Windows Analysis Report
Play Voicemail Transcription. (387.KB).svg

Overview

General Information

Sample name: Play Voicemail Transcription. (387.KB).svg
Analysis ID: 1640941
MD5: 577d2a99f19bf9ce5c1fdfc47627706e
SHA1: 76667c7d42bd16cc2b7962359b6fe5da9edb0fc5
SHA256: ad6646c0606816f5ddd4c3160eb971da0a70f54eac0ff58e837bd3a01242b5d4
Infos:

Detection

HTMLPhisher, Invisible JS, Tycoon2FA
Score: 100
Range: 0 - 100
Confidence: 100%

Signatures

AI detected phishing page
Antivirus detection for URL or domain
Found malware configuration
Yara detected AntiDebug via timestamp check
Yara detected HtmlPhish10
Yara detected HtmlPhish80
Yara detected Invisible JS
Yara detected Obfuscation Via HangulCharacter
Yara detected Tycoon 2FA PaaS
AI detected suspicious Javascript
AI detected suspicious URL
Queries random domain names (often used to prevent blacklisting and sinkholes)
Yara detected JavaScript embedded in SVG
Creates files inside the system directory
Deletes files inside the Windows folder
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
IP address seen in connection with other malware
Invalid T&C link found
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)

Classification

AV Detection

barindex
Source: https://grupomarina.brightnexst.ru/yzfSKSVVzwGEVLxY7bOA4NzirtCtF1GaMBQqxop8zPIfBhpW0CdjaQab180 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/ijbHPlXv32ebWvACIZbLFotR2xA3cdeNQ7GgeJq4gGCcuhx678168 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/yrhv76inSJaBVfGxBEwSxmLj7A0nIUCRosZ3LM0ORxbvHL4JE2FQRwo1v Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-vf2.woff2 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/pax6lf1/ Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/nm6KwyhgTPlcdaTFM6w4Te3A1nGYYINg9w5 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-regular.woff2 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/56clAjKv8GzXCyBZTPvhSGijqFC51GKJLn0iz7It89110 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/uv5tOb9SlHnVjDL3WYeZfQoF3Qs83rstFSZ0igTibpOtLLBCKZ34130 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/rqNX84y2LLLeotfXXhDH1k2LmulOVtkFLk3LFLhRu0ew Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-bold.woff Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-vf.woff2 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/ghBioawVsGsUA117yrJ412EaQY1Skt4YW6RuiH2YzmHxyQfrkxsWCkyew24xOurTOMWC6k8Q012210 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-regular.woff Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/stYI03OBVOCU6PTHp0UgOWjuR6YVCNeMM7jmnsOFLV5NiD0a9CgeCqBu7DmPKxRFjpU0zwRS32gh260 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/xyy6BRvgDOSBkrsxogh30 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/rsxdLZylu9sNLs7eTOu0UqzijrscZpLQuuew9C74mWaef200 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/opxSwtQgKAp3oNRo2XIhbcuyRLwKRd5xRghLW2MjECbAoN6NrGkr67139 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/favicon.ico Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/ijdastoNQHS8csTUxKMnYfLnTzCP891YpfDmPmdwyPnQeykuaxbSULSItkm2fyz222 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/GDSherpa-bold.woff2 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/56ACCeVmLlcdPPXc8920 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/mnDozZ86DfeH93KodasaV6JijAz0XdnqsnPjlpZlIO7O290148 Avira URL Cloud: Label: phishing
Source: https://grupomarina.brightnexst.ru/qr8qdLMcV1KyHq9RcCpDL8TGmNXiThRTm9oKUFrvN12Lp0gWgAcpxstwUy42SSCBNeoDKUyLiy7t5j5VJef232 Avira URL Cloud: Label: phishing
Source: 2.17.d.script.csv Malware Configuration Extractor: Tycoon2FA {"websitenames": "[\"godaddy\", \"okta\"]", "bes": "[\"Apple.com\",\"Netflix.com\"]", "pes": "[\"https:\\/\\/t.me\\/\",\"https:\\/\\/t.com\\/\",\"t.me\\/\",\"https:\\/\\/t.me.com\\/\",\"t.me.com\\/\",\"t.me@\",\"https:\\/\\/t.me@\",\"https:\\/\\/t.me\",\"https:\\/\\/t.com\",\"t.me\",\"https:\\/\\/t.me.com\",\"t.me.com\",\"t.me\\/@\",\"https:\\/\\/t.me\\/@\",\"https:\\/\\/t.me@\\/\",\"t.me@\\/\",\"https:\\/\\/www.telegram.me\\/\",\"https:\\/\\/www.telegram.me\"]", "capnum": "1", "appnum": "1", "pvn": "0", "view": "", "pagelinkval": "T8x6LF1", "emailcheck": "ssalazar@grupomarina.cl", "webname": "rtrim(/web8/, '/')", "urlo": "/yrhv76inSJaBVfGxBEwSxmLj7A0nIUCRosZ3LM0ORxbvHL4JE2FQRwo1v"}

Phishing

barindex
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The URL 'grupomarina.brightnexst.ru' does not match the legitimate domain for Microsoft., The domain 'brightnexst.ru' is unusual and not associated with Microsoft, which raises suspicion., The presence of a Russian domain extension '.ru' is not typical for Microsoft, which is primarily based in the US., The URL contains no direct reference to Microsoft, which is suspicious given the brand name provided., The email domain 'grupomarina.cl' does not align with Microsoft, suggesting potential phishing. DOM: 2.3.pages.csv
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The URL 'grupomarina.brightnexst.ru' does not match the legitimate domain for Microsoft., The domain 'brightnexst.ru' is unusual and not associated with Microsoft, raising suspicion., The presence of 'grupomarina' in the URL does not relate to Microsoft and could be an attempt to mislead users., The domain extension '.ru' is not typical for Microsoft, which usually uses '.com'., The email domain 'grupomarina.cl' does not match the Microsoft domain, suggesting a potential phishing attempt. DOM: 2.4.pages.csv
Source: Yara match File source: 2.4.pages.csv, type: HTML
Source: Yara match File source: 2.3.pages.csv, type: HTML
Source: Yara match File source: Play Voicemail Transcription. (387.KB).svg, type: SAMPLE
Source: Yara match File source: 1.2.d.script.csv, type: HTML
Source: Yara match File source: 1.0.pages.csv, type: HTML
Source: Yara match File source: 1.1.pages.csv, type: HTML
Source: Yara match File source: 1.2.d.script.csv, type: HTML
Source: Yara match File source: 2.19..script.csv, type: HTML
Source: Yara match File source: 1.1.pages.csv, type: HTML
Source: Yara match File source: 1.0.pages.csv, type: HTML
Source: Yara match File source: dropped/chromecache_77, type: DROPPED
Source: Yara match File source: 2.17.d.script.csv, type: HTML
Source: Yara match File source: 2.12..script.csv, type: HTML
Source: Yara match File source: 1.1.d.script.csv, type: HTML
Source: Yara match File source: 1.10.d.script.csv, type: HTML
Source: Yara match File source: 1.7..script.csv, type: HTML
Source: Yara match File source: 2.13..script.csv, type: HTML
Source: Yara match File source: 1.1.pages.csv, type: HTML
Source: Yara match File source: 1.0.pages.csv, type: HTML
Source: Yara match File source: 2.4.pages.csv, type: HTML
Source: Yara match File source: 2.3.pages.csv, type: HTML
Source: 1.1.d.script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including detecting the presence of web automation tools, blocking keyboard shortcuts and right-click functionality, and redirecting the user to an unrelated website after a delay. These behaviors are highly suspicious and indicate potential malicious intent, such as preventing the user from interacting with the page or redirecting them to a phishing site.
Source: 2.12..script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPH... This script exhibits several high-risk behaviors, including disabling common browser functionality, detecting and redirecting based on the presence of web automation tools, and intercepting clipboard operations. The combination of these behaviors suggests a highly suspicious and potentially malicious script.
Source: 1.10.d.script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including detecting the presence of web automation tools, disabling common keyboard shortcuts, and implementing a mechanism to detect and redirect the user to an external website upon detecting a debugger. These behaviors are highly suspicious and indicate potential malicious intent, such as preventing analysis or redirecting users to a malicious site.
Source: 1.3..script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://grupomarina.brightnexst.ru/pax6lf1/... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. The use of `atob` and `decodeURIComponent` to decode and execute remote code is a clear indicator of malicious intent. Additionally, the script appears to be sending user data to an untrusted domain, which poses a significant risk of data theft or other malicious activities. Overall, this script exhibits a high level of suspicion and should be treated as a potential security threat.
Source: 1.9..script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://grupomarina.brightnexst.ru/pax6lf1/... This script demonstrates several high-risk behaviors, including dynamic code execution, potential data exfiltration, and suspicious redirection. The use of obfuscated code and the presence of a debugger statement further increase the risk. Overall, this script exhibits a high level of malicious intent and should be considered a significant security threat.
Source: 1.8..script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://grupomarina.brightnexst.ru/pax6lf1/... This script exhibits several high-risk behaviors, including dynamic code execution through the use of `atob()` and string manipulation to obfuscate the code. Additionally, the script appears to be sending data to an external domain, which could potentially be used for data exfiltration. The heavy obfuscation and lack of transparency around the script's purpose suggest a high likelihood of malicious intent.
Source: 1.2.d.script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including dynamic code execution using `eval()`, potential data exfiltration, and the use of obfuscated code. The combination of these factors indicates a high likelihood of malicious intent, warranting a maximum risk score of 10.
Source: https://brightnexst.ru Joe Sandbox AI: The URL 'brightnexst.ru' appears to be a typosquatting attempt on the brand 'BrightNest'. The legitimate URL is 'brightnest.com', a known brand offering home organization and cleaning tips. The analyzed URL uses a visual character substitution by adding an 'x' to 'nest', which could easily be overlooked by users. The '.ru' domain extension is unrelated to the brand's typical '.com' domain, which may further confuse users. The similarity score is high due to the close resemblance in spelling and potential for user confusion. The likelihood of typosquatting is also high, given the structural similarity and the use of a misleading domain extension.
Source: Yara match File source: Play Voicemail Transcription. (387.KB).svg, type: SAMPLE
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Number of links: 0
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://grupomarina.brightnexst.ru/pax6lf1/#Tssalazar%40grupomarina.cl HTTP Parser: Base64 decoded: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Graphic Card Web Template</title> <style> body { font-family: 'Montserrat', sa...
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Title: Sign in to your account does not match URL
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Invalid link: Terms of use
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Invalid link: Privacy & cookies
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Invalid link: Terms of use
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: Invalid link: Privacy & cookies
Source: https://grupomarina.brightnexst.ru/pax6lf1/ HTTP Parser: function ifjondlauj(){sddnepvvsx = atob("pcfet0nuwvbfigh0bww+cjxodg1sigxhbmc9imvuij4kpghlywq+ciagica8bwv0ysbjagfyc2v0psjvveytoci+ciagica8bwv0ysbuyw1lpsj2awv3cg9ydcigy29udgvudd0id2lkdgg9zgv2awnllxdpzhrolcbpbml0awfslxnjywxlpteumci+ciagica8dgl0bgu+t2zmawnlidm2nsbeb2n1bwvudgf0aw9upc90axrszt4kicagidxzdhlszt4kicagicagicbib2r5ihskicagicagicagicagzm9udc1myw1pbhk6iefyawfslcbzyw5zlxnlcmlmowogicagicagicagicbsaw5llwhlawdoddogms42owogicagicagicagicbtyxjnaw46idiwchg7ciagicagicagfqogicagicagiggxlcbomib7ciagicagicagicagignvbg9yoiajmky1ndk2owogicagicagih0kicagicagicb1bcb7ciagicagicagicagigxpc3qtc3r5bgutdhlwztogc3f1yxjlowogicagicagih0kicagicagicbhihskicagicagicagicagy29sb3i6icmwmdc4rdq7ciagicagicagicagihrlehqtzgvjb3jhdglvbjogbm9uztskicagicagicb9ciagicagicagytpob3zlcib7ciagicagicagicagihrlehqtzgvjb3jhdglvbjogdw5kzxjsaw5lowogicagicagih0kicagidwvc3r5bgu+cjwvagvhzd4kpgjvzhk+ciagica8ade+r2v0dgluzybtdgfydgvkihdpdgggt2zmawnlidm2ntwvade+ciagica8cd5pzmzpy2ugmzy1iglzigegy2xvdwqtymfzzwqgc3vpdgugb2ygchjvzhvjdgl2axr5ihrvb2xzigrlc2lnbmvki...
Source: anonymous function HTTP Parser: var otherweburl = "";var websitenames = ["godaddy", "okta"];var bes = ["apple.com","netflix.com"];var pes = ["https:\/\/t.me\/","https:\/\/t.com\/","t.me\/","https:\/\/t.me.com\/","t.me.com\/","t.me@","https:\/\/t.me@","https:\/\/t.me","https:\/\/t.com","t.me","https:\/\/t.me.com","t.me.com","t.me\/@","https:\/\/t.me\/@","https:\/\/t.me@\/","t.me@\/","https:\/\/www.telegram.me\/","https:\/\/www.telegram.me"];var capnum = 1;var appnum = 1;var pvn = 0;var view = "";var pagelinkval = "t8x6lf1";var emailcheck = "ssalazar@grupomarina.cl";var webname = "rtrim(/web8/, '/')";var urlo = "/yrhv76insjabvfgxbewsxmlj7a0niucrosz3lm0orxbvhl4je2fqrwo1v";var gdf = "/ijwxbjcpujkugv6b0ius4gwxxngppk1dvmcd120";var odf = "/ijot2xt2gg4wdgglbtvt7ljm9dtswxxs8wxqfkqdlq4wcd650";var twa = 0;var currentreq = null;var requestsent = false;var pagedata = "";var redirecturl = "";var useragent = navigator.useragent;var browsername;var userip;var usercountry;var errorcodeexecuted = false;if(use...
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: <input type="password" .../> found
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No favicon
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No favicon
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No <meta name="author".. found
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No <meta name="author".. found
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No <meta name="copyright".. found
Source: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 104.21.2.147:443 -> 192.168.2.16:49699 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.2.137:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.95.41:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.24.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.24.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.184.196:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.6.189:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.6.189:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.180.46:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.180.46:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 140.82.121.4:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.110.133:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.96:443 -> 192.168.2.16:49775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.70.233:443 -> 192.168.2.16:49781 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.1.100:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.49.96:443 -> 192.168.2.16:49783 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.49.96:443 -> 192.168.2.16:49784 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.16:49798 version: TLS 1.2
Source: chrome.exe Memory has grown: Private usage: 1MB later: 53MB

Networking

barindex
Source: unknown DNS traffic detected: English language letter frequency does not match the domain names
Source: Joe Sandbox View IP Address: 104.26.1.100 104.26.1.100
Source: Joe Sandbox View IP Address: 104.16.6.189 104.16.6.189
Source: Joe Sandbox View IP Address: 185.199.110.133 185.199.110.133
Source: Joe Sandbox View IP Address: 185.199.110.133 185.199.110.133
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /8aF18c0N2CFbzCTcnC9dgBRsTPqgJHosieM4AfhPW0xfPX2eeciO211xYhM0xGUkwGUOoh4IvF3ZPcaD4TPZKiK82JYCYMTzbWRx33HFHsB2HZJgoelAJ9OHcyXYhSv2b4snjE0bGGsx1RQwtLZsb89T05LuiQaXEc9KIeYyXY9i9AkWnvTxHNq2RnYeMDlmw1AoOs54/YIwMRE5gwuQ2zFZXpZePC1d6JvR8UnaSyC28RNwjYQ2x6AJ3tVFbOjnL3Jjrq5OAPeOVsVhG8rpbVvDMM431NF6drmD5nCYhmRLNPBV491yoAqHcTFohgjfRtlhA8j39Ntt588ilQZr1SKngEgmbxe7oHVZMB0huT9so8f8UZb40zdENVSZ0SvQCOMzkctlE1yCXhk2Y/ssalazar@grupomarina.cl HTTP/1.1Host: xfeoii3kbm.woofradio.cfdConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /pax6lf1/ HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://xfeoii3kbm.woofradio.cfd/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /turnstile/v0/api.js?onload=onloadTurnstileCallback HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/crypto-js/4.1.1/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=QLIcY8zuRXkneduiM6OiCyNJFAdVng3DHFdLxD_QGD4-1742244904-1.0.1.1-CmjGgIbP4agpLv8m1vdI5en4sDXTII5DRrhGYBzfcy2viX4bO7YAMn5BeXAR8QFG_nTY7oy2NAljL2pUq6hYeVL21uR3v5wrsGyysyAqPP4
Source: global traffic HTTP traffic detected: GET /tarboz@gicb27 HTTP/1.1Host: xoq7.qakaco.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://grupomarina.brightnexst.ruSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /tarboz@gicb27 HTTP/1.1Host: xoq7.qakaco.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /pax6lf1/ HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://grupomarina.brightnexst.ru/pax6lf1/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlF2blkwdUpsTEdtemg1TEJsQ0RZY1E9PSIsInZhbHVlIjoiQzBmbnBLRVN2LzlKdGs0aEFOYmJYRDEwUUZvOElVWUZYT2FQYTBZWm1NWlNEY0V6L2JMdWQ0OWhjT0dZZG9EcGdYaS9NZ3R6QWNoOUVDcW5JVXVrZGVOSVBZYXRGemxMc2JENGd3dytBRE5rSzdKY1RaY2xta2VWMjRFTGduakciLCJtYWMiOiIyZWZiODJiNjQ5YjIxZDU4ZGVkMmU1MzA4OWQzODllOWQzZTYwZmU3MzMyMGZhNjUxN2IzOGVmMjBlMmIxNDkyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InpQR3kxT1U3eTRvL3VJRVdIV0pOWlE9PSIsInZhbHVlIjoiWGRFMzBHUStkdDV3c1BGWU5rd3l5STdDNjZpQnBpbTBBbjRrRFNXUmxDb1d6S3FmeitYY1VObzRIb3Z3THE1THhUYXk3OTNpbk83MkoyY2I1YWdaVmhTa0RxQW9ZaGlrTGowVlN5bVR2YXl2ZXBPaG5LeWZ4UGxqNEV6VTkxVFMiLCJtYWMiOiIxYzAzZmM2MDlmNjMwY2ExZWMwNmFjZTY2Yzk2Njk1MTA2YTI5OTQyNjkyZTkyM2E5YWU0MGEwZDk0N2UwNTI5IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /nm6KwyhgTPlcdaTFM6w4Te3A1nGYYINg9w5 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlF2blkwdUpsTEdtemg1TEJsQ0RZY1E9PSIsInZhbHVlIjoiQzBmbnBLRVN2LzlKdGs0aEFOYmJYRDEwUUZvOElVWUZYT2FQYTBZWm1NWlNEY0V6L2JMdWQ0OWhjT0dZZG9EcGdYaS9NZ3R6QWNoOUVDcW5JVXVrZGVOSVBZYXRGemxMc2JENGd3dytBRE5rSzdKY1RaY2xta2VWMjRFTGduakciLCJtYWMiOiIyZWZiODJiNjQ5YjIxZDU4ZGVkMmU1MzA4OWQzODllOWQzZTYwZmU3MzMyMGZhNjUxN2IzOGVmMjBlMmIxNDkyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InpQR3kxT1U3eTRvL3VJRVdIV0pOWlE9PSIsInZhbHVlIjoiWGRFMzBHUStkdDV3c1BGWU5rd3l5STdDNjZpQnBpbTBBbjRrRFNXUmxDb1d6S3FmeitYY1VObzRIb3Z3THE1THhUYXk3OTNpbk83MkoyY2I1YWdaVmhTa0RxQW9ZaGlrTGowVlN5bVR2YXl2ZXBPaG5LeWZ4UGxqNEV6VTkxVFMiLCJtYWMiOiIxYzAzZmM2MDlmNjMwY2ExZWMwNmFjZTY2Yzk2Njk1MTA2YTI5OTQyNjkyZTkyM2E5YWU0MGEwZDk0N2UwNTI5IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPW HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://grupomarina.brightnexst.ru/pax6lf1/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6InV6ajB3QzJmbWdEdW80c250Z2ZEd3c9PSIsInZhbHVlIjoiN2V0VFRjc245T3RsSTd2cDVjVUc3RGZudkpxdkdjcVFMTHJmOFJ0ZmdBYlFxRjY2S3NVMS9zcWVvTTZUSGtabHNsVGN4eGMzRU1JZDN2VWFtZjRYQU5hU3UvMW90SUp2S3oyQWUyekhvc3dTSGVsOU9JN3VsUVBrTDRDZjJ5MmgiLCJtYWMiOiJhNTBiZmRiYjYyOGM3YzYxOGZiZGFlZjBlZmU2NzJlOTkzMjhlMmExZGJmYzNlNzE5YWY0NTRhMWI3MmI0ZjczIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6ImgxMUpTYkJzeVZQWkVTZGhxalhEY3c9PSIsInZhbHVlIjoiY3BnOFVteUpMbHBmVFdRYTM3UEQ2L0huUkNVUTBLQitPbW05bTQvTzhCL3VrMlpYRDA0Mi9OM0hPOFVOaEFhQ25BWVNlVVJvVm93MlEwaXd3TlFVRFBTODB4N0Z4bkNMUVVObzZiVUJYdkVVNHdORnVxTkVmRWNlMUdhYU54dFUiLCJtYWMiOiIyZGU3MDU3ZWExNjZkYWU3YTZjODkwM2FkMjY3MjRiYTk0MzA3MjY2ZjEwZjE3MTI0NGE2MjMxY2QzZDgyNTFkIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rqNX84y2LLLeotfXXhDH1k2LmulOVtkFLk3LFLhRu0ew HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6InV6ajB3QzJmbWdEdW80c250Z2ZEd3c9PSIsInZhbHVlIjoiN2V0VFRjc245T3RsSTd2cDVjVUc3RGZudkpxdkdjcVFMTHJmOFJ0ZmdBYlFxRjY2S3NVMS9zcWVvTTZUSGtabHNsVGN4eGMzRU1JZDN2VWFtZjRYQU5hU3UvMW90SUp2S3oyQWUyekhvc3dTSGVsOU9JN3VsUVBrTDRDZjJ5MmgiLCJtYWMiOiJhNTBiZmRiYjYyOGM3YzYxOGZiZGFlZjBlZmU2NzJlOTkzMjhlMmExZGJmYzNlNzE5YWY0NTRhMWI3MmI0ZjczIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6ImgxMUpTYkJzeVZQWkVTZGhxalhEY3c9PSIsInZhbHVlIjoiY3BnOFVteUpMbHBmVFdRYTM3UEQ2L0huUkNVUTBLQitPbW05bTQvTzhCL3VrMlpYRDA0Mi9OM0hPOFVOaEFhQ25BWVNlVVJvVm93MlEwaXd3TlFVRFBTODB4N0Z4bkNMUVVObzZiVUJYdkVVNHdORnVxTkVmRWNlMUdhYU54dFUiLCJtYWMiOiIyZGU3MDU3ZWExNjZkYWU3YTZjODkwM2FkMjY3MjRiYTk0MzA3MjY2ZjEwZjE3MTI0NGE2MjMxY2QzZDgyNTFkIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/pax6lf1/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImY2L3FleFlvRmx1ZmVHMmY1NXRETWc9PSIsInZhbHVlIjoiV01HdnVjLzhnNTZiaWhvYVhqcDdNNUlJejdoVXl3K0pWQlo3TVZxWXkwQjFtTk9xV0FTOXk5YkZFb1p5a1NnR2hsNFo0bXhSVkFIbmFwOTFPSHFaNk5DUVJWc25ERmdBRUVXc05SSGdNYzR1TSsvMGZSWnpMV21vZ1o2OUxQMW8iLCJtYWMiOiI0NjE5YTYwNzJiY2M4NWQyZTNiZTMwOGY4MWE2YTA3NDVjMDM5MGY3ZDE4NjI3YzA3MzhkZDM2Njc4OTM1Nzc5IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InBhWmtrUUJVNmJoNlQ5ZHA2MTU0Wnc9PSIsInZhbHVlIjoiZWhGaENsY05ybkRuWGx1YUlDdlR3TTZGNndSUGtFNlZBQ0l2OFd0VTg2a1hDU1ppdHR3b29SNDg1cUhMRzZWYzE3b1NWZ2RESnFFdDA1N2VjQUdnZi9YZHYxcUJxT2s5SkY3TmFIc0w4aXJZZVA2eXdFZWxQZ2MzaURkTWkzSEEiLCJtYWMiOiI0OWY1OWQ3OTVmMjY4MWI1M2FiYTU1ZjU4N2IzN2M4ZjZiYzJiMGI0NzNiY2Q1NTAzNGM4NWZiNzRmNGQwMzA5IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /56ACCeVmLlcdPPXc8920 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /xyy6BRvgDOSBkrsxogh30 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /GDSherpa-bold.woff2 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /GDSherpa-bold.woff HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /GDSherpa-regular.woff2 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /GDSherpa-regular.woff HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /fent/randexp.js/releases/download/v0.4.3/randexp.min.js HTTP/1.1Host: github.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.18.0/css/okta-sign-in.min.css HTTP/1.1Host: ok4static.oktacdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/loginpage/css/loginpage-theme.e0d37a504604ef874bad26435d62011f.css HTTP/1.1Host: ok4static.oktacdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /GDSherpa-vf.woff2 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /GDSherpa-vf2.woff2 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveOrigin: https://grupomarina.brightnexst.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /56clAjKv8GzXCyBZTPvhSGijqFC51GKJLn0iz7It89110 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /github-production-release-asset-2e65be/2925284/11f3acf8-4ccb-11e6-8ce4-c179c0a212de?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=releaseassetproduction%2F20250317%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250317T205513Z&X-Amz-Expires=300&X-Amz-Signature=e616e7388ad102e9cb0d3ae02f97cd7c71b53bb553c2889c097375ffd2fede86&X-Amz-SignedHeaders=host&response-content-disposition=attachment%3B%20filename%3Drandexp.min.js&response-content-type=application%2Foctet-stream HTTP/1.1Host: objects.githubusercontent.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ijdastoNQHS8csTUxKMnYfLnTzCP891YpfDmPmdwyPnQeykuaxbSULSItkm2fyz222 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mn7axJgNsfJZOnXe9HMLiMbkijOyTcCkXpGKdJddrqJTO29kXFFoLgmgRouv220 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ijdastoNQHS8csTUxKMnYfLnTzCP891YpfDmPmdwyPnQeykuaxbSULSItkm2fyz222 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /uv5tOb9SlHnVjDL3WYeZfQoF3Qs83rstFSZ0igTibpOtLLBCKZ34130 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /opxSwtQgKAp3oNRo2XIhbcuyRLwKRd5xRghLW2MjECbAoN6NrGkr67139 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mn7axJgNsfJZOnXe9HMLiMbkijOyTcCkXpGKdJddrqJTO29kXFFoLgmgRouv220 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjI4b0N4cTAvWllwVzAxWEVkaEpCQnc9PSIsInZhbHVlIjoiUDJGTmVSazA1d1Y2U2NOZzJZZlNDSkZtSTNjRUZmQiszc0FzdHpkUXE4Z2RrK3RjN0FnOUhGa0tKVlllM0ZXYytmaC8zajFZeFlsMUFSSXFuaElPQ3psTWVUcDc5QVlxMUdhanpqRW9KT1Uwa1dBUUFXcHFsYjZnaWVLU3JnK1kiLCJtYWMiOiJiZjViMTUxNTdmN2U1N2QwNDgwZmIxMWFmZGM3N2Q1MjU3M2ExYzZmY2ZkN2JmNGM0YzU0MTZiNDM0MTVmZWQ0IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6Ik5IMCthcU5iZ2I3SExSdzJoNFJUU3c9PSIsInZhbHVlIjoiN2VqZmVNQm9zbDhJenZIanphOEltNzEvaW9VcytsMXEyQmFLWnpzV0hUeU1ZM0MwMUFScFJlZXRveXp0TzdtdGJKK3Rrc2J1S2xWWWJxT3poUVpwTjVtMDhQbjU4WFRJZG9vRWpUQ3EyUjFwZU0ybFI5YUZwMmk5Y05oVHRyTWgiLCJtYWMiOiI3YjMzMmQ3ZmRkOWE4ZjE2N2EyZTcxMDRiMjRkNTAwNzMxNDcwNDMwYTIwZmViZmY0NjU2OGM0Zjc3ZmZhOGQxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mnDozZ86DfeH93KodasaV6JijAz0XdnqsnPjlpZlIO7O290148 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ijbHPlXv32ebWvACIZbLFotR2xA3cdeNQ7GgeJq4gGCcuhx678168 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yzfSKSVVzwGEVLxY7bOA4NzirtCtF1GaMBQqxop8zPIfBhpW0CdjaQab180 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yrhv76inSJaBVfGxBEwSxmLj7A0nIUCRosZ3LM0ORxbvHL4JE2FQRwo1v HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rsxdLZylu9sNLs7eTOu0UqzijrscZpLQuuew9C74mWaef200 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /opxSwtQgKAp3oNRo2XIhbcuyRLwKRd5xRghLW2MjECbAoN6NrGkr67139 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /uv5tOb9SlHnVjDL3WYeZfQoF3Qs83rstFSZ0igTibpOtLLBCKZ34130 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ghBioawVsGsUA117yrJ412EaQY1Skt4YW6RuiH2YzmHxyQfrkxsWCkyew24xOurTOMWC6k8Q012210 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ijbHPlXv32ebWvACIZbLFotR2xA3cdeNQ7GgeJq4gGCcuhx678168 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /qr8qdLMcV1KyHq9RcCpDL8TGmNXiThRTm9oKUFrvN12Lp0gWgAcpxstwUy42SSCBNeoDKUyLiy7t5j5VJef232 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yzfSKSVVzwGEVLxY7bOA4NzirtCtF1GaMBQqxop8zPIfBhpW0CdjaQab180 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /fs/bcg/4/gfsh9pi7jcWKJKMAs1t7 HTTP/1.1Host: ok4static.oktacdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /stYI03OBVOCU6PTHp0UgOWjuR6YVCNeMM7jmnsOFLV5NiD0a9CgeCqBu7DmPKxRFjpU0zwRS32gh260 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mnDozZ86DfeH93KodasaV6JijAz0XdnqsnPjlpZlIO7O290148 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rsxdLZylu9sNLs7eTOu0UqzijrscZpLQuuew9C74mWaef200 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /qr8qdLMcV1KyHq9RcCpDL8TGmNXiThRTm9oKUFrvN12Lp0gWgAcpxstwUy42SSCBNeoDKUyLiy7t5j5VJef232 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /fs/bcg/4/gfsh9pi7jcWKJKMAs1t7 HTTP/1.1Host: ok4static.oktacdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ghBioawVsGsUA117yrJ412EaQY1Skt4YW6RuiH2YzmHxyQfrkxsWCkyew24xOurTOMWC6k8Q012210 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /stYI03OBVOCU6PTHp0UgOWjuR6YVCNeMM7jmnsOFLV5NiD0a9CgeCqBu7DmPKxRFjpU0zwRS32gh260 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://grupomarina.brightnexst.ru/AMCNUFNXZDUICPHJPN1DKQYE79CZQHUFVI5DL1S6E2BHE?VPBVFBFRDRWKLIZWKSEPXXPWAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjJVYndkK0dCY2FoRGdTdGdKMXMrSFE9PSIsInZhbHVlIjoiTHVzMDhDNXFoYzJIZnBlQWRtNzlVd2MwZnpReEJVYThMWTg4a1NpeTh4ekNiMW9IT3JyeEhyVlA5UUFseWNUWmxzT3FpQ1ZzSXNPWkpUbFV3SG0yY25sRjYzTSs4SGErWEZ4bWpxSHRGcC9FUzIrLy9DakIzOHl6S1B2d2JHQWsiLCJtYWMiOiJiZjIwNGRjMDc4NDAzYmJkNTNhOGE1ZDAzZDc4NjBmNjQ3NWQzMzk2YWFmNGJjNDZhYzg5YmE4YWY3NmJiMDMyIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjRkVEdNV3VhTko2TmRCMzY0RXloVUE9PSIsInZhbHVlIjoiZ0pucVFXb2tmbXVNUlIvMEdraHJYRHNBblFaZXExZG4yUGQzS0lxWVdSMDVRV1k0QTFnbUMxR3JQbC9aTW1ZTm5wN1d6ZW9JV1NTWGJKcGIxR1FJZnQ4TXBETjlvRDYxNk92cHd5cGRjYld4TTRSYTRxUlRSbzZJeTBVU1pNMFIiLCJtYWMiOiJkMDdkYTlhZWY2NmNlNjk4ZTBiMTQzZDExYzQ2YWQ3MTNkNzc0ZmRiN2Q0MTkyZDBhNjRhYTIyZWI3OTI2NjFlIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /v1/ip/geo.json HTTP/1.1Host: get.geojs.ioConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: application/json, text/javascript, */*; q=0.01sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Origin: https://grupomarina.brightnexst.ruSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://grupomarina.brightnexst.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /v1/ip/geo.json HTTP/1.1Host: get.geojs.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /qroGHAUDePLpnzyKkQmczDpopPjitYSbVTVKVKMUJVFITSMCWETEESJCFPZDLPJNJXIrsk0agvHzvnbvksSbpV12V8Bcwx40 HTTP/1.1Host: 5qdxsl77lrspjgndviiqjboedfl99fkwrbe1q8uvc7kmybiei89u.amayaxw.esConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /qroGHAUDePLpnzyKkQmczDpopPjitYSbVTVKVKMUJVFITSMCWETEESJCFPZDLPJNJXIrsjeRFV6JKY12RPztaFwx38 HTTP/1.1Host: 5qdxsl77lrspjgndviiqjboedfl99fkwrbe1q8uvc7kmybiei89u.amayaxw.esConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: xfeoii3kbm.woofradio.cfd
Source: global traffic DNS traffic detected: DNS query: grupomarina.brightnexst.ru
Source: global traffic DNS traffic detected: DNS query: code.jquery.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: developers.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: xoq7.qakaco.ru
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: github.com
Source: global traffic DNS traffic detected: DNS query: ok4static.oktacdn.com
Source: global traffic DNS traffic detected: DNS query: objects.githubusercontent.com
Source: global traffic DNS traffic detected: DNS query: get.geojs.io
Source: global traffic DNS traffic detected: DNS query: 5qdxsl77lrspjgndviiqjboedfl99fkwrbe1q8uvc7kmybiei89u.amayaxw.es
Source: unknown HTTP traffic detected: POST /nm6KwyhgTPlcdaTFM6w4Te3A1nGYYINg9w5 HTTP/1.1Host: grupomarina.brightnexst.ruConnection: keep-aliveContent-Length: 809sec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryAxg0t7rZuRME4SDxsec-ch-ua-mobile: ?0Accept: */*Origin: https://grupomarina.brightnexst.ruSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://grupomarina.brightnexst.ru/pax6lf1/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6InRLOEtjTVhIWUcrNGFaY0NYYmg4T0E9PSIsInZhbHVlIjoidE5lQ1dTM1A0NkNHbGV5ajZjVzViTzVxbDgybVpsWlFHc09FaHFLaTZwY3hFUml3ZFJKWldJcEhkS0RIMzE4dVZVTjZ2OVg0Zzg2dWM1SlZRdzFWMW5ucW9YM0pqczFCVVc5ekJrTzJDRGU3SlNuUjBkYmFJR0hCcmFpY0lGQzUiLCJtYWMiOiIxYTBiZjkwYTVjYmM3Yzk4Zjc1ODc1ZjQyYWRlYWQ5MGI1ODM3ZjQwMGJhZmY1MWY0M2ZhMGYzNmRhY2ZkYjJlIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IkxMVXpXbmc0U1N0WTRTc1NGbFppUUE9PSIsInZhbHVlIjoia1NoQXFBVGR5Ynd5SVpYbHNWM25EWkhQdEFBcVNyU0RhWExTdGZ3bFkvekRzN0UrcDV2cGJyNDJSbXl6RytwUWxhejVXcUcvWUc1TzBpcGJkd3dTZ1hsMkhMcThzdWNoOUdpTWJoV2tCLzNUYW9MRFZLU3V4NUx4Rk92ekdzVE8iLCJtYWMiOiI4ZDA5NWRmODYzMTJiOTBhMmI0NjdlNDllNjgwODc0YjM2YjUwMzUxMzE2YWM5YzVhZDliMWVhMjkxMzAyNGQ0IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 17 Mar 2025 20:55:11 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=M38fjdfrZwMhGFgUDmUvPM9bt5QvH3JId4Mx%2BqAaPhycRfw1luQ6fV4eKXgcqlgHJsfyB5s7OV3viqiNx1SobaJGrA1NNUK%2F5ODu%2BVstk%2Ftq9UHQsKR%2BxefYBWT2"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}server-timing: cfL4;desc="?proto=TCP&rtt=1512&min_rtt=1332&rtt_var=492&sent=4&recv=8&lost=0&retrans=0&sent_bytes=2826&recv_bytes=2059&delivery_rate=1991746&cwnd=251&unsent_bytes=0&cid=4e1a2a2ba52e5651&ts=87&x=0"Server: cloudflareCF-RAY: 921f63c7ea698cbd-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1794&min_rtt=1789&rtt_var=681&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2833&recv_bytes=1720&delivery_rate=1596500&cwnd=183&unsent_bytes=0&cid=28ef9c26b81f0ccb&ts=409&x=0"
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 17 Mar 2025 20:55:12 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7rl53jo%2FaF9PMyZ58I2rxkMVjLCL19Hr9fITUInjwtiM5UMEaICinvW1rqVy25h0ZAGlqtJfbPXOe3FZESl7UlCCxOzWpwqPvmzyIxEZeHBwrdGzJ9F0TB7KR4vK"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}server-timing: cfL4;desc="?proto=TCP&rtt=1694&min_rtt=1499&rtt_var=594&sent=4&recv=8&lost=0&retrans=0&sent_bytes=2826&recv_bytes=2068&delivery_rate=1920424&cwnd=250&unsent_bytes=0&cid=8def3e7a98fcb408&ts=86&x=0"Server: cloudflareCF-RAY: 921f63d01e3c432b-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1707&min_rtt=1699&rtt_var=654&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2834&recv_bytes=1729&delivery_rate=1650650&cwnd=190&unsent_bytes=0&cid=aaa63fda0f09f7c1&ts=425&x=0"
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 17 Mar 2025 20:55:16 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICvary: accept-encodingReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ThFIpE0Tr%2BKwwkfKT5mmL9SCjiU98BQrTdJPeYfB7%2BQCzpzU1M6slVJnThgdSALxeocpQKgd5sBZFt5YaFmSRBOS2tMHsAKAO555WRLcjj7eSGq1Ztg1wEvP35Jw"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}server-timing: cfL4;desc="?proto=TCP&rtt=1244&min_rtt=1236&rtt_var=480&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2826&recv_bytes=2080&delivery_rate=2219157&cwnd=251&unsent_bytes=0&cid=b941efcfaaabf3a8&ts=73&x=0"Server: cloudflareCF-RAY: 921f63e72c580c9e-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1685&min_rtt=1681&rtt_var=639&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2834&recv_bytes=1742&delivery_rate=1700640&cwnd=81&unsent_bytes=0&cid=8f953bdf33a91e01&ts=584&x=0"
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 17 Mar 2025 20:55:19 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4ESolW0Cf3pQqasSDugpsMcSG6oBoq0fLXP0Ppa9D4y7daoicYdaJx2vXf83w8aIvXzKc0qoxak%2B1ZR3jmO6hz%2BBz9OAYc5FQE818C4D2vKOquBeUMcdZ6PEjex0"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Vary: Accept-Encodingserver-timing: cfL4;desc="?proto=TCP&rtt=1162&min_rtt=1104&rtt_var=412&sent=5&recv=8&lost=0&retrans=0&sent_bytes=2826&recv_bytes=2319&delivery_rate=2126284&cwnd=251&unsent_bytes=0&cid=ce0fc092dea349f3&ts=77&x=0"Cache-Control: max-age=14400CF-Cache-Status: MISSServer: cloudflareCF-RAY: 921f63f9eff714a8-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=2115&min_rtt=2114&rtt_var=795&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2833&recv_bytes=1980&delivery_rate=1373471&cwnd=162&unsent_bytes=0&cid=7f97e4a6b7aef019&ts=403&x=0"
Source: chromecache_98.1.dr String found in binary or memory: http://github.com/fent/randexp.js/raw/master/LICENSE
Source: chromecache_98.1.dr String found in binary or memory: https://github.com/fent)
Source: chromecache_102.1.dr String found in binary or memory: https://www.etsy.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49679 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49671 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49803
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 104.21.2.147:443 -> 192.168.2.16:49699 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 151.101.2.137:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.95.41:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.24.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.24.14:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.184.196:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.6.189:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.6.189:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.180.46:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.180.46:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.41.104:443 -> 192.168.2.16:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 140.82.121.4:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.110.133:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.68:443 -> 192.168.2.16:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.33.187.96:443 -> 192.168.2.16:49775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.70.233:443 -> 192.168.2.16:49781 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.1.100:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.49.96:443 -> 192.168.2.16:49783 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.49.96:443 -> 192.168.2.16:49784 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.16:49798 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Windows\SystemTemp\scoped_dir6248_548697735 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File deleted: C:\Windows\SystemTemp\scoped_dir6248_548697735 Jump to behavior
Source: classification engine Classification label: mal100.phis.troj.evad.winSVG@21/80@44/18
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\PLAYVO~1.SVG
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7288536219110086134,15413776007562023016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2216 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2044,i,7288536219110086134,15413776007562023016,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2216 /prefetch:3 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected

Malware Analysis System Evasion

barindex
Source: Yara match File source: 2.12..script.csv, type: HTML
Source: Yara match File source: 1.1.d.script.csv, type: HTML
Source: Yara match File source: 2.13..script.csv, type: HTML
Source: Yara match File source: 2.4.pages.csv, type: HTML
Source: Yara match File source: 2.3.pages.csv, type: HTML
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs