (8bit):5.07486771793288
              Encrypted:false
              SSDEEP:12:qTjxReR/JMF8EfUszoC1Zz1hPxFdrP1aevjRvetQwzRXLSFezHD:0jTeR/JZqvHz1L3ceLheV7S8j
              MD5:D8EFA34E9202163B90489EB1EEAD4D76
              SHA1:2AADCA84CE919DA37E845F792A328F9B920028F0
              SHA-256:28E8D6CA16281B61453FC074393A70DD88728734FD6546313F5197B9AB243B44
              SHA-512:AC4BE531043C35F6B72A1C46B65998E2B06422DC9B713B7EE94A014DF7713CD0294A67F68AA3E0178C6A413F9E39223EB8326C4ACF3FDF9D3D8346D30D181B64
              Malicious:false
              Reputation:low
              URL:https://www.windowsdnsservicereload.icu/favicon.ico
              Preview:<!doctype html><html><head><title>404 Not Found</title><style>.body { background-color: #fcfcfc; color: #333333; margin: 0; padding:0; }.h1 { font-size: 1.5em; font-weight: normal; background-color: #9999cc; min-height:2em; line-height:2em; border-bottom: 1px inset black; margin: 0; }.h1, p { padding-left: 10px; }.code.url { background-color: #eeeeee; font-family:monospace; padding:0 2px;}.</style>.</head><body><h1>Not Found</h1><p>The requested resource <code class="url">/favicon.ico</code> was not found on this server.</p></body></html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):533
              Entropy (8bit):5.0699832275535215
              Encrypted:false
              SSDEEP:12:qTjxReR/JMF8EfUszoC1Zz1hPxFdrP1aevjRvetQwzRoKD6SFezHD:0jTeR/JZqvHz1L3ceLheVOS8j
              MD5:9508CD2DD7691A107F4C17A10FD5734C
              SHA1:E02A4B55F73760649DDFB6D06863CCE9BCFBCCFF
              SHA-256:5334CAC9B835EF4763769C614488CA62D92F6019BDE6BFBCFFD485D1C5875F33
              SHA-512:DD5B5E996D7A17DC6A762D0BC08F84150FDFF600B87316E3F1B2AE3848158D9F6C408F9BF9F11C7DF5EA34A073A6A73BA6207904EEA00DB129F68A9D63AD378B
              Malicious:false
              Reputation:low
              URL:https://www.windowsdnsservicereload.icu/
              Preview:<!doctype html><html><head><title>404 Not Found</title><style>.body { background-color: #fcfcfc; color: #333333; margin: 0; padding:0; }.h1 { font-size: 1.5em; font-weight: normal; background-color: #9999cc; min-height:2em; line-height:2em; border-bottom: 1px inset black; margin: 0; }.h1, p { padding-left: 10px; }.code.url { background-color: #eeeeee; font-family:monospace; padding:0 2px;}.</style>.</head><body><h1>Not Found</h1><p>The requested resource <code class="url">/</code> was not found on this server.</p></body></html>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Mar 14, 2025 12:37:53.093837023 CET4968180192.168.2.42.17.190.73
              Mar 14, 2025 12:37:54.031291962 CET49680443192.168.2.4204.79.197.222
              Mar 14, 2025 12:37:58.521879911 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:37:58.906327963 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:37:59.609420061 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:38:00.893081903 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:38:02.702934027 CET4968180192.168.2.42.17.190.73
              Mar 14, 2025 12:38:03.296953917 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:38:03.640718937 CET49680443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:04.571518898 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:04.571562052 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:04.571635962 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:04.571892023 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:04.571907043 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:05.228914022 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:05.229131937 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:05.230412960 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:05.230424881 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:05.230722904 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:05.281069994 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:05.711195946 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:05.711230993 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:05.715009928 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:05.716600895 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:05.716622114 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.270210981 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.270494938 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:06.280447006 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:06.280467987 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.280693054 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.284852982 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:06.332328081 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.700392962 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:06.942430973 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.942562103 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:06.942624092 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:06.963354111 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:06.963391066 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:06.963447094 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:06.963805914 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:06.963815928 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:06.975542068 CET49729443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:06.975580931 CET44349729104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:07.002166033 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:07.068896055 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:07.068957090 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:07.069097042 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:07.069305897 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:07.069324017 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:07.440597057 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.440679073 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.442053080 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.442063093 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.442281961 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.442847967 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.488325119 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.569752932 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.569843054 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.569969893 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.570256948 CET49731443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.570277929 CET4434973135.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.571300030 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.571352959 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.571448088 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.571602106 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:07.571619987 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:07.602333069 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:07.902668953 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:07.902966022 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:07.903000116 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:07.903178930 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:07.903184891 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:08.100590944 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.100940943 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:08.100964069 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.101236105 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:08.101242065 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.108644962 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:38:08.231178045 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.231261015 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.231317997 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:08.232119083 CET49733443192.168.2.435.190.80.1
              Mar 14, 2025 12:38:08.232141972 CET4434973335.190.80.1192.168.2.4
              Mar 14, 2025 12:38:08.792104006 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:08.792234898 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:08.792320013 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:08.794928074 CET49732443192.168.2.4104.21.80.1
              Mar 14, 2025 12:38:08.794946909 CET44349732104.21.80.1192.168.2.4
              Mar 14, 2025 12:38:08.811788082 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:10.858217955 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:10.858217955 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:10.858489037 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:10.862988949 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:10.863109112 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:10.863121033 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:10.954425097 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:10.954562902 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:10.955301046 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:10.959942102 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:11.048650026 CET44349713204.79.197.222192.168.2.4
              Mar 14, 2025 12:38:11.048839092 CET49713443192.168.2.4204.79.197.222
              Mar 14, 2025 12:38:11.218640089 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:15.133805990 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:15.133861065 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:15.133976936 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:16.023940086 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:16.487071991 CET49727443192.168.2.4216.58.206.68
              Mar 14, 2025 12:38:16.487121105 CET44349727216.58.206.68192.168.2.4
              Mar 14, 2025 12:38:17.714029074 CET49671443192.168.2.4204.79.197.203
              Mar 14, 2025 12:38:25.635149956 CET49678443192.168.2.420.189.173.27
              Mar 14, 2025 12:38:46.359539032 CET4971480192.168.2.4142.250.181.227
              Mar 14, 2025 12:38:46.359637022 CET4971280192.168.2.4199.232.210.172
              Mar 14, 2025 12:38:46.359683990 CET4971580192.168.2.4199.232.210.172
              Mar 14, 2025 12:38:46.364607096 CET8049714142.250.181.227192.168.2.4
              Mar 14, 2025 12:38:46.364696026 CET4971480192.168.2.4142.250.181.227
              Mar 14, 2025 12:38:46.364847898 CET8049712199.232.210.172192.168.2.4
              Mar 14, 2025 12:38:46.364859104 CET8049715199.232.210.172192.168.2.4
              Mar 14, 2025 12:38:46.364905119 CET4971280192.168.2.4199.232.210.172
              Mar 14, 2025 12:38:46.364921093 CET4971580192.168.2.4199.232.210.172
              Mar 14, 2025 12:39:04.625989914 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:04.626043081 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:04.626151085 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:04.626426935 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:04.626444101 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:05.274529934 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:05.275003910 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:05.275044918 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:06.955311060 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:06.955368996 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:06.955437899 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:06.955622911 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:06.955640078 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.410003901 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.410543919 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.410576105 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.410593987 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.410598993 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.539211035 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.539309978 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.539366961 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.539632082 CET49741443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.539653063 CET4434974135.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.540421009 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.540472031 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:07.540549040 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.540664911 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:07.540678024 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.000971079 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.001446009 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:08.001475096 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.001631975 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:08.001637936 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.129991055 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.130062103 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:08.130140066 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:08.130341053 CET49742443192.168.2.435.190.80.1
              Mar 14, 2025 12:39:08.130358934 CET4434974235.190.80.1192.168.2.4
              Mar 14, 2025 12:39:15.175410032 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:15.175447941 CET44349739216.58.206.68192.168.2.4
              Mar 14, 2025 12:39:15.175497055 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:16.486866951 CET49739443192.168.2.4216.58.206.68
              Mar 14, 2025 12:39:16.486908913 CET44349739216.58.206.68192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Mar 14, 2025 12:38:00.506015062 CET53503851.1.1.1192.168.2.4
              Mar 14, 2025 12:38:00.533229113 CET53612831.1.1.1192.168.2.4
              Mar 14, 2025 12:38:02.631207943 CET53564581.1.1.1192.168.2.4
              Mar 14, 2025 12:38:04.563564062 CET5342153192.168.2.41.1.1.1
              Mar 14, 2025 12:38:04.563766003 CET5309853192.168.2.41.1.1.1
              Mar 14, 2025 12:38:04.570355892 CET53530981.1.1.1192.168.2.4
              Mar 14, 2025 12:38:04.570373058 CET53534211.1.1.1192.168.2.4
              Mar 14, 2025 12:38:05.664110899 CET6542053192.168.2.41.1.1.1
              Mar 14, 2025 12:38:05.664110899 CET5943253192.168.2.41.1.1.1
              Mar 14, 2025 12:38:05.676671028 CET53654201.1.1.1192.168.2.4
              Mar 14, 2025 12:38:05.677598953 CET53594321.1.1.1192.168.2.4
              Mar 14, 2025 12:38:05.686088085 CET4919353192.168.2.41.1.1.1
              Mar 14, 2025 12:38:05.686642885 CET5032853192.168.2.41.1.1.1
              Mar 14, 2025 12:38:05.698656082 CET53491931.1.1.1192.168.2.4
              Mar 14, 2025 12:38:05.699434042 CET53503281.1.1.1192.168.2.4
              Mar 14, 2025 12:38:06.945035934 CET5221953192.168.2.41.1.1.1
              Mar 14, 2025 12:38:06.945322037 CET5018953192.168.2.41.1.1.1
              Mar 14, 2025 12:38:06.951508045 CET53522191.1.1.1192.168.2.4
              Mar 14, 2025 12:38:06.952027082 CET53501891.1.1.1192.168.2.4
              Mar 14, 2025 12:38:19.591943979 CET53558121.1.1.1192.168.2.4
              Mar 14, 2025 12:38:38.478970051 CET53607371.1.1.1192.168.2.4
              Mar 14, 2025 12:38:59.903305054 CET53637701.1.1.1192.168.2.4
              Mar 14, 2025 12:39:01.041687965 CET53652621.1.1.1192.168.2.4
              Mar 14, 2025 12:39:02.649239063 CET53577241.1.1.1192.168.2.4
              Mar 14, 2025 12:39:06.100424051 CET138138192.168.2.4192.168.2.255
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 14, 2025 12:38:04.563564062 CET192.168.2.41.1.1.10xe2b2Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:04.563766003 CET192.168.2.41.1.1.10xd17fStandard query (0)www.google.com65IN (0x0001)false
              Mar 14, 2025 12:38:05.664110899 CET192.168.2.41.1.1.10x97b0Standard query (0)www.windowsdnsservicereload.icuA (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.664110899 CET192.168.2.41.1.1.10xc251Standard query (0)www.windowsdnsservicereload.icu65IN (0x0001)false
              Mar 14, 2025 12:38:05.686088085 CET192.168.2.41.1.1.10x9ba7Standard query (0)www.windowsdnsservicereload.icuA (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.686642885 CET192.168.2.41.1.1.10x1463Standard query (0)www.windowsdnsservicereload.icu65IN (0x0001)false
              Mar 14, 2025 12:38:06.945035934 CET192.168.2.41.1.1.10x271cStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:06.945322037 CET192.168.2.41.1.1.10xa166Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 14, 2025 12:38:04.570355892 CET1.1.1.1192.168.2.40xd17fNo error (0)www.google.com65IN (0x0001)false
              Mar 14, 2025 12:38:04.570373058 CET1.1.1.1192.168.2.40xe2b2No error (0)www.google.com216.58.206.68A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.96.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.64.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.112.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.16.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.80.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.32.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.676671028 CET1.1.1.1192.168.2.40x97b0No error (0)www.windowsdnsservicereload.icu104.21.48.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.677598953 CET1.1.1.1192.168.2.40xc251No error (0)www.windowsdnsservicereload.icu65IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.80.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.96.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.112.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.64.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.32.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.16.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.698656082 CET1.1.1.1192.168.2.40x9ba7No error (0)www.windowsdnsservicereload.icu104.21.48.1A (IP address)IN (0x0001)false
              Mar 14, 2025 12:38:05.699434042 CET1.1.1.1192.168.2.40x1463No error (0)www.windowsdnsservicereload.icu65IN (0x0001)false
              Mar 14, 2025 12:38:06.951508045 CET1.1.1.1192.168.2.40x271cNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              • www.windowsdnsservicereload.icu
              • a.nel.cloudflare.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449729104.21.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:38:06 UTC681OUTGET / HTTP/1.1
              Host: www.windowsdnsservicereload.icu
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:38:06 UTC884INHTTP/1.1 404 Not Found
              Date: Fri, 14 Mar 2025 11:38:06 GMT
              Content-Type: text/html; charset=UTF-8
              Transfer-Encoding: chunked
              Connection: close
              Host: www.windowsdnsservicereload.icu
              X-Powered-By: PHP/8.4.2
              cf-cache-status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFi"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 92037b9d9fc66a5e-EWR
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=4250&min_rtt=1587&rtt_var=5770&sent=6&recv=8&lost=0&retrans=0&sent_bytes=3058&recv_bytes=1257&delivery_rate=2685469&cwnd=216&unsent_bytes=0&cid=d0a2b6d54e965941&ts=777&x=0"
              2025-03-14 11:38:06 UTC540INData Raw: 32 31 35 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 0a 62 6f 64 79 20 7b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 63 66 63 66 63 3b 20 63 6f 6c 6f 72 3a 20 23 33 33 33 33 33 33 3b 20 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 30 3b 20 7d 0a 68 31 20 7b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 2e 35 65 6d 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 6e 6f 72 6d 61 6c 3b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 39 39 39 39 63 63 3b 20 6d 69 6e 2d 68 65 69 67 68 74 3a 32 65 6d 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 32 65 6d 3b 20 62 6f 72 64 65 72 2d 62 6f
              Data Ascii: 215<!doctype html><html><head><title>404 Not Found</title><style>body { background-color: #fcfcfc; color: #333333; margin: 0; padding:0; }h1 { font-size: 1.5em; font-weight: normal; background-color: #9999cc; min-height:2em; line-height:2em; border-bo
              2025-03-14 11:38:06 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973135.190.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:38:07 UTC582OUTOPTIONS /report/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFi HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://www.windowsdnsservicereload.icu
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:38:07 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: POST, OPTIONS
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Fri, 14 Mar 2025 11:38:07 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449732104.21.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:38:07 UTC625OUTGET /favicon.ico HTTP/1.1
              Host: www.windowsdnsservicereload.icu
              Connection: keep-alive
              sec-ch-ua-platform: "Windows"
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://www.windowsdnsservicereload.icu/
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:38:08 UTC892INHTTP/1.1 404 Not Found
              Date: Fri, 14 Mar 2025 11:38:08 GMT
              Content-Type: text/html; charset=UTF-8
              Transfer-Encoding: chunked
              Connection: close
              Host: www.windowsdnsservicereload.icu
              X-Powered-By: PHP/8.4.2
              cf-cache-status: MISS
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HdcscSZT3tmArxUdMNadau%2B558qC3%2F0%2F6k5PS%2FIZ6S9O8HS9ERTJG%2FOf%2FniJCX6faGGt1W%2FE9%2Ba%2FLsY5gZdDFpxGMx86vSV%2FgTFhWIT4%2Fy3UHivvy07RCTJfzw518PNLgCZ6PqxGHjuoSeEX9cB47BBP"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 92037ba8eab68c6d-EWR
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=3740&min_rtt=2041&rtt_var=3971&sent=6&recv=7&lost=0&retrans=0&sent_bytes=3058&recv_bytes=1201&delivery_rate=2133463&cwnd=242&unsent_bytes=0&cid=c525ad7be0a4cfcf&ts=1243&x=0"
              2025-03-14 11:38:08 UTC477INData Raw: 32 32 30 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 0a 62 6f 64 79 20 7b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 63 66 63 66 63 3b 20 63 6f 6c 6f 72 3a 20 23 33 33 33 33 33 33 3b 20 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 30 3b 20 7d 0a 68 31 20 7b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 2e 35 65 6d 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 6e 6f 72 6d 61 6c 3b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 39 39 39 39 63 63 3b 20 6d 69 6e 2d 68 65 69 67 68 74 3a 32 65 6d 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 32 65 6d 3b 20 62 6f 72 64 65 72 2d 62 6f
              Data Ascii: 220<!doctype html><html><head><title>404 Not Found</title><style>body { background-color: #fcfcfc; color: #333333; margin: 0; padding:0; }h1 { font-size: 1.5em; font-weight: normal; background-color: #9999cc; min-height:2em; line-height:2em; border-bo
              2025-03-14 11:38:08 UTC74INData Raw: 75 72 6c 22 3e 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 3c 2f 63 6f 64 65 3e 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: url">/favicon.ico</code> was not found on this server.</p></body></html>
              2025-03-14 11:38:08 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44973335.190.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:38:08 UTC557OUTPOST /report/v4?s=0bwEOfJaX%2FG5DDLmuHBSQRsATSFOsDVwJSar%2B%2BW%2Bj7DXETPFPMABubYI9cULhkd%2BgqHD4cDuHBxFhjYSrzgse1ZojVSOaB69tRKXhxRJk2tUI6yRPMzHZRKu%2BnNkvckLKiWUnQNeFKKuxObqvLGEtJFi HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 400
              Content-Type: application/reports+json
              Origin: https://www.windowsdnsservicereload.icu
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:38:08 UTC400OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 32 35 38 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 38 30 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 77 69 6e 64 6f 77 73 64 6e 73 73 65 72
              Data Ascii: [{"age":0,"body":{"elapsed_time":1258,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.80.1","status_code":404,"type":"http.error"},"type":"network-error","url":"https://www.windowsdnsser
              2025-03-14 11:38:08 UTC214INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-allow-origin: *
              vary: Origin
              date: Fri, 14 Mar 2025 11:38:07 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.44974135.190.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:39:07 UTC592OUTOPTIONS /report/v4?s=HdcscSZT3tmArxUdMNadau%2B558qC3%2F0%2F6k5PS%2FIZ6S9O8HS9ERTJG%2FOf%2FniJCX6faGGt1W%2FE9%2Ba%2FLsY5gZdDFpxGMx86vSV%2FgTFhWIT4%2Fy3UHivvy07RCTJfzw518PNLgCZ6PqxGHjuoSeEX9cB47BBP HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://www.windowsdnsservicereload.icu
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:39:07 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: OPTIONS, POST
              access-control-allow-origin: *
              access-control-allow-headers: content-type, content-length
              date: Fri, 14 Mar 2025 11:39:06 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.44974235.190.80.14434724C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-03-14 11:39:07 UTC567OUTPOST /report/v4?s=HdcscSZT3tmArxUdMNadau%2B558qC3%2F0%2F6k5PS%2FIZ6S9O8HS9ERTJG%2FOf%2FniJCX6faGGt1W%2FE9%2Ba%2FLsY5gZdDFpxGMx86vSV%2FgTFhWIT4%2Fy3UHivvy07RCTJfzw518PNLgCZ6PqxGHjuoSeEX9cB47BBP HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 455
              Content-Type: application/reports+json
              Origin: https://www.windowsdnsservicereload.icu
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-03-14 11:39:07 UTC455OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 38 31 36 31 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 37 32 34 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 77 69 6e 64 6f 77 73 64 6e 73 73 65 72 76 69 63 65 72 65 6c 6f 61 64 2e 69 63 75 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 38 30 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74
              Data Ascii: [{"age":58161,"body":{"elapsed_time":1724,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://www.windowsdnsservicereload.icu/","sampling_fraction":1.0,"server_ip":"104.21.80.1","status_code":404,"type":"http.error"},"type":"net
              2025-03-14 11:39:08 UTC214INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-allow-origin: *
              vary: Origin
              date: Fri, 14 Mar 2025 11:39:08 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:1
              Start time:07:37:55
              Start date:14/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:07:37:58
              Start date:14/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2284,i,9971183535984344018,10597027212667236915,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2416 /prefetch:3
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:4
              Start time:07:38:04
              Start date:14/03/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.windowsdnsservicereload.icu"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly