Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://wtrxus.com

Overview

General Information

Sample URL:http://wtrxus.com
Analysis ID:890578
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Antivirus detection for URL or domain

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 4608 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://wtrxus.com/ MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 3524 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1760,i,9039821029062897786,500805447024722094,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://wtrxus.comAvira URL Cloud: detection malicious, Label: malware
Source: https://wtrxus.com/Virustotal: Detection: 6%Perma Link
Source: http://wtrxus.com/Virustotal: Detection: 5%Perma Link
Source: http://wtrxus.comVirustotal: Detection: 5%Perma Link
Source: https://wtrxus.com/favicon.icoAvira URL Cloud: Label: malware
Source: http://wtrxus.com/Avira URL Cloud: Label: malware
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownDNS traffic detected: queries for: wtrxus.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: wtrxus.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: wtrxus.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://wtrxus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: wtrxus.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://wtrxus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: wtrxus.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://wtrxus.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: wtrxus.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: wtrxus.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
Source: classification engineClassification label: mal72.win@26/3@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://wtrxus.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1760,i,9039821029062897786,500805447024722094,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1760,i,9039821029062897786,500805447024722094,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://wtrxus.com6%VirustotalBrowse
http://wtrxus.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://wtrxus.com/favicon.ico100%Avira URL Cloudmalware
https://wtrxus.com/7%VirustotalBrowse
http://wtrxus.com/6%VirustotalBrowse
http://wtrxus.com/100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.181.237
truefalse
    high
    www.google.com
    142.250.186.164
    truefalse
      high
      clients.l.google.com
      142.250.184.238
      truefalse
        high
        wtrxus.com
        147.182.140.228
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            http://wtrxus.com/true
            • 6%, Virustotal, Browse
            • Avira URL Cloud: malware
            unknown
            https://wtrxus.com/falseunknown
            https://wtrxus.com/favicon.icofalse
            • Avira URL Cloud: malware
            unknown
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                https://wtrxus.com/falseunknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.181.237
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                142.250.184.196
                unknownUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.184.238
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                147.182.140.228
                wtrxus.comUnited States
                27555BV-PUBLIC-ASNUSfalse
                IP
                192.168.2.1
                Joe Sandbox Version:37.1.0 Beryl
                Analysis ID:890578
                Start date and time:2023-06-19 18:29:01 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 3m 39s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Sample URL:http://wtrxus.com
                Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                Number of analysed new started processes analysed:4
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal72.win@26/3@8/6
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.185.67, 34.104.35.123, 142.250.186.67
                • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, login.live.com, update.googleapis.com, clientservices.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):5
                Entropy (8bit):1.9219280948873623
                Encrypted:false
                SSDEEP:3:iKn:p
                MD5:5D41402ABC4B2A76B9719D911017C592
                SHA1:AAF4C61DDCC5E8A2DABEDE0F3B482CD9AEA9434D
                SHA-256:2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824
                SHA-512:9B71D224BD62F3785D96D46AD3EA3D73319BFBC2890CAADAE2DFF72519673CA72323C3D99BA5C11D7C7ACC6E14B8C5DA0C4663475C2E5C3ADEF46F73BCDEC043
                Malicious:false
                Reputation:low
                URL:https://wtrxus.com/favicon.ico
                Preview:hello
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):5
                Entropy (8bit):1.9219280948873623
                Encrypted:false
                SSDEEP:3:iKn:p
                MD5:5D41402ABC4B2A76B9719D911017C592
                SHA1:AAF4C61DDCC5E8A2DABEDE0F3B482CD9AEA9434D
                SHA-256:2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824
                SHA-512:9B71D224BD62F3785D96D46AD3EA3D73319BFBC2890CAADAE2DFF72519673CA72323C3D99BA5C11D7C7ACC6E14B8C5DA0C4663475C2E5C3ADEF46F73BCDEC043
                Malicious:false
                Reputation:low
                URL:https://wtrxus.com/
                Preview:hello
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:dropped
                Size (bytes):5
                Entropy (8bit):1.9219280948873623
                Encrypted:false
                SSDEEP:3:iKn:p
                MD5:5D41402ABC4B2A76B9719D911017C592
                SHA1:AAF4C61DDCC5E8A2DABEDE0F3B482CD9AEA9434D
                SHA-256:2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824
                SHA-512:9B71D224BD62F3785D96D46AD3EA3D73319BFBC2890CAADAE2DFF72519673CA72323C3D99BA5C11D7C7ACC6E14B8C5DA0C4663475C2E5C3ADEF46F73BCDEC043
                Malicious:false
                Reputation:low
                Preview:hello
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Jun 19, 2023 18:29:30.093600988 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.093693018 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.093792915 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.094248056 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.094569921 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.094646931 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.094750881 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.096743107 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.096812010 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.097078085 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.097115040 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.098025084 CEST4975580192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.185877085 CEST4975680192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.195939064 CEST8049753147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.196072102 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.196994066 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.199678898 CEST8049755147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.199806929 CEST4975580192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.237946033 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.238068104 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.238281012 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.238359928 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.238444090 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.238495111 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.239012957 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.239115000 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.240051031 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.240075111 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.240179062 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.240220070 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.283499956 CEST8049756147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.283617020 CEST4975680192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.298657894 CEST8049753147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.298713923 CEST8049753147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.338606119 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.370309114 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.370366096 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.370455027 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.370755911 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.370790958 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.472330093 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.472575903 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.472601891 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.472693920 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.472801924 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.473191977 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.473220110 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.473264933 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.507261038 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.507369995 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.507421017 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.507700920 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.507805109 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.508111954 CEST49752443192.168.2.3142.250.184.238
                Jun 19, 2023 18:29:30.508143902 CEST44349752142.250.184.238192.168.2.3
                Jun 19, 2023 18:29:30.514853001 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.514900923 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.528326035 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.528410912 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.528455019 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.528645039 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.528734922 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.529496908 CEST49754443192.168.2.3142.250.181.237
                Jun 19, 2023 18:29:30.529531002 CEST44349754142.250.181.237192.168.2.3
                Jun 19, 2023 18:29:30.590781927 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.591696978 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.591722012 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.593440056 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.593542099 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.600290060 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.600518942 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.601214886 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.601237059 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.640723944 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.780287981 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.780437946 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.780519962 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.781754017 CEST49757443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.781773090 CEST44349757147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.910434961 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.910523891 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:30.910655975 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.914254904 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:30.914300919 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.077433109 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.077528954 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.077641010 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.081995010 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.082035065 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.125430107 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.126648903 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.126714945 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.127993107 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.128487110 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.128705978 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.128741026 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.168667078 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.168703079 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.303800106 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.304183960 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.304217100 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.305577040 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.306163073 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.306298971 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.306436062 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.318363905 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.318614006 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.318756104 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.346859932 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.408487082 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.408617973 CEST44349760147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.408718109 CEST49760443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.415028095 CEST49759443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.415076971 CEST44349759147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.449457884 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.449533939 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.449687004 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.450061083 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.450098991 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.655637980 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.656145096 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.656179905 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.658452034 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.658565044 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.659168005 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.659333944 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.659380913 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.698678970 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.698715925 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.738724947 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.850104094 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.850287914 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.850424051 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.853415966 CEST49761443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.853465080 CEST44349761147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.860836029 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.860929966 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:31.861073971 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.861509085 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:31.861550093 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.074477911 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.075052023 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.075103998 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.076188087 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.076951981 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.077086926 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.077111959 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.117793083 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.117861032 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.268907070 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.269128084 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:32.269253016 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.270544052 CEST49763443192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:32.270586014 CEST44349763147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:34.247366905 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.247437000 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.247601986 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.248306990 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.248334885 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.313791990 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.314270020 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.314310074 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.315534115 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.315632105 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.318572998 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.318681002 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.357956886 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:34.357990980 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:34.398955107 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:36.774604082 CEST8049755147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:36.774781942 CEST4975580192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:36.984540939 CEST8049753147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:36.984751940 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:37.044285059 CEST4975580192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:37.045219898 CEST4975380192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:37.052247047 CEST8049756147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:37.052498102 CEST4975680192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:37.150369883 CEST8049755147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:37.150422096 CEST8049753147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:39.043890953 CEST4975680192.168.2.3147.182.140.228
                Jun 19, 2023 18:29:39.141596079 CEST8049756147.182.140.228192.168.2.3
                Jun 19, 2023 18:29:44.336973906 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:44.337141037 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:29:44.337371111 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:45.045413017 CEST49765443192.168.2.3142.250.184.196
                Jun 19, 2023 18:29:45.045469046 CEST44349765142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.312423944 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:34.312499046 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.312608957 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:34.313133955 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:34.313178062 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.377250910 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.377677917 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:34.377727985 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.378277063 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.378901958 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:34.379021883 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:34.419178009 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:44.370754957 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:44.370923042 CEST44349768142.250.184.196192.168.2.3
                Jun 19, 2023 18:30:44.371128082 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:45.052792072 CEST49768443192.168.2.3142.250.184.196
                Jun 19, 2023 18:30:45.052851915 CEST44349768142.250.184.196192.168.2.3
                TimestampSource PortDest PortSource IPDest IP
                Jun 19, 2023 18:29:29.939065933 CEST5537653192.168.2.31.1.1.1
                Jun 19, 2023 18:29:29.939661980 CEST6054553192.168.2.31.1.1.1
                Jun 19, 2023 18:29:29.941535950 CEST6253453192.168.2.31.1.1.1
                Jun 19, 2023 18:29:29.956748009 CEST53553761.1.1.1192.168.2.3
                Jun 19, 2023 18:29:29.956882000 CEST53605451.1.1.1192.168.2.3
                Jun 19, 2023 18:29:29.958547115 CEST53625341.1.1.1192.168.2.3
                Jun 19, 2023 18:29:30.308932066 CEST5490953192.168.2.31.1.1.1
                Jun 19, 2023 18:29:30.327116966 CEST53549091.1.1.1192.168.2.3
                Jun 19, 2023 18:29:34.205941916 CEST5405653192.168.2.31.1.1.1
                Jun 19, 2023 18:29:34.223092079 CEST53540561.1.1.1192.168.2.3
                Jun 19, 2023 18:29:34.228827953 CEST5483053192.168.2.31.1.1.1
                Jun 19, 2023 18:29:34.245894909 CEST53548301.1.1.1192.168.2.3
                Jun 19, 2023 18:30:34.262151957 CEST5023753192.168.2.31.1.1.1
                Jun 19, 2023 18:30:34.280185938 CEST53502371.1.1.1192.168.2.3
                Jun 19, 2023 18:30:34.292855978 CEST5823853192.168.2.31.1.1.1
                Jun 19, 2023 18:30:34.309948921 CEST53582381.1.1.1192.168.2.3
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Jun 19, 2023 18:29:29.939065933 CEST192.168.2.31.1.1.10xb288Standard query (0)wtrxus.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:29.939661980 CEST192.168.2.31.1.1.10x4ba4Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:29.941535950 CEST192.168.2.31.1.1.10x6d91Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:30.308932066 CEST192.168.2.31.1.1.10x4f25Standard query (0)wtrxus.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:34.205941916 CEST192.168.2.31.1.1.10xc64fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:34.228827953 CEST192.168.2.31.1.1.10xf76bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:30:34.262151957 CEST192.168.2.31.1.1.10x9e7Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Jun 19, 2023 18:30:34.292855978 CEST192.168.2.31.1.1.10x1917Standard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Jun 19, 2023 18:29:29.956748009 CEST1.1.1.1192.168.2.30xb288No error (0)wtrxus.com147.182.140.228A (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:29.956882000 CEST1.1.1.1192.168.2.30x4ba4No error (0)accounts.google.com142.250.181.237A (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:29.958547115 CEST1.1.1.1192.168.2.30x6d91No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Jun 19, 2023 18:29:29.958547115 CEST1.1.1.1192.168.2.30x6d91No error (0)clients.l.google.com142.250.184.238A (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:30.327116966 CEST1.1.1.1192.168.2.30x4f25No error (0)wtrxus.com147.182.140.228A (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:34.223092079 CEST1.1.1.1192.168.2.30xc64fNo error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                Jun 19, 2023 18:29:34.245894909 CEST1.1.1.1192.168.2.30xf76bNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
                Jun 19, 2023 18:30:34.280185938 CEST1.1.1.1192.168.2.30x9e7No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
                Jun 19, 2023 18:30:34.309948921 CEST1.1.1.1192.168.2.30x1917No error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • wtrxus.com
                • https:
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349752142.250.184.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349754142.250.181.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.349757147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.349759147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                4192.168.2.349760147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                5192.168.2.349761147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                6192.168.2.349763147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                7192.168.2.349753147.182.140.22880C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Jun 19, 2023 18:29:30.196994066 CEST143OUTGET / HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Jun 19, 2023 18:29:30.298713923 CEST159INHTTP/1.1 301 Moved Permanently
                Server: nginx/1.22.0 (Ubuntu)
                Date: Mon, 19 Jun 2023 16:29:30 GMT
                Content-Type: text/html
                Content-Length: 178
                Connection: keep-alive
                Location: https://wtrxus.com/
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx/1.22.0 (Ubuntu)</center></body></html>


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349752142.250.184.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:30 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.102
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-06-19 16:29:30 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-rmVPz5cU0-guY9ffA1FhCQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 19 Jun 2023 16:29:30 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6013
                X-Daystart: 34170
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-06-19 16:29:30 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 31 33 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 34 31 37 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6013" elapsed_seconds="34170"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2023-06-19 16:29:30 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2023-06-19 16:29:30 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349754142.250.181.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:30 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
                2023-06-19 16:29:30 UTC1OUTData Raw: 20
                Data Ascii:
                2023-06-19 16:29:30 UTC2INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 19 Jun 2023 16:29:30 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Cross-Origin-Opener-Policy: same-origin
                Content-Security-Policy: script-src 'report-sample' 'nonce-TWB8MA3C14XZPUAVsB1w6w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-06-19 16:29:30 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2023-06-19 16:29:30 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.349757147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:30 UTC4OUTGET / HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-06-19 16:29:30 UTC5INHTTP/1.1 200 OK
                Server: nginx/1.22.0 (Ubuntu)
                Date: Mon, 19 Jun 2023 16:29:30 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                2023-06-19 16:29:30 UTC5INData Raw: 35 0d 0a 68 65 6c 6c 6f 0d 0a 30 0d 0a 0d 0a
                Data Ascii: 5hello0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.349759147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:31 UTC5OUTGET / HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                Cache-Control: max-age=0
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                Referer: https://wtrxus.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-06-19 16:29:31 UTC6INHTTP/1.1 200 OK
                Server: nginx/1.22.0 (Ubuntu)
                Date: Mon, 19 Jun 2023 16:29:31 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                2023-06-19 16:29:31 UTC6INData Raw: 35 0d 0a 68 65 6c 6c 6f 0d 0a 30 0d 0a 0d 0a
                Data Ascii: 5hello0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                4192.168.2.349760147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:31 UTC5OUTGET /favicon.ico HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://wtrxus.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9


                Session IDSource IPSource PortDestination IPDestination PortProcess
                5192.168.2.349761147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:31 UTC6OUTGET /favicon.ico HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://wtrxus.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-06-19 16:29:31 UTC7INHTTP/1.1 200 OK
                Server: nginx/1.22.0 (Ubuntu)
                Date: Mon, 19 Jun 2023 16:29:31 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                2023-06-19 16:29:31 UTC7INData Raw: 35 0d 0a 68 65 6c 6c 6f 0d 0a 30 0d 0a 0d 0a
                Data Ascii: 5hello0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                6192.168.2.349763147.182.140.228443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-06-19 16:29:32 UTC7OUTGET /favicon.ico HTTP/1.1
                Host: wtrxus.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: */*
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: cors
                Sec-Fetch-Dest: empty
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-06-19 16:29:32 UTC7INHTTP/1.1 200 OK
                Server: nginx/1.22.0 (Ubuntu)
                Date: Mon, 19 Jun 2023 16:29:32 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                2023-06-19 16:29:32 UTC7INData Raw: 35 0d 0a 68 65 6c 6c 6f 0d 0a 30 0d 0a 0d 0a
                Data Ascii: 5hello0


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:18:29:27
                Start date:19/06/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://wtrxus.com/
                Imagebase:0x7ff70f0c0000
                File size:2852640 bytes
                MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:18:29:29
                Start date:19/06/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1760,i,9039821029062897786,500805447024722094,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff70f0c0000
                File size:2852640 bytes
                MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly