Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://usdtmen.com

Overview

General Information

Sample URL:https://usdtmen.com
Analysis ID:756100
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

HTML body contains low number of good links
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://usdtmen.com/ MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 3268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,2961118636078509660,12337485403736736407,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://usdtmen.com/index/order/index.htmlHTTP Parser: Number of links: 1
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: HTML title missing
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: HTML title missing
Source: https://usdtmen.com/index/order/index.htmlHTTP Parser: HTML title missing
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: No <meta name="author".. found
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: No <meta name="author".. found
Source: https://usdtmen.com/index/order/index.htmlHTTP Parser: No <meta name="author".. found
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://usdtmen.com/index/passport/login.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://usdtmen.com/index/order/index.htmlHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49781 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49890 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49892 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49915 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49914 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:50018 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:50020 version: TLS 1.2
Source: unknownDNS traffic detected: queries for: usdtmen.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49982
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49973
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49972
Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49972 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50018
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50021
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50020
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50021 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
Source: unknownNetwork traffic detected: HTTP traffic on port 49973 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50007 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49963 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50007
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50008
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50020 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50008 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49982 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49987 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 49903 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49888 -> 443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /index/passport/logout.html HTTP/1.1Host: usdtmen.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /index/passport/login.html HTTP/1.1Host: usdtmen.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/weui.css HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/bootstrap.min.css HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/iconfont.css HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/common.css HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/zepto.min.js HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/jquery.min.js HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/weui.min.js HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /layer3.1/layer.js HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/common.js HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/en-us.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/es-es.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /layer3.1/theme/default/layer.css?v=3.1.1 HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/logo.cba20b1b.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/username_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/bg1.6c9f941a.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/password_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/pt-pt.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/fr.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/ar-ae.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/en-us.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/ko.jpg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/bootstrap.min.css.map HTTP/1.1Host: usdtmen.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/es-es.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/pt-pt.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/fr.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/ar-ae.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/ko.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/logo.cba20b1b.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/username_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/password_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /index/index/index.html HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1sec-ch-ua-platform: "Android"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://usdtmen.com/index/passport/login.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/card.8c0955e2.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/image/common.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/transfer_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/withdraw_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/records2.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/menu.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/portrait.jpeg HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/head.b8e5d31e.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav1.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav3.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/menu.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav2.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav4.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav5.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav6.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav7.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav8.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/nav9.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/deposit_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/en-us.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:46 GMTIf-None-Match: "63157702-102c"
Source: global trafficHTTP traffic detected: GET /image/portrait.jpeg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/viplevel_icon.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/records1.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/bootstrap.min.css.map HTTP/1.1Host: usdtmen.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/es-es.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:52 GMTIf-None-Match: "63157708-a97a"
Source: global trafficHTTP traffic detected: GET /image/pt-pt.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:13:08 GMTIf-None-Match: "63157754-f282"
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/fr.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:57 GMTIf-None-Match: "6315770d-760"
Source: global trafficHTTP traffic detected: GET /image/ko.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:10 GMTIf-None-Match: "6315771a-1031a"
Source: global trafficHTTP traffic detected: GET /image/ar-ae.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:10:54 GMTIf-None-Match: "631576ce-ef01"
Source: global trafficHTTP traffic detected: GET /image/head.b8e5d31e.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav1.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav2.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav3.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav4.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav5.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav6.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav7.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav8.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/nav9.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/deposit_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/withdraw_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/transfer_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/viplevel_icon.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/records2.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /image/records1.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.com
Source: global trafficHTTP traffic detected: GET /index/news/about.html HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1sec-ch-ua-platform: "Android"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://usdtmen.com/index/index/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/icons8-tether-48.png HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36sec-ch-ua-platform: "Android"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usdtmen.com/index/news/about.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/menu.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:19 GMTIf-None-Match: "63157723-597"
Source: global trafficHTTP traffic detected: GET /image/bootstrap.min.css.map HTTP/1.1Host: usdtmen.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/portrait.jpeg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:13:04 GMTIf-None-Match: "63157750-3ce5"
Source: global trafficHTTP traffic detected: GET /image/en-us.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:46 GMTIf-None-Match: "63157702-102c"
Source: global trafficHTTP traffic detected: GET /image/es-es.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:52 GMTIf-None-Match: "63157708-a97a"
Source: global trafficHTTP traffic detected: GET /image/pt-pt.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:13:08 GMTIf-None-Match: "63157754-f282"
Source: global trafficHTTP traffic detected: GET /image/ar-ae.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:10:54 GMTIf-None-Match: "631576ce-ef01"
Source: global trafficHTTP traffic detected: GET /index/order/index.html HTTP/1.1Host: usdtmen.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?1sec-ch-ua-platform: "Android"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Linux; Android 9.0; SAMSUNG SM-F900U Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Mobile Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://usdtmen.com/index/news/about.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/fr.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:57 GMTIf-None-Match: "6315770d-760"
Source: global trafficHTTP traffic detected: GET /image/bootstrap.min.css.map HTTP/1.1Host: usdtmen.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheSec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: think_var=en-us; PHPSESSID=936v1rpvj2sh4tcp5er972br82
Source: global trafficHTTP traffic detected: GET /image/ko.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:10 GMTIf-None-Match: "6315771a-1031a"
Source: global trafficHTTP traffic detected: GET /image/head.b8e5d31e.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:11:59 GMTIf-None-Match: "6315770f-31c0"
Source: global trafficHTTP traffic detected: GET /image/nav1.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:21 GMTIf-None-Match: "63157725-450"
Source: global trafficHTTP traffic detected: GET /image/nav3.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:29 GMTIf-None-Match: "6315772d-253"
Source: global trafficHTTP traffic detected: GET /image/nav2.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:23 GMTIf-None-Match: "63157727-299"
Source: global trafficHTTP traffic detected: GET /image/nav4.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:34 GMTIf-None-Match: "63157732-1198"
Source: global trafficHTTP traffic detected: GET /image/nav5.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:39 GMTIf-None-Match: "63157737-3eb"
Source: global trafficHTTP traffic detected: GET /image/nav7.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:54 GMTIf-None-Match: "63157746-121b"
Source: global trafficHTTP traffic detected: GET /image/nav6.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:46 GMTIf-None-Match: "6315773e-450"
Source: global trafficHTTP traffic detected: GET /image/nav8.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: usdtmen.comIf-Modified-Since: Mon, 05 Sep 2022 04:12:56 GMTIf-None-Match: "63157748-d29"
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 29 Nov 2022 15:35:41 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encoding
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 29 Nov 2022 15:36:25 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encoding
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 29 Nov 2022 15:36:59 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encoding
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 29 Nov 2022 15:37:06 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encoding
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=YES+srp.gws-20210525-0-RC1.de+FX+704
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49781 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49890 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49892 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49915 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:49914 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:50018 version: TLS 1.2
Source: unknownHTTPS traffic detected: 154.211.96.136:443 -> 192.168.2.2:50020 version: TLS 1.2
Source: classification engineClassification label: clean1.win@28/0@15/8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://usdtmen.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,2961118636078509660,12337485403736736407,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,2961118636078509660,12337485403736736407,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://usdtmen.com1%VirustotalBrowse
https://usdtmen.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://usdtmen.com/layer3.1/layer.js0%Avira URL Cloudsafe
https://usdtmen.com/image/nav1.png0%Avira URL Cloudsafe
https://usdtmen.com/image/fr.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/bg1.6c9f941a.png0%Avira URL Cloudsafe
https://usdtmen.com/image/records1.png0%Avira URL Cloudsafe
https://usdtmen.com/index/passport/logout.html0%Avira URL Cloudsafe
https://usdtmen.com/image/portrait.jpeg0%Avira URL Cloudsafe
https://usdtmen.com/image/weui.min.js0%Avira URL Cloudsafe
https://usdtmen.com/image/viplevel_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/withdraw_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/nav2.png0%Avira URL Cloudsafe
https://usdtmen.com/layer3.1/theme/default/layer.css?v=3.1.10%Avira URL Cloudsafe
https://usdtmen.com/image/records2.png0%Avira URL Cloudsafe
https://usdtmen.com/image/nav3.png0%Avira URL Cloudsafe
https://usdtmen.com/image/common.css0%Avira URL Cloudsafe
https://usdtmen.com/image/menu.png0%Avira URL Cloudsafe
https://beacons2.gvt2.com/domainreliability/upload-nel0%Avira URL Cloudsafe
https://usdtmen.com/favicon.ico0%Avira URL Cloudsafe
https://usdtmen.com/image/zepto.min.js0%Avira URL Cloudsafe
https://usdtmen.com/image/nav4.png0%Avira URL Cloudsafe
https://usdtmen.com/image/weui.css0%Avira URL Cloudsafe
https://usdtmen.com/0%Avira URL Cloudsafe
https://usdtmen.com/image/iconfont.css0%Avira URL Cloudsafe
https://usdtmen.com/image/nav5.png0%Avira URL Cloudsafe
https://usdtmen.com/image/jquery.min.js0%Avira URL Cloudsafe
https://usdtmen.com/image/es-es.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/transfer_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/head.b8e5d31e.png0%Avira URL Cloudsafe
https://usdtmen.com/image/password_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/bootstrap.min.css0%Avira URL Cloudsafe
https://usdtmen.com/image/card.8c0955e2.png0%Avira URL Cloudsafe
https://usdtmen.com/image/deposit_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/nav6.png0%Avira URL Cloudsafe
https://usdtmen.com/image/icons8-tether-48.png0%Avira URL Cloudsafe
https://usdtmen.com/image/common.js0%Avira URL Cloudsafe
https://usdtmen.com/image/ko.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/username_icon.png0%Avira URL Cloudsafe
https://usdtmen.com/image/bootstrap.min.css.map0%Avira URL Cloudsafe
https://usdtmen.com/image/nav7.png0%Avira URL Cloudsafe
https://usdtmen.com/image/logo.cba20b1b.png0%Avira URL Cloudsafe
https://usdtmen.com/image/ar-ae.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/pt-pt.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/nav9.png0%Avira URL Cloudsafe
https://usdtmen.com/image/en-us.jpg0%Avira URL Cloudsafe
https://usdtmen.com/image/nav8.png0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.184.237
truefalse
    high
    usdtmen.com
    154.211.96.136
    truefalse
      unknown
      www.google.com
      142.250.185.132
      truefalse
        high
        beacons2.gvt2.com
        216.239.38.117
        truefalse
          unknown
          clients.l.google.com
          142.250.186.110
          truefalse
            high
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://usdtmen.com/index/order/index.htmlfalse
                unknown
                https://usdtmen.com/layer3.1/layer.jsfalse
                • Avira URL Cloud: safe
                unknown
                https://usdtmen.com/index/index/index.htmlfalse
                  unknown
                  https://usdtmen.com/index/news/about.htmlfalse
                    unknown
                    https://usdtmen.com/image/nav1.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/fr.jpgfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/bg1.6c9f941a.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/records1.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/index/passport/logout.htmlfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/portrait.jpegfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/weui.min.jsfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/viplevel_icon.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/withdraw_icon.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/nav2.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/layer3.1/theme/default/layer.css?v=3.1.1false
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/image/records2.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://usdtmen.com/index/passport/login.htmlfalse
                      unknown
                      https://usdtmen.com/image/nav3.pngfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://usdtmen.com/image/common.cssfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://usdtmen.com/image/menu.pngfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://beacons2.gvt2.com/domainreliability/upload-nelfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://usdtmen.com/index/passport/login.htmlfalse
                        unknown
                        https://usdtmen.com/favicon.icofalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/zepto.min.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/nav4.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/weui.cssfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/false
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/iconfont.cssfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/nav5.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/jquery.min.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/es-es.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/transfer_icon.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://usdtmen.com/image/password_icon.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                          high
                          https://usdtmen.com/image/head.b8e5d31e.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/bootstrap.min.cssfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/card.8c0955e2.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/deposit_icon.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/nav6.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/icons8-tether-48.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/common.jsfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/ko.jpgfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/image/username_icon.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://usdtmen.com/index/index/index.htmlfalse
                            unknown
                            https://usdtmen.com/image/bootstrap.min.css.mapfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://usdtmen.com/index/news/about.htmlfalse
                              unknown
                              https://accounts.google.com/domainreliability/uploadfalse
                                high
                                https://usdtmen.com/image/nav7.pngfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://usdtmen.com/image/logo.cba20b1b.pngfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://usdtmen.com/image/ar-ae.jpgfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://usdtmen.com/image/pt-pt.jpgfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://usdtmen.com/index/order/index.htmlfalse
                                  unknown
                                  https://usdtmen.com/image/nav9.pngfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://usdtmen.com/image/en-us.jpgfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://usdtmen.com/image/nav8.pngfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    154.211.96.136
                                    usdtmen.comSeychelles
                                    134705ITACE-AS-APItaceInternationalLimitedHKfalse
                                    142.250.185.100
                                    unknownUnited States
                                    15169GOOGLEUSfalse
                                    239.255.255.250
                                    unknownReserved
                                    unknownunknownfalse
                                    142.250.184.237
                                    accounts.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.186.110
                                    clients.l.google.comUnited States
                                    15169GOOGLEUSfalse
                                    172.217.16.196
                                    unknownUnited States
                                    15169GOOGLEUSfalse
                                    216.239.38.117
                                    beacons2.gvt2.comUnited States
                                    15169GOOGLEUSfalse
                                    IP
                                    127.0.0.1
                                    Joe Sandbox Version:36.0.0 Rainbow Opal
                                    Analysis ID:756100
                                    Start date and time:2022-11-29 16:34:35 +01:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:0h 4m 5s
                                    Hypervisor based Inspection enabled:false
                                    Report type:light
                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                    Sample URL:https://usdtmen.com
                                    Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                    Number of analysed new started processes analysed:7
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • HDC enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:CLEAN
                                    Classification:clean1.win@28/0@15/8
                                    EGA Information:Failed
                                    HDC Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    • Exclude process from analysis (whitelisted): RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                                    • TCP Packets have been reduced to 100
                                    • Excluded IPs from analysis (whitelisted): 142.250.186.67, 34.104.35.123, 142.250.186.138, 172.217.18.10, 142.250.185.234, 142.250.185.138, 142.250.181.234, 172.217.16.202, 142.250.185.202, 216.58.212.138, 142.250.185.106, 172.217.16.138, 142.250.184.234, 142.250.185.74, 142.250.184.202, 142.250.186.42, 142.250.186.170, 142.250.185.170, 142.250.185.227, 142.250.186.106, 172.217.18.106, 142.250.74.202, 142.250.186.74, 216.58.212.170
                                    • Excluded domains from analysis (whitelisted): client.wns.windows.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, login.live.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, cdn.onenote.net
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    No created / dropped files found
                                    No static file info
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 29, 2022 16:35:08.933305025 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:08.933347940 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:08.933442116 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:08.933768034 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:08.933856010 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:08.933995008 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:08.934210062 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:08.934231043 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:08.935841084 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:08.935878038 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.023745060 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.023804903 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.023932934 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.024252892 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.024288893 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.048182011 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.056142092 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.056159973 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.057837009 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.057976007 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.065637112 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.072374105 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.072432041 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.072983027 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.073096037 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.074866056 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.074960947 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.357707024 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.357788086 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.357827902 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.357842922 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.358078957 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.358206034 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.358263016 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.358475924 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.358495951 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.358618975 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.393388987 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.393544912 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.393601894 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.393650055 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.393717051 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.394799948 CET49720443192.168.2.2142.250.186.110
                                    Nov 29, 2022 16:35:09.394829988 CET44349720142.250.186.110192.168.2.2
                                    Nov 29, 2022 16:35:09.398066998 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.398101091 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.405095100 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.405164957 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.405186892 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.405414104 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.405481100 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.407345057 CET49719443192.168.2.2142.250.184.237
                                    Nov 29, 2022 16:35:09.407375097 CET44349719142.250.184.237192.168.2.2
                                    Nov 29, 2022 16:35:09.803222895 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.803695917 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.803733110 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.805032015 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.805135012 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.807235956 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.807254076 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.807353973 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.807840109 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:09.807868004 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:09.847151041 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.530600071 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:10.530754089 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:10.530853033 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.531311035 CET49722443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.531347036 CET44349722154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:10.535629034 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.535711050 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:10.535847902 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.536159992 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:10.536194086 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.066715002 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.066766024 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.066839933 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.067223072 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.067240000 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.130240917 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.130584002 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.130609989 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.131877899 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.131947041 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.134362936 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.134380102 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.134484053 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.174340963 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.174376011 CET44349726172.217.16.196192.168.2.2
                                    Nov 29, 2022 16:35:12.214277983 CET49726443192.168.2.2172.217.16.196
                                    Nov 29, 2022 16:35:12.652659893 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.655206919 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:12.655265093 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.655854940 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.683619022 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:12.683653116 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.683898926 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:12.684128046 CET49724443192.168.2.2154.211.96.136
                                    Nov 29, 2022 16:35:12.684144020 CET44349724154.211.96.136192.168.2.2
                                    Nov 29, 2022 16:35:13.461122036 CET44349724154.211.96.136192.168.2.2
                                    TimestampSource PortDest PortSource IPDest IP
                                    Nov 29, 2022 16:35:08.845860958 CET5643753192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:08.849659920 CET5917053192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:08.852261066 CET6017453192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:08.867503881 CET53591701.1.1.1192.168.2.2
                                    Nov 29, 2022 16:35:08.870886087 CET53601741.1.1.1192.168.2.2
                                    Nov 29, 2022 16:35:09.022564888 CET53564371.1.1.1192.168.2.2
                                    Nov 29, 2022 16:35:11.992185116 CET6500953192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:12.010351896 CET53650091.1.1.1192.168.2.2
                                    Nov 29, 2022 16:35:12.015737057 CET6037253192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:12.039489985 CET53603721.1.1.1192.168.2.2
                                    Nov 29, 2022 16:35:38.380709887 CET5974453192.168.2.21.1.1.1
                                    Nov 29, 2022 16:35:38.401396036 CET53597441.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:09.737880945 CET6425853192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:10.133202076 CET53642581.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:10.142847061 CET5310253192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:10.161789894 CET53531021.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:10.282659054 CET5397053192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:10.300344944 CET53539701.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:11.673815012 CET6036653192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:11.844702959 CET53603661.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:12.050575018 CET6228853192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:12.070384026 CET53622881.1.1.1192.168.2.2
                                    Nov 29, 2022 16:36:12.074632883 CET5355553192.168.2.21.1.1.1
                                    Nov 29, 2022 16:36:12.092705011 CET53535551.1.1.1192.168.2.2
                                    Nov 29, 2022 16:37:10.435528040 CET6385953192.168.2.21.1.1.1
                                    Nov 29, 2022 16:37:10.455703974 CET53638591.1.1.1192.168.2.2
                                    Nov 29, 2022 16:37:12.099045992 CET5186053192.168.2.21.1.1.1
                                    Nov 29, 2022 16:37:12.117491961 CET53518601.1.1.1192.168.2.2
                                    Nov 29, 2022 16:37:12.119719982 CET5209053192.168.2.21.1.1.1
                                    Nov 29, 2022 16:37:12.138839960 CET53520901.1.1.1192.168.2.2
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Nov 29, 2022 16:35:08.845860958 CET192.168.2.21.1.1.10xc52dStandard query (0)usdtmen.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:08.849659920 CET192.168.2.21.1.1.10xa4b2Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:08.852261066 CET192.168.2.21.1.1.10xca57Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:11.992185116 CET192.168.2.21.1.1.10x6cc9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:12.015737057 CET192.168.2.21.1.1.10xcf24Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:38.380709887 CET192.168.2.21.1.1.10x28c5Standard query (0)usdtmen.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:09.737880945 CET192.168.2.21.1.1.10x927dStandard query (0)usdtmen.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.142847061 CET192.168.2.21.1.1.10x4fddStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.282659054 CET192.168.2.21.1.1.10x1ec8Standard query (0)beacons2.gvt2.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:11.673815012 CET192.168.2.21.1.1.10x963dStandard query (0)usdtmen.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:12.050575018 CET192.168.2.21.1.1.10x8bddStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:12.074632883 CET192.168.2.21.1.1.10x25e6Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:10.435528040 CET192.168.2.21.1.1.10x59a3Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:12.099045992 CET192.168.2.21.1.1.10x7e09Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:12.119719982 CET192.168.2.21.1.1.10x805cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Nov 29, 2022 16:35:08.867503881 CET1.1.1.1192.168.2.20xa4b2No error (0)accounts.google.com142.250.184.237A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:08.870886087 CET1.1.1.1192.168.2.20xca57No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                    Nov 29, 2022 16:35:08.870886087 CET1.1.1.1192.168.2.20xca57No error (0)clients.l.google.com142.250.186.110A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:09.022564888 CET1.1.1.1192.168.2.20xc52dNo error (0)usdtmen.com154.211.96.136A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:12.010351896 CET1.1.1.1192.168.2.20x6cc9No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:12.039489985 CET1.1.1.1192.168.2.20xcf24No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:35:38.401396036 CET1.1.1.1192.168.2.20x28c5No error (0)usdtmen.com154.211.96.136A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.133202076 CET1.1.1.1192.168.2.20x927dNo error (0)usdtmen.com154.211.96.136A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.161789894 CET1.1.1.1192.168.2.20x4fddNo error (0)accounts.google.com142.250.184.237A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.300344944 CET1.1.1.1192.168.2.20x1ec8No error (0)beacons2.gvt2.com216.239.38.117A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.300344944 CET1.1.1.1192.168.2.20x1ec8No error (0)beacons2.gvt2.com216.239.32.117A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.300344944 CET1.1.1.1192.168.2.20x1ec8No error (0)beacons2.gvt2.com216.239.34.117A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:10.300344944 CET1.1.1.1192.168.2.20x1ec8No error (0)beacons2.gvt2.com216.239.36.117A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:11.844702959 CET1.1.1.1192.168.2.20x963dNo error (0)usdtmen.com154.211.96.136A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:12.070384026 CET1.1.1.1192.168.2.20x8bddNo error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:36:12.092705011 CET1.1.1.1192.168.2.20x25e6No error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:10.455703974 CET1.1.1.1192.168.2.20x59a3No error (0)accounts.google.com142.250.186.45A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:12.117491961 CET1.1.1.1192.168.2.20x7e09No error (0)www.google.com172.217.18.100A (IP address)IN (0x0001)false
                                    Nov 29, 2022 16:37:12.138839960 CET1.1.1.1192.168.2.20x805cNo error (0)www.google.com172.217.16.132A (IP address)IN (0x0001)false
                                    • clients2.google.com
                                    • accounts.google.com
                                    • usdtmen.com
                                    • https:
                                    • beacons2.gvt2.com

                                    Click to jump to process

                                    Target ID:0
                                    Start time:16:35:04
                                    Start date:29/11/2022
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://usdtmen.com/
                                    Imagebase:0x7ff600460000
                                    File size:2852640 bytes
                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    Target ID:1
                                    Start time:16:35:06
                                    Start date:29/11/2022
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,2961118636078509660,12337485403736736407,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                    Imagebase:0x7ff600460000
                                    File size:2852640 bytes
                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    No disassembly