Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://bit.ly/3TRQuxO

Overview

General Information

Sample URL:https://bit.ly/3TRQuxO
Analysis ID:756304
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 5088 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1612 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6068 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://bit.ly/3TRQuxOSlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /3TRQuxO HTTP/1.1Host: bit.lyConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /Sa09wy4x7ub HTTP/1.1Host: dqb4v.app.linkConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA HTTP/1.1Host: 3kjarwa.associatesuitcase.co.inConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: mal48.win@30/0@8/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://bit.ly/3TRQuxO3%VirustotalBrowse
https://bit.ly/3TRQuxO0%Avira URL Cloudsafe
https://bit.ly/3TRQuxO100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://3kjarwa.associatesuitcase.co.in/usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA0%Avira URL Cloudsafe
https://thetrueline-life.world/?a=1nrK&c=d&s=931%VirustotalBrowse
http://thetrueline-life.world/?a=1nrK&c=d&s=931%VirustotalBrowse
http://thetrueline-life.world/?a=1nrK&c=d&s=930%Avira URL Cloudsafe
https://thetrueline-life.world/?a=1nrK&c=d&s=930%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
3kjarwa.associatesuitcase.co.in
84.21.172.16
truefalse
    unknown
    thetrueline-life.world
    213.227.155.34
    truefalse
      unknown
      accounts.google.com
      172.217.168.45
      truefalse
        high
        bit.ly
        67.199.248.11
        truefalse
          high
          dqb4v.app.link
          18.65.39.84
          truefalse
            high
            www.google.com
            172.217.168.68
            truefalse
              high
              clients.l.google.com
              142.250.203.110
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    http://3kjarwa.associatesuitcase.co.in/usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAAfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://bit.ly/3TRQuxOfalse
                      high
                      https://dqb4v.app.link/Sa09wy4x7ubfalse
                        high
                        https://thetrueline-life.world/?a=1nrK&c=d&s=93false
                        • 1%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        http://thetrueline-life.world/?a=1nrK&c=d&s=93false
                        • 1%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                          high
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          18.65.39.84
                          dqb4v.app.linkUnited States
                          3MIT-GATEWAYSUSfalse
                          142.250.203.110
                          clients.l.google.comUnited States
                          15169GOOGLEUSfalse
                          172.217.168.68
                          www.google.comUnited States
                          15169GOOGLEUSfalse
                          84.21.172.16
                          3kjarwa.associatesuitcase.co.inGermany
                          30823COMBAHTONcombahtonGmbHDEfalse
                          172.217.168.45
                          accounts.google.comUnited States
                          15169GOOGLEUSfalse
                          239.255.255.250
                          unknownReserved
                          unknownunknownfalse
                          213.227.155.34
                          thetrueline-life.worldNetherlands
                          60781LEASEWEB-NL-AMS-01NetherlandsNLfalse
                          67.199.248.11
                          bit.lyUnited States
                          396982GOOGLE-PRIVATE-CLOUDUSfalse
                          IP
                          192.168.2.1
                          127.0.0.1
                          Joe Sandbox Version:36.0.0 Rainbow Opal
                          Analysis ID:756304
                          Start date and time:2022-11-30 00:22:10 +01:00
                          Joe Sandbox Product:CloudBasic
                          Overall analysis duration:0h 5m 0s
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:browseurl.jbs
                          Sample URL:https://bit.ly/3TRQuxO
                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                          Number of analysed new started processes analysed:10
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • HDC enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Detection:MAL
                          Classification:mal48.win@30/0@8/10
                          EGA Information:Failed
                          HDC Information:Failed
                          HCA Information:
                          • Successful, ratio: 100%
                          • Number of executed functions: 0
                          • Number of non-executed functions: 0
                          • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                          • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                          • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size getting too big, too many NtWriteVirtualMemory calls found.
                          No simulations
                          No context
                          No context
                          No context
                          No context
                          No context
                          No created / dropped files found
                          No static file info
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2022 00:23:14.278610945 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.278671980 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.278745890 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.279064894 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.279099941 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.279169083 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.280710936 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.280751944 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.280879974 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.280895948 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.383877993 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.393577099 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.439941883 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.443464041 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.502834082 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.502877951 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.504590988 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.504733086 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.504812956 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.504841089 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.508227110 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.508390903 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.508559942 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.508651972 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.508658886 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.594691992 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.594749928 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.594831944 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.595304012 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.595329046 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.639935970 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.664751053 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.782946110 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.857853889 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.857903004 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.861604929 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.861706972 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.861757994 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.981913090 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.352822065 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.352904081 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.353286028 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.353797913 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.353857994 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.354146957 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.354209900 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.354922056 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.354971886 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.355106115 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.355125904 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.355192900 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.355308056 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.355446100 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.355479002 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.390867949 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391006947 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.391041994 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391293049 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391377926 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.397468090 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.397510052 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.430311918 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430504084 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.430540085 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430723906 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430830956 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.440006971 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.440073013 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.452543020 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.452589035 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.478593111 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.478729963 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.513979912 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.514043093 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.683275938 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683331966 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.683413029 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683846951 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683861971 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.754347086 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.762408972 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.762443066 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.764111996 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.764247894 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.766701937 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.766716003 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.766838074 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.766997099 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.767007113 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.843724012 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.843790054 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.843878984 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.844238997 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.844284058 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.913541079 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.914004087 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.914033890 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.915328979 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.915437937 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.918338060 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.918354034 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.918459892 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.939975977 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.959441900 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.959569931 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.959696054 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.973498106 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.973529100 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:16.040000916 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:16.040033102 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:16.139988899 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:16.295927048 CET4971980192.168.2.784.21.172.16
                          Nov 30, 2022 00:23:16.323165894 CET804971984.21.172.16192.168.2.7
                          Nov 30, 2022 00:23:16.323278904 CET4971980192.168.2.784.21.172.16
                          Nov 30, 2022 00:23:16.326791048 CET4971980192.168.2.784.21.172.16
                          Nov 30, 2022 00:23:16.396615028 CET804971984.21.172.16192.168.2.7
                          Nov 30, 2022 00:23:16.587255001 CET804971984.21.172.16192.168.2.7
                          Nov 30, 2022 00:23:16.587341070 CET4971980192.168.2.784.21.172.16
                          Nov 30, 2022 00:23:16.588051081 CET4971980192.168.2.784.21.172.16
                          Nov 30, 2022 00:23:16.615300894 CET804971984.21.172.16192.168.2.7
                          Nov 30, 2022 00:23:16.631452084 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.656471014 CET8049720213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.656627893 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.660864115 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.686038017 CET8049720213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.686100960 CET8049720213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.694139004 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.694221973 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.694324970 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.694686890 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.694724083 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.782440901 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.811290979 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.811783075 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.811830044 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.813060045 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.813153028 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.815592051 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.815617085 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.815764904 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.822110891 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:16.822158098 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:16.940118074 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:17.019964933 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:17.020123959 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:17.020214081 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:17.020922899 CET49721443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:17.021018982 CET44349721213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.120485067 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.120573044 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.120745897 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.121756077 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.121839046 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.123944044 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.124015093 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.124123096 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.124914885 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.124957085 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.213359118 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.214005947 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.214076042 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.214507103 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.214576960 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.215177059 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.215209007 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.215864897 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.215913057 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.215981960 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.216011047 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.216253996 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.216274977 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.216674089 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.216696978 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.216850996 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.287652969 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.441828966 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.441989899 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:18.442130089 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.507955074 CET49722443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:18.508007050 CET44349722213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:25.901998043 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:25.902077913 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:25.902201891 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:27.904062033 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:27.904115915 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:27.904289961 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.904335022 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.905669928 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.905725002 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.905828953 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.906238079 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.906266928 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.968142033 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.980904102 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.980961084 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.982039928 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.985434055 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:27.985462904 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:27.985733986 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.102519989 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.102658033 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.102721930 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.102849007 CET49723443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.102890015 CET44349723213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.103295088 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.103312016 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.298793077 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.299010992 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.299094915 CET49728443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.299123049 CET44349728213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.299818039 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.299880028 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.299962044 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.300303936 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.300333977 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.359482050 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.359868050 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.359920979 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.361351013 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.375252962 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.375344038 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.375420094 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.375437975 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.375583887 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.440933943 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.615890026 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.616086006 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:28.616159916 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.616764069 CET49730443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:28.616791964 CET44349730213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:46.689285040 CET8049720213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:46.689671993 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.708493948 CET4972080192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.708991051 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.709059954 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.709155083 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.709546089 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.709621906 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.709705114 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.715296984 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.715348959 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.715570927 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.715626001 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.733820915 CET8049720213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.808378935 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.808686018 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.850249052 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.859221935 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.954447985 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.954477072 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.954762936 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.954811096 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.956149101 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.956857920 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.959479094 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.959518909 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.959743023 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.959925890 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:58.959968090 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:58.960213900 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.000214100 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.002217054 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.032601118 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.032629013 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.229420900 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.229532003 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.229667902 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.259089947 CET49749443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.259141922 CET44349749213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.259557009 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.259603024 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.458949089 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.459114075 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.459213018 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.822120905 CET49748443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.822175980 CET44349748213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.823191881 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.823293924 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.823410034 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.823697090 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.823729992 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.886945963 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.927288055 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.933614016 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.933645964 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.935308933 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.935967922 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.936012030 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.936194897 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:23:59.937230110 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:23:59.937262058 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:24:00.149509907 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:24:00.150136948 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:24:00.150250912 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:24:00.150887966 CET49750443192.168.2.7213.227.155.34
                          Nov 30, 2022 00:24:00.150919914 CET44349750213.227.155.34192.168.2.7
                          Nov 30, 2022 00:24:15.892724991 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:15.892803907 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.893016100 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:15.893275023 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:15.893309116 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.954989910 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.955518007 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:15.955538988 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.956617117 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.958808899 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:15.958853960 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:15.959067106 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:16.008677959 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:25.989553928 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:25.989700079 CET44349766172.217.168.68192.168.2.7
                          Nov 30, 2022 00:24:25.990088940 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:26.513012886 CET49766443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:24:26.513060093 CET44349766172.217.168.68192.168.2.7
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2022 00:23:14.152200937 CET5333653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.155282974 CET5100753192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.158768892 CET5051353192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.170192003 CET53533368.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:14.177088976 CET53505138.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:14.181938887 CET53510078.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.587124109 CET5828353192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:15.632625103 CET53582838.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.786753893 CET4951653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:15.804167032 CET53495168.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.979427099 CET6139253192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:16.294555902 CET53613928.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:16.597486973 CET6535653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:16.625588894 CET53653568.8.8.8192.168.2.7
                          Nov 30, 2022 00:24:15.864783049 CET5622453192.168.2.78.8.8.8
                          Nov 30, 2022 00:24:15.890614986 CET53562248.8.8.8192.168.2.7
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Nov 30, 2022 00:23:14.152200937 CET192.168.2.78.8.8.80x3b23Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.155282974 CET192.168.2.78.8.8.80x9d3aStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.158768892 CET192.168.2.78.8.8.80x55c3Standard query (0)bit.lyA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.587124109 CET192.168.2.78.8.8.80xe19cStandard query (0)dqb4v.app.linkA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.786753893 CET192.168.2.78.8.8.80xd206Standard query (0)www.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.979427099 CET192.168.2.78.8.8.80x42eeStandard query (0)3kjarwa.associatesuitcase.co.inA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.597486973 CET192.168.2.78.8.8.80x9095Standard query (0)thetrueline-life.worldA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:24:15.864783049 CET192.168.2.78.8.8.80x9e5aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Nov 30, 2022 00:23:14.170192003 CET8.8.8.8192.168.2.70x3b23No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.177088976 CET8.8.8.8192.168.2.70x55c3No error (0)bit.ly67.199.248.11A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.177088976 CET8.8.8.8192.168.2.70x55c3No error (0)bit.ly67.199.248.10A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.181938887 CET8.8.8.8192.168.2.70x9d3aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                          Nov 30, 2022 00:23:14.181938887 CET8.8.8.8192.168.2.70x9d3aNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.84A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.105A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.26A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.3A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.804167032 CET8.8.8.8192.168.2.70xd206No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.294555902 CET8.8.8.8192.168.2.70x42eeNo error (0)3kjarwa.associatesuitcase.co.in84.21.172.16A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.625588894 CET8.8.8.8192.168.2.70x9095No error (0)thetrueline-life.world213.227.155.34A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:24:15.890614986 CET8.8.8.8192.168.2.70x9e5aNo error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                          • accounts.google.com
                          • clients2.google.com
                          • bit.ly
                          • dqb4v.app.link
                          • thetrueline-life.world
                          • 3kjarwa.associatesuitcase.co.in
                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          0192.168.2.749713172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          1192.168.2.749711142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          10192.168.2.749748213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          11192.168.2.749750213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          12192.168.2.74971984.21.172.1680C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          Nov 30, 2022 00:23:16.326791048 CET463OUTGET /usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA HTTP/1.1
                          Host: 3kjarwa.associatesuitcase.co.in
                          Connection: keep-alive
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Accept-Encoding: gzip, deflate
                          Accept-Language: en-US,en;q=0.9
                          Nov 30, 2022 00:23:16.587255001 CET464INHTTP/1.1 302 Found
                          Date: Tue, 29 Nov 2022 23:23:16 GMT
                          Server: Apache/2.4.38 (Debian)
                          Access-Control-Allow-Origin: *
                          Set-Cookie: zcknrt_usdon=0; expires=Wed, 30-Nov-2022 23:23:16 GMT; Max-Age=86400; path=/
                          Location: http://thetrueline-life.world/?a=1nrK&c=d&s=93
                          Content-Length: 0
                          Connection: close
                          Content-Type: text/html; charset=UTF-8


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          13192.168.2.749720213.227.155.3480C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          Nov 30, 2022 00:23:16.660864115 CET465OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Accept-Encoding: gzip, deflate
                          Accept-Language: en-US,en;q=0.9
                          Nov 30, 2022 00:23:16.686100960 CET465INHTTP/1.1 301 Moved Permanently
                          Server: nginx/1.12.2
                          Date: Tue, 29 Nov 2022 23:23:16 GMT
                          Content-Type: text/html
                          Content-Length: 185
                          Connection: keep-alive
                          Location: https://thetrueline-life.world/?a=1nrK&c=d&s=93
                          Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                          Data Ascii: <html><head><title>301 Moved Permanently</title></head><body bgcolor="white"><center><h1>301 Moved Permanently</h1></center><hr><center>nginx/1.12.2</center></body></html>


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          2192.168.2.74971267.199.248.11443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          3192.168.2.74971418.65.39.84443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          4192.168.2.749721213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          5192.168.2.749722213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          6192.168.2.749723213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          7192.168.2.749728213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          8192.168.2.749730213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          9192.168.2.749749213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          0192.168.2.749713172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:15 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                          Host: accounts.google.com
                          Connection: keep-alive
                          Content-Length: 1
                          Origin: https://www.google.com
                          Content-Type: application/x-www-form-urlencoded
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: no-cors
                          Sec-Fetch-Dest: empty
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2022-11-29 23:23:15 UTC0OUTData Raw: 20
                          Data Ascii:
                          2022-11-29 23:23:15 UTC3INHTTP/1.1 200 OK
                          Content-Type: application/json; charset=utf-8
                          Access-Control-Allow-Origin: https://www.google.com
                          Access-Control-Allow-Credentials: true
                          X-Content-Type-Options: nosniff
                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                          Pragma: no-cache
                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                          Date: Tue, 29 Nov 2022 23:23:15 GMT
                          Strict-Transport-Security: max-age=31536000; includeSubDomains
                          Content-Security-Policy: script-src 'report-sample' 'nonce-B7kxEX14Jcce8Tsl5QR0iw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                          Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                          Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                          Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                          Cross-Origin-Opener-Policy: same-origin
                          Server: ESF
                          X-XSS-Protection: 0
                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                          Accept-Ranges: none
                          Vary: Accept-Encoding
                          Connection: close
                          Transfer-Encoding: chunked
                          2022-11-29 23:23:15 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                          Data Ascii: 11["gaia.l.a.r",[]]
                          2022-11-29 23:23:15 UTC5INData Raw: 30 0d 0a 0d 0a
                          Data Ascii: 0


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          1192.168.2.749711142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:15 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                          Host: clients2.google.com
                          Connection: keep-alive
                          X-Goog-Update-Interactivity: fg
                          X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                          X-Goog-Update-Updater: chromecrx-104.0.5112.81
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: no-cors
                          Sec-Fetch-Dest: empty
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2022-11-29 23:23:15 UTC1INHTTP/1.1 200 OK
                          Content-Security-Policy: script-src 'report-sample' 'nonce-KWsvhBSEHXb3GEsidUDMfA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                          Pragma: no-cache
                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                          Date: Tue, 29 Nov 2022 23:23:15 GMT
                          Content-Type: text/xml; charset=UTF-8
                          X-Daynum: 5811
                          X-Daystart: 55395
                          X-Content-Type-Options: nosniff
                          X-Frame-Options: SAMEORIGIN
                          X-XSS-Protection: 1; mode=block
                          Server: GSE
                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                          Accept-Ranges: none
                          Vary: Accept-Encoding
                          Connection: close
                          Transfer-Encoding: chunked
                          2022-11-29 23:23:15 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 31 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 35 33 39 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                          Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5811" elapsed_seconds="55395"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                          2022-11-29 23:23:15 UTC3INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                          Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                          2022-11-29 23:23:15 UTC3INData Raw: 30 0d 0a 0d 0a
                          Data Ascii: 0


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          10192.168.2.749748213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:59 UTC11OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          11192.168.2.749750213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:59 UTC11OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          2192.168.2.74971267.199.248.11443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:15 UTC1OUTGET /3TRQuxO HTTP/1.1
                          Host: bit.ly
                          Connection: keep-alive
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2022-11-29 23:23:15 UTC5INHTTP/1.1 301 Moved Permanently
                          Server: nginx
                          Date: Tue, 29 Nov 2022 23:23:15 GMT
                          Content-Type: text/html; charset=utf-8
                          Content-Length: 121
                          Cache-Control: private, max-age=90
                          Location: https://dqb4v.app.link/Sa09wy4x7ub
                          Set-Cookie: _bit=matnnf-baca65775efe36555a-00j; Domain=bit.ly; Expires=Sun, 28 May 2023 23:23:15 GMT
                          Via: 1.1 google
                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                          Connection: close
                          2022-11-29 23:23:15 UTC5INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 42 69 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 64 71 62 34 76 2e 61 70 70 2e 6c 69 6e 6b 2f 53 61 30 39 77 79 34 78 37 75 62 22 3e 6d 6f 76 65 64 20 68 65 72 65 3c 2f 61 3e 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                          Data Ascii: <html><head><title>Bitly</title></head><body><a href="https://dqb4v.app.link/Sa09wy4x7ub">moved here</a></body></html>


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          3192.168.2.74971418.65.39.84443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:15 UTC5OUTGET /Sa09wy4x7ub HTTP/1.1
                          Host: dqb4v.app.link
                          Connection: keep-alive
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2022-11-29 23:23:15 UTC6INHTTP/1.1 307 Temporary Redirect
                          Transfer-Encoding: chunked
                          Connection: close
                          Server: openresty
                          Date: Tue, 29 Nov 2022 23:23:15 GMT
                          Set-Cookie: _s=v%2BXq8IH08ai5WmyT%2F1nyvlXZxUcu%2FO9rVikb%2Bl5jC3ot%2FuaUZ6UGOLt5ufuj2d5m; Max-Age=31536000; Domain=.app.link; Path=/; Expires=Wed, 29 Nov 2023 23:23:15 GMT; Secure; SameSite=None
                          Last-Modified: Tue, 29 Nov 2022 23:23:15 GMT
                          Location: http://3kjarwa.associatesuitcase.co.in/usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA
                          Strict-Transport-Security: max-age=31536000; includeSubDomains
                          X-Cache: Miss from cloudfront
                          Via: 1.1 f5d6b2021b5a22554c0e7f5b20207324.cloudfront.net (CloudFront)
                          X-Amz-Cf-Pop: AMS1-P1
                          X-Amz-Cf-Id: aS4_172KwT6QxRN5MYOjLExUW42d5Lb1GpCWoZI_8Yv-vLiQC5vnRA==
                          2022-11-29 23:23:15 UTC7INData Raw: 30 0d 0a 0d 0a
                          Data Ascii: 0


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          4192.168.2.749721213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:16 UTC7OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          5192.168.2.749722213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:18 UTC7OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          6192.168.2.749723213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:27 UTC8OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          7192.168.2.749728213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:28 UTC9OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          8192.168.2.749730213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:28 UTC9OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          9192.168.2.749749213.227.155.34443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2022-11-29 23:23:59 UTC10OUTGET /?a=1nrK&c=d&s=93 HTTP/1.1
                          Host: thetrueline-life.world
                          Connection: keep-alive
                          Cache-Control: max-age=0
                          sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                          sec-ch-ua-mobile: ?0
                          sec-ch-ua-platform: "Windows"
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: navigate
                          Sec-Fetch-User: ?1
                          Sec-Fetch-Dest: document
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:00:23:08
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:1
                          Start time:00:23:09
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:2
                          Start time:00:23:10
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          No disassembly