Source: https://kerijigobiwut.poletofuti.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=92eb32750cf9dab9 | Avira URL Cloud: Label: malware |
Source: https://file-connection-all-ez.com/dive-into-the-intuitive-interface-of-folder-size-shell-3-2/?utm_term=free+audio+visualizer+templates&utm_content=19fo3tg69ff21&utm_medium=link&utm_source=A3xYd050003810000000008066419&referer=https%3A%2F%2Fkerijigobiwut.poletofuti.com%2F | Avira URL Cloud: Label: malware |
Source: https://kerijigobiwut.poletofuti.com/favicon.ico | Avira URL Cloud: Label: malware |
Source: https://file-connection-all-ez.com/dive-into-the-intuitive-interface-of-folder-size-shell-3-2/?utm_source=19fo3tg69ff21&utm_term=free%20audio%20visualizer%20templates&utm_content=19fo3tg69ff21&utm_medium=link | Avira URL Cloud: Label: malware |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizi | Avira URL Cloud: Label: malware |
Source: https://kerijigobiwut.poletofuti.com/mgo.php?q=free+audio+visualizer+templates&s1=19fo3tg69ff21 | Avira URL Cloud: Label: malware |
Source: https://kerijigobiwut.poletofuti.com/b.js | Avira URL Cloud: Label: malware |
Source: 0.0..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://kerijigobiwut.poletofuti.com/6612345172723... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. It appears to be a malicious script designed to collect sensitive user data and potentially execute remote code. The combination of these behaviors, along with the use of suspicious domains, indicates a high risk of malicious intent. |
Source: 1.6..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: blob:https://kerijigobiwut.poletofuti.com/1b66dad0... This script demonstrates high-risk behavior by using the `eval()` function to execute dynamic code received from an untrusted source. The use of `eval()` allows for the execution of arbitrary JavaScript, which poses a significant security risk. Additionally, the lack of origin verification and the absence of a message source indicate that this script is vulnerable to cross-origin attacks and could be used to execute malicious code on the client-side. |
Source: 3.39..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://file-connection-all-ez.com/dive-into-the-i... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. It also attempts to redirect the user to a suspicious domain and collects sensitive information like screen size and device information. These behaviors are highly indicative of malicious intent, likely for phishing or other malicious purposes. |
Source: 1.37..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://kerijigobiwut.poletofuti.com/6612345172723... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and aggressive DOM manipulation. The script imports a remote script, which could potentially execute arbitrary code, and then sends a GET request to an external server if the 'bot' detection result is true. Additionally, the script dynamically generates an HTML form and submits it, which could be used for malicious purposes such as redirecting the user to a malicious website. Overall, the combination of these behaviors suggests a high-risk script that should be further investigated. |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz | HTTP Parser: No favicon |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz | HTTP Parser: No favicon |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz | HTTP Parser: No favicon |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz | HTTP Parser: No favicon |
Source: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz | HTTP Parser: No favicon |
Source: unknown | HTTPS traffic detected: 142.250.9.105:443 -> 192.168.2.6:49710 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.69.67:443 -> 192.168.2.6:49712 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.69.67:443 -> 192.168.2.6:49711 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.6:49713 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.18.94.41:443 -> 192.168.2.6:49722 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.18.95.41:443 -> 192.168.2.6:49725 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.206.7:443 -> 192.168.2.6:49726 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.18.95.41:443 -> 192.168.2.6:49729 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 188.72.236.249:443 -> 192.168.2.6:49747 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.6:49750 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.6:49752 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.6:49759 version: TLS 1.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.215 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.125.21.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.191.45.158 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-full-version: "134.0.6998.36"sec-ch-ua-arch: "x86"sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-model: ""sec-ch-ua-bitness: "64"sec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=92eb32750cf9dab9 HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua-platform: "Windows"sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-mobile: ?0sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "134.0.6998.36"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua-platform-version: "10.0.0"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz&__cf_chl_rt_tk=rxBEHBMCIovLp0YugJxo0lBCB1oUhRC92UQR8wyouIg-1744381986-1.0.1.1-TBNIjGLN7TtVdslL1yKNjSfqhwnDUp22gGkVKycdm3QAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua-platform: "Windows"sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-mobile: ?0sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "134.0.6998.36"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua-platform-version: "10.0.0"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuzAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/b/580ba44007a6/api.js?onload=cvpQy6&render=explicit HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveOrigin: https://kerijigobiwut.poletofuti.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua-platform: "Windows"sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-mobile: ?0sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "134.0.6998.36"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua-platform-version: "10.0.0"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuzAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/995gw/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/new/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/936337903:1744380938:oR-9-m3aw6V2rO4pwtzAs27eAHzLKpxtC10gpunltXY/92eb32750cf9dab9/otVwIVXPW6j3s72PdKM811TjniWMJk5hJYqmkNsF2PY-1744381986-1.2.1.1-ICRpsc7r4R.aCngPsV4ljYutw_LC8jT7s.F0dLxmq9kxEvI6W8Da4dffdmSzzcrH HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=92eb328b2adbbf64&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/995gw/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/995gw/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1778400508:1744381001:XGiTuYOGW6wpFRHUnkWBsJFraewXm8b4sQE_vjD9Emg/92eb328b2adbbf64/6lryQLcJN1NfweLOBJVy36cTqkRm6XAhjMTZ2JSCJRk-1744381989-1.1.1.1-yjH.9VpUY5zWzTkqrumR3OqAmQES5brs55.pPHyRIxKSDww86cZfIzqwG3rBh3EL HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/pat/92eb328b2adbbf64/1744381991009/70a6cf2a69bd23dcc28381f1c6477935d71cc457cff60721cfe4f53163aa73e0/vO8IGsqIx1DCPwV HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/995gw/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/d/92eb328b2adbbf64/1744381991010/hKGTnbzwxdsmpB0 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/995gw/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/d/92eb328b2adbbf64/1744381991010/hKGTnbzwxdsmpB0 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1778400508:1744381001:XGiTuYOGW6wpFRHUnkWBsJFraewXm8b4sQE_vjD9Emg/92eb328b2adbbf64/6lryQLcJN1NfweLOBJVy36cTqkRm6XAhjMTZ2JSCJRk-1744381989-1.1.1.1-yjH.9VpUY5zWzTkqrumR3OqAmQES5brs55.pPHyRIxKSDww86cZfIzqwG3rBh3EL HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1778400508:1744381001:XGiTuYOGW6wpFRHUnkWBsJFraewXm8b4sQE_vjD9Emg/92eb328b2adbbf64/6lryQLcJN1NfweLOBJVy36cTqkRm6XAhjMTZ2JSCJRk-1744381989-1.1.1.1-yjH.9VpUY5zWzTkqrumR3OqAmQES5brs55.pPHyRIxKSDww86cZfIzqwG3rBh3EL HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/936337903:1744380938:oR-9-m3aw6V2rO4pwtzAs27eAHzLKpxtC10gpunltXY/92eb32750cf9dab9/otVwIVXPW6j3s72PdKM811TjniWMJk5hJYqmkNsF2PY-1744381986-1.2.1.1-ICRpsc7r4R.aCngPsV4ljYutw_LC8jT7s.F0dLxmq9kxEvI6W8Da4dffdmSzzcrH HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua-platform: "Windows"sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-mobile: ?0sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "134.0.6998.36"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua-platform-version: "10.0.0"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuz&__cf_chl_tk=rxBEHBMCIovLp0YugJxo0lBCB1oUhRC92UQR8wyouIg-1744381986-1.0.1.1-TBNIjGLN7TtVdslL1yKNjSfqhwnDUp22gGkVKycdm3QAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: cf_clearance=43dvR2GOpyqnl0k8cUMRGtXgMTub3n0HojWrSyZJau4-1744382005-1.2.1.1-3SWNz_IyzUVzbkwM65TiZ4b7cPDaBy.ibuxwmXKIa7hcsU_ilauwtsUEk2RvBTfiUN62WVKOCtTNYJbU4pnRbrgqnENzt0Be6MuhMwi2vUDX_BdSdCRpCoeMsFifJxvwR22r97V5XjpKoB1EGt1uuwpcB4DDFzp4j6LfsC3EJv7tW1VK7tGnwvg9ArHwvkl.uOe31kPBMNEGif3.O1t3JdDuPA15ayAL7rF7q5PAkrMdsvbtEzIkGLkZ5FWC6poDnbqrv4f3l.zv2i7OIoKJ4xVg6AK7n3Ngu4gxG42.pCr1CRE.nx9Tvkxr.J1oC6TRtul5HysC0MN5bcxfy3QRCpetgpaWjZMT8XYDjz3ywjyw3wABW6yqhhrR7uCIRafG |
Source: global traffic | HTTP traffic detected: GET /b.js HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-aliveOrigin: https://kerijigobiwut.poletofuti.comsec-ch-ua-platform: "Windows"sec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-mobile: ?0sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "134.0.6998.36"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua-platform-version: "10.0.0"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuzAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: cf_clearance=43dvR2GOpyqnl0k8cUMRGtXgMTub3n0HojWrSyZJau4-1744382005-1.2.1.1-3SWNz_IyzUVzbkwM65TiZ4b7cPDaBy.ibuxwmXKIa7hcsU_ilauwtsUEk2RvBTfiUN62WVKOCtTNYJbU4pnRbrgqnENzt0Be6MuhMwi2vUDX_BdSdCRpCoeMsFifJxvwR22r97V5XjpKoB1EGt1uuwpcB4DDFzp4j6LfsC3EJv7tW1VK7tGnwvg9ArHwvkl.uOe31kPBMNEGif3.O1t3JdDuPA15ayAL7rF7q5PAkrMdsvbtEzIkGLkZ5FWC6poDnbqrv4f3l.zv2i7OIoKJ4xVg6AK7n3Ngu4gxG42.pCr1CRE.nx9Tvkxr.J1oC6TRtul5HysC0MN5bcxfy3QRCpetgpaWjZMT8XYDjz3ywjyw3wABW6yqhhrR7uCIRafG; _subid=19fo3tg69ff21; 4ec93=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1wic3RyZWFtc1wiOntcIjg5NFwiOjE3NDQzODIwMDYsXCIxMTM2XCI6MTc0NDM4MjAwNn0sXCJjYW1wYWlnbnNcIjp7XCI1M1wiOjE3NDQzODIwMDYsXCIyXCI6MTc0NDM4MjAwNn0sXCJ0aW1lXCI6MTc0NDM4MjAwNn0ifQ.ENmVGVs9PCgEpEXIEHAPEJLXw7jZUfbvrDCalGfad-M; 936d96e1s2=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoiMTEzNiJ9.6cKp7l_MULsZiDIjlRYwZqRbj9sHfrWZ9WjHWumYbMs; 936d96e1s2ip=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoiXCI4OS4xODcuMTcxLjE2MVwiIn0.RCqEz6viMc_-oGcODII0KxAxf0LNkE3bik5zhCGBl9o; _token=uuid_19fo3tg69ff21_19fo3tg69ff2167f928366c4167.48309969 |
Source: global traffic | HTTP traffic detected: GET /mgo.php?q=free+audio+visualizer+templates&s1=19fo3tg69ff21 HTTP/1.1Host: kerijigobiwut.poletofuti.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-full-version: "134.0.6998.36"sec-ch-ua-arch: "x86"sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-model: ""sec-ch-ua-bitness: "64"sec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://kerijigobiwut.poletofuti.com/66123451727231077721876524?busudukepezifakijidurudizezuliginizinojedax=sigadogilidamuvusajikotenazaduluwulukajuxavodomazofifizosenejigirobasabulesewukugowizatologebisojuzoxazumesokolupinokajetikoputazuvigavarelejamobupaditezulolatenoxusomoxudamegarofusenewogopiworudejidu&utm_term=free+audio+visualizer+templates&joxiraripotavusajipejebiniwopebenilumojetipexesiwavejaxemukozegapowuzuvof=baduwowonavawevepixifowosamulopotolobopopivasexutatobodevadogijomuzujotojuvurekibakirisamonemomagijimirufakesudumogodevojuzAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: cf_clearance=43dvR2GOpyqnl0k8cUMRGtXgMTub3n0HojWrSyZJau4-1744382005-1.2.1.1-3SWNz_IyzUVzbkwM65TiZ4b7cPDaBy.ibuxwmXKIa7hcsU_ilauwtsUEk2RvBTfiUN62WVKOCtTNYJbU4pnRbrgqnENzt0Be6MuhMwi2vUDX_BdSdCRpCoeMsFifJxvwR22r97V5XjpKoB1EGt1uuwpcB4DDFzp4j6LfsC3EJv7tW1VK7tGnwvg9ArHwvkl.uOe31kPBMNEGif3.O1t3JdDuPA15ayAL7rF7q5PAkrMdsvbtEzIkGLkZ5FWC6poDnbqrv4f3l.zv2i7OIoKJ4xVg6AK7n3Ngu4gxG42.pCr1CRE.nx9Tvkxr.J1oC6TRtul5HysC0MN5bcxfy3QRCpetgpaWjZMT8XYDjz3ywjyw3wABW6yqhhrR7uCIRafG; _subid=19fo3tg69ff21; 4ec93=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1wic3RyZWFtc1wiOntcIjg5NFwiOjE3NDQzODIwMDYsXCIxMTM2XCI6MTc0NDM4MjAwNn0sXCJjYW1wYWlnbnNcIjp7XCI1M1wiOjE3NDQzODIwMDYsXCIyXCI6MTc0NDM4MjAwNn0sXCJ0aW1lXCI6MTc0NDM4MjAwNn0ifQ.ENmVGVs9PCgEpEXIEHAPEJLXw7jZUfbvrDCalGfad-M; 936d96e1s2=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoiMTEzNiJ9.6cKp7l_MULsZiDIjlRYwZqRbj9sHfrWZ9WjHWumYbMs; 936d96e1s2ip=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoiXCI4OS4xODcuMTcxLjE2MVwi |