Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N

Overview

General Information

Sample URL:https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
Analysis ID:1638529
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

  • System is w10x64
  • chrome.exe (PID: 5716 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2412 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,15356335459786314934,5695136569734279863,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2032 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7048 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://office.a8a.shop/xHIqAnQIAvira URL Cloud: Label: phishing
Source: https://office.a8a.shop/xHIqAnQI#citytitle@citytitleagency.comHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.186.36:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.210.98.14:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.210.98.14:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.136.69:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.136.69:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.23.99
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.23.99
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.96.81
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N HTTP/1.1Host: intimidadcondiosgt.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: intimidadcondiosgt.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20NAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /xHIqAnQI HTTP/1.1Host: office.a8a.shopConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://intimidadcondiosgt.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJWhywEInP7MAQiFoM0BCL7VzgEIgNbOAQjI3M4BCIrgzgEIruTOAQiL5c4BSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: office.a8a.shopConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://office.a8a.shop/xHIqAnQIAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: intimidadcondiosgt.com
Source: global trafficDNS traffic detected: DNS query: office.a8a.shop
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=PZPfdnm%2Bp4dG8ctHkpf1YqCz9%2BUOugEIFn7yx1calyNJfUpcDfVuEoDYK6J9Mwazjk4ohBaDaFO4GPCoBpifhHRCRaweE955oWOifuchIOR6OwSyebDX65Lzj5s%2B2FPqX7M%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 426Content-Type: application/reports+jsonOrigin: https://office.a8a.shopUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 1251date: Fri, 14 Mar 2025 12:47:14 GMTserver: LiteSpeedalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 142.250.186.36:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.210.98.14:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.210.98.14:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.136.69:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.136.69:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir5716_1734302738Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir5716_1734302738Jump to behavior
Source: classification engineClassification label: mal48.win@22/2@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,15356335459786314934,5695136569734279863,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2032 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,15356335459786314934,5695136569734279863,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2032 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://office.a8a.shop/xHIqAnQI100%Avira URL Cloudphishing
https://office.a8a.shop/favicon.ico0%Avira URL Cloudsafe
https://intimidadcondiosgt.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
office.a8a.shop
172.67.136.69
truefalse
    unknown
    intimidadcondiosgt.com
    162.210.98.14
    truefalse
      unknown
      a.nel.cloudflare.com
      35.190.80.1
      truefalse
        high
        www.google.com
        142.250.186.36
        truefalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://office.a8a.shop/xHIqAnQI#citytitle@citytitleagency.comfalse
            unknown
            https://a.nel.cloudflare.com/report/v4?s=PZPfdnm%2Bp4dG8ctHkpf1YqCz9%2BUOugEIFn7yx1calyNJfUpcDfVuEoDYK6J9Mwazjk4ohBaDaFO4GPCoBpifhHRCRaweE955oWOifuchIOR6OwSyebDX65Lzj5s%2B2FPqX7M%3Dfalse
              high
              https://intimidadcondiosgt.com/favicon.icofalse
              • Avira URL Cloud: safe
              unknown
              https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20Nfalse
                unknown
                https://office.a8a.shop/xHIqAnQIfalse
                • Avira URL Cloud: phishing
                unknown
                https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
                  high
                  https://office.a8a.shop/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.186.36
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  172.67.136.69
                  office.a8a.shopUnited States
                  13335CLOUDFLARENETUSfalse
                  35.190.80.1
                  a.nel.cloudflare.comUnited States
                  15169GOOGLEUSfalse
                  162.210.98.14
                  intimidadcondiosgt.comUnited States
                  32748STEADFASTUSfalse
                  IP
                  192.168.2.4
                  192.168.2.23
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1638529
                  Start date and time:2025-03-14 13:46:10 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 0s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:20
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@22/2@8/6
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.184.206, 142.250.186.131, 64.233.184.84, 142.250.186.35, 216.58.206.46, 142.250.186.78, 142.250.184.238, 172.217.16.206, 184.30.131.245, 142.250.185.174, 142.250.185.238, 142.250.186.174, 142.250.185.195, 142.250.185.78, 142.250.185.227, 216.58.206.78, 23.60.203.209, 20.12.23.50
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • VT rate limit hit for: https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (879)
                  Category:downloaded
                  Size (bytes):884
                  Entropy (8bit):5.175091821968257
                  Encrypted:false
                  SSDEEP:24:t/ImaejK2SBHslgT1d1uawBATT3uoBN2t2t2t2t2t2t2tomffffffo:CoyKlgJXwBAP3uSNYYYYYYYomffffffo
                  MD5:A44BC707A290913978B8CA2411F858F2
                  SHA1:D4C9C6B181281F129FD6640651FFC093EA44AF8F
                  SHA-256:F843E57C52DCBEEBAEA805142B30AC5FB1572482BE7949A0BBCAAB218F880BCE
                  SHA-512:EFAFA39B4F5B9B27A366006567A6352BCA940386B9A05942C90EAB383082501AFEC32B82EEF3C711EF133E2F5E8D519D06404545EC8C6CF1AD3FA8F5762F1127
                  Malicious:false
                  Reputation:low
                  URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
                  Preview:)]}'.["",["niantic sells pokemon go","wordle today march 14","td bank closing branches","sudiksha konanki missing punta cana","severe weather storm","what time can i play mlb the show 25","landman renewed","blood moon total lunar eclipse tonight"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002}],"google:suggesteventid":"-8180498827131315052","google:suggestrelevance":[1257,1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY"]}]
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 14, 2025 13:47:08.163425922 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:08.471491098 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:09.174604893 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:10.377485037 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:11.636569977 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:11.636616945 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:11.636714935 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:11.636893988 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:11.636912107 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:12.304099083 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:12.304600954 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:12.305541992 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:12.305556059 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:12.305820942 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:12.346270084 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:12.783776999 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:13.825817108 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.825843096 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:13.826004982 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.826072931 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.826078892 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:13.826448917 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.826503992 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:13.826558113 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.826710939 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:13.826728106 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.353490114 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.353494883 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.353579998 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.354722023 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.354722023 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.354737043 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.354957104 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.355086088 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.355098963 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.355299950 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.355323076 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.398921967 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.400319099 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.574599981 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.574671030 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.574723959 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.575247049 CET49734443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.575258017 CET44349734162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.683368921 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.690920115 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.690967083 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:14.691023111 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.691406965 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.691437006 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:14.691499949 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.692296028 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.692313910 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:14.692322016 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:14.692334890 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:14.728318930 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.801382065 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.802467108 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:14.802515984 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.803431988 CET49735443192.168.2.4162.210.98.14
                  Mar 14, 2025 13:47:14.803453922 CET44349735162.210.98.14192.168.2.4
                  Mar 14, 2025 13:47:15.194720030 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.194820881 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.194912910 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:15.194912910 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:15.205874920 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:15.205892086 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.206126928 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.206760883 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:15.206787109 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.206907034 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:15.207024097 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.252332926 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:15.260355949 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:16.941525936 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:17.251279116 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:17.436934948 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:17.484323025 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:17.587023973 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:17.639477015 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:17.642222881 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:17.642291069 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:17.654577971 CET49732443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:47:17.654593945 CET44349732142.250.186.36192.168.2.4
                  Mar 14, 2025 13:47:17.858292103 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:18.182629108 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:18.490923882 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:18.881694078 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:18.882447958 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:18.882477999 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:18.886358976 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:18.887145996 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:18.887156010 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:18.976655006 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:18.976711988 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:18.977319002 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:18.981950045 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:19.068763018 CET4434970952.113.196.254192.168.2.4
                  Mar 14, 2025 13:47:19.068820953 CET49709443192.168.2.452.113.196.254
                  Mar 14, 2025 13:47:19.072191000 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:19.102777958 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:20.315624952 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:21.473743916 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:22.723824024 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:26.279476881 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:27.194056988 CET49671443192.168.2.4204.79.197.203
                  Mar 14, 2025 13:47:27.532887936 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:30.055438995 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:30.055520058 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:30.055588961 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:30.145082951 CET49737443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:30.145109892 CET44349737172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:35.883757114 CET49678443192.168.2.420.189.173.27
                  Mar 14, 2025 13:47:37.134535074 CET4968180192.168.2.42.17.190.73
                  Mar 14, 2025 13:47:54.033153057 CET4971580192.168.2.4172.217.23.99
                  Mar 14, 2025 13:47:54.033241987 CET4971780192.168.2.4199.232.214.172
                  Mar 14, 2025 13:47:54.033303022 CET4971980192.168.2.4199.232.214.172
                  Mar 14, 2025 13:47:54.039325953 CET8049715172.217.23.99192.168.2.4
                  Mar 14, 2025 13:47:54.039402962 CET4971580192.168.2.4172.217.23.99
                  Mar 14, 2025 13:47:54.039927959 CET8049717199.232.214.172192.168.2.4
                  Mar 14, 2025 13:47:54.039974928 CET8049719199.232.214.172192.168.2.4
                  Mar 14, 2025 13:47:54.039978027 CET4971780192.168.2.4199.232.214.172
                  Mar 14, 2025 13:47:54.040024996 CET4971980192.168.2.4199.232.214.172
                  Mar 14, 2025 13:47:54.515621901 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:54.515698910 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:54.515767097 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:54.517616987 CET49736443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:54.517637968 CET44349736172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:54.526556015 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:54.526593924 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:54.526660919 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:54.541285038 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:54.541305065 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:54.580425024 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:54.580471992 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:54.580610991 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:54.580946922 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:54.580964088 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:54.759614944 CET49716443192.168.2.42.19.96.81
                  Mar 14, 2025 13:47:54.759919882 CET4971880192.168.2.4199.232.214.172
                  Mar 14, 2025 13:47:55.035985947 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.036082983 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.041121960 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.041129112 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.041379929 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.042391062 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.084146023 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:55.084330082 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.108041048 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:55.108062983 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:55.145302057 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:47:55.145315886 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:47:55.164850950 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.164922953 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.164984941 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.195207119 CET49743443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.195218086 CET4434974335.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.196012974 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.196059942 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.196125031 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.196254015 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.196264982 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.757443905 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.757767916 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.757787943 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.758009911 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.758018017 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.890511990 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.890666962 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.890707016 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.890832901 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.890845060 CET4434974535.190.80.1192.168.2.4
                  Mar 14, 2025 13:47:55.890856028 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:47:55.890897036 CET49745443192.168.2.435.190.80.1
                  Mar 14, 2025 13:48:11.691780090 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:11.691838026 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:11.691952944 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:11.692138910 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:11.692154884 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:12.353619099 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:12.353996992 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:12.354018927 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:14.582652092 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:48:14.582720041 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:48:14.582911015 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:48:14.583421946 CET49744443192.168.2.4172.67.136.69
                  Mar 14, 2025 13:48:14.583441019 CET44349744172.67.136.69192.168.2.4
                  Mar 14, 2025 13:48:22.255953074 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:22.256019115 CET44349750142.250.186.36192.168.2.4
                  Mar 14, 2025 13:48:22.256078959 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:24.144486904 CET49750443192.168.2.4142.250.186.36
                  Mar 14, 2025 13:48:24.144524097 CET44349750142.250.186.36192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 14, 2025 13:47:08.099586964 CET53527121.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:08.795367956 CET53603981.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:09.835558891 CET53589231.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:09.943046093 CET53587871.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:11.628418922 CET5940353192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:11.628659010 CET6151353192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:11.635360003 CET53594031.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:11.635854959 CET53615131.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:13.702570915 CET6086553192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:13.702609062 CET6437653192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:13.747795105 CET53643761.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:13.825083017 CET53608651.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:14.673263073 CET5868153192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:14.673629999 CET4932453192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:14.686547041 CET53493241.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:14.689357996 CET53586811.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:26.927177906 CET53554181.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:44.682929993 CET53517201.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:45.731013060 CET53494191.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:54.517330885 CET4979153192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:54.517510891 CET5156253192.168.2.41.1.1.1
                  Mar 14, 2025 13:47:54.524367094 CET53497911.1.1.1192.168.2.4
                  Mar 14, 2025 13:47:54.524420977 CET53515621.1.1.1192.168.2.4
                  Mar 14, 2025 13:48:07.558911085 CET53616181.1.1.1192.168.2.4
                  Mar 14, 2025 13:48:08.163665056 CET53588001.1.1.1192.168.2.4
                  Mar 14, 2025 13:48:10.214771986 CET53619821.1.1.1192.168.2.4
                  Mar 14, 2025 13:48:16.414477110 CET138138192.168.2.4192.168.2.255
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Mar 14, 2025 13:47:11.628418922 CET192.168.2.41.1.1.10xd31bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:11.628659010 CET192.168.2.41.1.1.10x5af6Standard query (0)www.google.com65IN (0x0001)false
                  Mar 14, 2025 13:47:13.702570915 CET192.168.2.41.1.1.10xbaeStandard query (0)intimidadcondiosgt.comA (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:13.702609062 CET192.168.2.41.1.1.10x5a66Standard query (0)intimidadcondiosgt.com65IN (0x0001)false
                  Mar 14, 2025 13:47:14.673263073 CET192.168.2.41.1.1.10x4850Standard query (0)office.a8a.shopA (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:14.673629999 CET192.168.2.41.1.1.10x50d9Standard query (0)office.a8a.shop65IN (0x0001)false
                  Mar 14, 2025 13:47:54.517330885 CET192.168.2.41.1.1.10xbaf9Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:54.517510891 CET192.168.2.41.1.1.10x1451Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Mar 14, 2025 13:47:11.635360003 CET1.1.1.1192.168.2.40xd31bNo error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:11.635854959 CET1.1.1.1192.168.2.40x5af6No error (0)www.google.com65IN (0x0001)false
                  Mar 14, 2025 13:47:13.825083017 CET1.1.1.1192.168.2.40xbaeNo error (0)intimidadcondiosgt.com162.210.98.14A (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:14.686547041 CET1.1.1.1192.168.2.40x50d9No error (0)office.a8a.shop65IN (0x0001)false
                  Mar 14, 2025 13:47:14.689357996 CET1.1.1.1192.168.2.40x4850No error (0)office.a8a.shop172.67.136.69A (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:14.689357996 CET1.1.1.1192.168.2.40x4850No error (0)office.a8a.shop104.21.26.128A (IP address)IN (0x0001)false
                  Mar 14, 2025 13:47:54.524367094 CET1.1.1.1192.168.2.40xbaf9No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                  • intimidadcondiosgt.com
                    • office.a8a.shop
                  • www.google.com
                  • a.nel.cloudflare.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.449734162.210.98.144432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:14 UTC732OUTGET /fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N HTTP/1.1
                  Host: intimidadcondiosgt.com
                  Connection: keep-alive
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:14 UTC410INHTTP/1.1 200 OK
                  Connection: close
                  refresh: 0;url=https://office.a8a.shop/xHIqAnQI#citytitle@citytitleagency.com
                  content-type: text/html; charset=UTF-8
                  content-length: 0
                  date: Fri, 14 Mar 2025 12:47:14 GMT
                  server: LiteSpeed
                  alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.449735162.210.98.144432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:14 UTC667OUTGET /favicon.ico HTTP/1.1
                  Host: intimidadcondiosgt.com
                  Connection: keep-alive
                  sec-ch-ua-platform: "Windows"
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:14 UTC416INHTTP/1.1 404 Not Found
                  Connection: close
                  cache-control: private, no-cache, no-store, must-revalidate, max-age=0
                  pragma: no-cache
                  content-type: text/html
                  content-length: 1251
                  date: Fri, 14 Mar 2025 12:47:14 GMT
                  server: LiteSpeed
                  alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
                  2025-03-14 12:47:14 UTC952INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79
                  Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</sty
                  2025-03-14 12:47:14 UTC299INData Raw: 2d 74 6f 70 3a 20 31 70 78 20 73 6f 6c 69 64 20 72 67 62 61 28 30 2c 30 2c 30 2c 30 2e 31 35 29 3b 62 6f 78 2d 73 68 61 64 6f 77 3a 20 30 20 31 70 78 20 30 20 72 67 62 61 28 32 35 35 2c 20 32 35 35 2c 20 32 35 35 2c 20 30 2e 33 29 20 69 6e 73 65 74 3b 22 3e 0a 3c 62 72 3e 50 72 6f 75 64 6c 79 20 70 6f 77 65 72 65 64 20 62 79 20 4c 69 74 65 53 70 65 65 64 20 57 65 62 20 53 65 72 76 65 72 3c 70 3e 50 6c 65 61 73 65 20 62 65 20 61 64 76 69 73 65 64 20 74 68 61 74 20 4c 69 74 65 53 70 65 65 64 20 54 65 63 68 6e 6f 6c 6f 67 69 65 73 20 49 6e 63 2e 20 69 73 20 6e 6f 74 20 61 20 77 65 62 20 68 6f 73 74 69 6e 67 20 63 6f 6d 70 61 6e 79 20 61 6e 64 2c 20 61 73 20 73 75 63 68 2c 20 68 61 73 20 6e 6f 20 63 6f 6e 74 72 6f 6c 20 6f 76 65 72 20 63 6f 6e 74 65 6e 74 20
                  Data Ascii: -top: 1px solid rgba(0,0,0,0.15);box-shadow: 0 1px 0 rgba(255, 255, 255, 0.3) inset;"><br>Proudly powered by LiteSpeed Web Server<p>Please be advised that LiteSpeed Technologies Inc. is not a web hosting company and, as such, has no control over content


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449736172.67.136.694432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:15 UTC701OUTGET /xHIqAnQI HTTP/1.1
                  Host: office.a8a.shop
                  Connection: keep-alive
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: cross-site
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-Dest: document
                  Referer: https://intimidadcondiosgt.com/
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:54 UTC952INHTTP/1.1 522
                  Date: Fri, 14 Mar 2025 12:47:54 GMT
                  Content-Type: text/plain; charset=UTF-8
                  Content-Length: 15
                  Connection: close
                  Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=PZPfdnm%2Bp4dG8ctHkpf1YqCz9%2BUOugEIFn7yx1calyNJfUpcDfVuEoDYK6J9Mwazjk4ohBaDaFO4GPCoBpifhHRCRaweE955oWOifuchIOR6OwSyebDX65Lzj5s%2B2FPqX7M%3D"}],"group":"cf-nel","max_age":604800}
                  NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                  X-Frame-Options: SAMEORIGIN
                  Referrer-Policy: same-origin
                  Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                  Expires: Thu, 01 Jan 1970 00:00:01 GMT
                  Server: cloudflare
                  CF-RAY: 9203e0e88d0a42f5-EWR
                  alt-svc: h3=":443"; ma=86400
                  server-timing: cfL4;desc="?proto=TCP&rtt=1918&min_rtt=1918&rtt_var=959&sent=6&recv=7&lost=0&retrans=1&sent_bytes=4170&recv_bytes=1273&delivery_rate=400054&cwnd=177&unsent_bytes=0&cid=690f29e4b3d39541&ts=39352&x=0"
                  2025-03-14 12:47:54 UTC15INData Raw: 65 72 72 6f 72 20 63 6f 64 65 3a 20 35 32 32
                  Data Ascii: error code: 522


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.449732142.250.186.364432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:17 UTC579OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
                  Host: www.google.com
                  Connection: keep-alive
                  X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEI0qDKAQig4coBCJWhywEInP7MAQiFoM0BCL7VzgEIgNbOAQjI3M4BCIrgzgEIruTOAQiL5c4B
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:17 UTC1303INHTTP/1.1 200 OK
                  Date: Fri, 14 Mar 2025 12:47:17 GMT
                  Pragma: no-cache
                  Expires: -1
                  Cache-Control: no-cache, must-revalidate
                  Content-Type: text/javascript; charset=UTF-8
                  Strict-Transport-Security: max-age=31536000
                  Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-gPkKgfM5ws0zvltnP-NBTg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                  Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                  Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                  Accept-CH: Sec-CH-Prefers-Color-Scheme
                  Accept-CH: Downlink
                  Accept-CH: RTT
                  Accept-CH: Sec-CH-UA-Form-Factors
                  Accept-CH: Sec-CH-UA-Platform
                  Accept-CH: Sec-CH-UA-Platform-Version
                  Accept-CH: Sec-CH-UA-Full-Version
                  Accept-CH: Sec-CH-UA-Arch
                  Accept-CH: Sec-CH-UA-Model
                  Accept-CH: Sec-CH-UA-Bitness
                  Accept-CH: Sec-CH-UA-Full-Version-List
                  Accept-CH: Sec-CH-UA-WoW64
                  Permissions-Policy: unload=()
                  Content-Disposition: attachment; filename="f.txt"
                  Server: gws
                  X-XSS-Protection: 0
                  X-Frame-Options: SAMEORIGIN
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2025-03-14 12:47:17 UTC87INData Raw: 33 37 34 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 6e 69 61 6e 74 69 63 20 73 65 6c 6c 73 20 70 6f 6b 65 6d 6f 6e 20 67 6f 22 2c 22 77 6f 72 64 6c 65 20 74 6f 64 61 79 20 6d 61 72 63 68 20 31 34 22 2c 22 74 64 20 62 61 6e 6b 20 63 6c 6f 73 69 6e 67 20 62 72 61 6e
                  Data Ascii: 374)]}'["",["niantic sells pokemon go","wordle today march 14","td bank closing bran
                  2025-03-14 12:47:17 UTC804INData Raw: 63 68 65 73 22 2c 22 73 75 64 69 6b 73 68 61 20 6b 6f 6e 61 6e 6b 69 20 6d 69 73 73 69 6e 67 20 70 75 6e 74 61 20 63 61 6e 61 22 2c 22 73 65 76 65 72 65 20 77 65 61 74 68 65 72 20 73 74 6f 72 6d 22 2c 22 77 68 61 74 20 74 69 6d 65 20 63 61 6e 20 69 20 70 6c 61 79 20 6d 6c 62 20 74 68 65 20 73 68 6f 77 20 32 35 22 2c 22 6c 61 6e 64 6d 61 6e 20 72 65 6e 65 77 65 64 22 2c 22 62 6c 6f 6f 64 20 6d 6f 6f 6e 20 74 6f 74 61 6c 20 6c 75 6e 61 72 20 65 63 6c 69 70 73 65 20 74 6f 6e 69 67 68 74 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70
                  Data Ascii: ches","sudiksha konanki missing punta cana","severe weather storm","what time can i play mlb the show 25","landman renewed","blood moon total lunar eclipse tonight"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:group
                  2025-03-14 12:47:17 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.44974335.190.80.14432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:55 UTC542OUTOPTIONS /report/v4?s=PZPfdnm%2Bp4dG8ctHkpf1YqCz9%2BUOugEIFn7yx1calyNJfUpcDfVuEoDYK6J9Mwazjk4ohBaDaFO4GPCoBpifhHRCRaweE955oWOifuchIOR6OwSyebDX65Lzj5s%2B2FPqX7M%3D HTTP/1.1
                  Host: a.nel.cloudflare.com
                  Connection: keep-alive
                  Origin: https://office.a8a.shop
                  Access-Control-Request-Method: POST
                  Access-Control-Request-Headers: content-type
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:55 UTC336INHTTP/1.1 200 OK
                  Content-Length: 0
                  access-control-max-age: 86400
                  access-control-allow-methods: POST, OPTIONS
                  access-control-allow-origin: *
                  access-control-allow-headers: content-length, content-type
                  date: Fri, 14 Mar 2025 12:47:54 GMT
                  Via: 1.1 google
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Connection: close


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  5192.168.2.449744172.67.136.694432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:55 UTC601OUTGET /favicon.ico HTTP/1.1
                  Host: office.a8a.shop
                  Connection: keep-alive
                  sec-ch-ua-platform: "Windows"
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://office.a8a.shop/xHIqAnQI
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:48:14 UTC960INHTTP/1.1 522
                  Date: Fri, 14 Mar 2025 12:48:14 GMT
                  Content-Type: text/plain; charset=UTF-8
                  Content-Length: 15
                  Connection: close
                  Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=q7ogexuaKwLEeaKxq5YD1%2FBI1tUNchum43QxgnEs2aNcEqVJ3YGGWYOg6ho88asoFcu65TjfMgtG0BBjSSA%2F5u%2FrXBNXppxikwxaoFF%2F8WF52WMjzgZJDn9p6I%2B%2FjCjCiCw%3D"}],"group":"cf-nel","max_age":604800}
                  NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                  X-Frame-Options: SAMEORIGIN
                  Referrer-Policy: same-origin
                  Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
                  Expires: Thu, 01 Jan 1970 00:00:01 GMT
                  Server: cloudflare
                  CF-RAY: 9203e1e1f85943ee-EWR
                  alt-svc: h3=":443"; ma=86400
                  server-timing: cfL4;desc="?proto=TCP&rtt=7101&min_rtt=1832&rtt_var=3992&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2815&recv_bytes=1173&delivery_rate=1593886&cwnd=228&unsent_bytes=0&cid=f6190f0baa64162b&ts=19503&x=0"
                  2025-03-14 12:48:14 UTC15INData Raw: 65 72 72 6f 72 20 63 6f 64 65 3a 20 35 32 32
                  Data Ascii: error code: 522


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  6192.168.2.44974535.190.80.14432412C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-03-14 12:47:55 UTC517OUTPOST /report/v4?s=PZPfdnm%2Bp4dG8ctHkpf1YqCz9%2BUOugEIFn7yx1calyNJfUpcDfVuEoDYK6J9Mwazjk4ohBaDaFO4GPCoBpifhHRCRaweE955oWOifuchIOR6OwSyebDX65Lzj5s%2B2FPqX7M%3D HTTP/1.1
                  Host: a.nel.cloudflare.com
                  Connection: keep-alive
                  Content-Length: 426
                  Content-Type: application/reports+json
                  Origin: https://office.a8a.shop
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-03-14 12:47:55 UTC426OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 33 39 38 33 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 69 6e 74 69 6d 69 64 61 64 63 6f 6e 64 69 6f 73 67 74 2e 63 6f 6d 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 33 36 2e 36 39 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 35 32 32 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72
                  Data Ascii: [{"age":0,"body":{"elapsed_time":39832,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://intimidadcondiosgt.com/","sampling_fraction":1.0,"server_ip":"172.67.136.69","status_code":522,"type":"http.error"},"type":"network-error
                  2025-03-14 12:47:55 UTC214INHTTP/1.1 200 OK
                  Content-Length: 0
                  access-control-allow-origin: *
                  vary: Origin
                  date: Fri, 14 Mar 2025 12:47:55 GMT
                  Via: 1.1 google
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Connection: close


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:1
                  Start time:08:47:02
                  Start date:14/03/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff786830000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:08:47:06
                  Start date:14/03/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2004,i,15356335459786314934,5695136569734279863,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2032 /prefetch:3
                  Imagebase:0x7ff659320000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:4
                  Start time:08:47:12
                  Start date:14/03/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N"
                  Imagebase:0x7ff786830000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly