Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://178.159.37.73

Overview

General Information

Sample URL:http://178.159.37.73
Analysis ID:1280483
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5596 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 3792 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1632,i,10970043307928765264,5024773461406919374,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6012 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://178.159.37.73 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://178.159.37.73/Virustotal: Detection: 11%Perma Link
Source: http://178.159.37.73Virustotal: Detection: 11%Perma Link
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: unknownTCP traffic detected without corresponding DNS query: 178.159.37.73
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 178.159.37.73Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 178.159.37.73Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://178.159.37.73/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 178.159.37.73Connection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://178.159.37.73/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 26 Jul 2023 17:48:09 GMTContent-Type: text/html; charset=UTF-8Content-Length: 13Connection: keep-aliveCache-Control: no-cache, no-store, must-revalidateExpires: 0Pragma: no-cacheVary: Accept-EncodingData Raw: 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 Data Ascii: 404 Not Found
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 26 Jul 2023 17:48:09 GMTContent-Type: text/htmlContent-Length: 548Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 26 Jul 2023 17:48:11 GMTContent-Type: text/html; charset=UTF-8Content-Length: 13Connection: keep-aliveCache-Control: no-cache, no-store, must-revalidateExpires: 0Pragma: no-cacheVary: Accept-EncodingData Raw: 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 Data Ascii: 404 Not Found
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: mal56.win@24/1@4/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1632,i,10970043307928765264,5024773461406919374,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://178.159.37.73
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1632,i,10970043307928765264,5024773461406919374,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://178.159.37.7311%VirustotalBrowse
http://178.159.37.730%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://178.159.37.73/favicon.ico0%Avira URL Cloudsafe
http://178.159.37.73/11%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.36.237
truefalse
    high
    www.google.com
    172.217.16.164
    truefalse
      high
      clients.l.google.com
      142.251.36.174
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            http://178.159.37.73/favicon.icotrue
            • Avira URL Cloud: safe
            unknown
            http://178.159.37.73/trueunknown
            http://178.159.37.73/trueunknown
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.251.36.237
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              178.159.37.73
              unknownRussian Federation
              206791SBY-TELECOM-ASUAfalse
              142.251.36.174
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              172.217.16.164
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              192.168.2.3
              Joe Sandbox Version:38.0.0 Beryl
              Analysis ID:1280483
              Start date and time:2023-07-26 19:47:10 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 7m 33s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://178.159.37.73
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:6
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal56.win@24/1@4/7
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.16.163, 34.104.35.123
              • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):548
              Entropy (8bit):4.688532577858027
              Encrypted:false
              SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
              MD5:370E16C3B7DBA286CFF055F93B9A94D8
              SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
              SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
              SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
              Malicious:false
              Reputation:low
              URL:http://178.159.37.73/favicon.ico
              Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Jul 26, 2023 19:48:08.728298903 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:08.728374004 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:08.728456974 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:08.728754044 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:08.728790998 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.728852034 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:08.729741096 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:08.729751110 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:08.729765892 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.729784966 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:08.817958117 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:08.818478107 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:08.818516970 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:08.823735952 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:08.823843002 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:08.843264103 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.844207048 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:08.844307899 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.845299006 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.845393896 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:08.846981049 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:08.847064972 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.079721928 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.079948902 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.080066919 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.080092907 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.080689907 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.080822945 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.080837965 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.081132889 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.129997969 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.130132914 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.130158901 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.130183935 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.130243063 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.130984068 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.131005049 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.132215977 CEST49720443192.168.2.5142.251.36.174
              Jul 26, 2023 19:48:09.132246017 CEST44349720142.251.36.174192.168.2.5
              Jul 26, 2023 19:48:09.133266926 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.133343935 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.133358955 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.133521080 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.133577108 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.139869928 CEST49719443192.168.2.5142.251.36.237
              Jul 26, 2023 19:48:09.139900923 CEST44349719142.251.36.237192.168.2.5
              Jul 26, 2023 19:48:09.612400055 CEST4972280192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.612454891 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.674534082 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:09.674601078 CEST8049722178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:09.674678087 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.674742937 CEST4972280192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.675050020 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.737215996 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:09.755511999 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:09.908952951 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:09.982395887 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:10.044811010 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:10.116115093 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:10.993954897 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:11.073647022 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:11.207737923 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:12.694245100 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.694314003 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.694449902 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.694927931 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.694963932 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.765696049 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.838258982 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.838295937 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.840488911 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.840559959 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.840632915 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.842936993 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.843178034 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:12.985167027 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:12.985213995 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:13.111000061 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:22.758161068 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:22.758323908 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:22.758440971 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:24.930924892 CEST49726443192.168.2.5172.217.16.164
              Jul 26, 2023 19:48:24.930969000 CEST44349726172.217.16.164192.168.2.5
              Jul 26, 2023 19:48:54.679924965 CEST4972280192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:54.742331982 CEST8049722178.159.37.73192.168.2.5
              Jul 26, 2023 19:48:56.086394072 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:48:56.148602962 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:49:09.736937046 CEST8049722178.159.37.73192.168.2.5
              Jul 26, 2023 19:49:09.737205029 CEST4972280192.168.2.5178.159.37.73
              Jul 26, 2023 19:49:10.928070068 CEST4972280192.168.2.5178.159.37.73
              Jul 26, 2023 19:49:10.990184069 CEST8049722178.159.37.73192.168.2.5
              Jul 26, 2023 19:49:12.820239067 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:12.820298910 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.820384979 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:12.820734978 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:12.820753098 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.894865990 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.895277023 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:12.895303965 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.895893097 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.896591902 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:12.896738052 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:12.949369907 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:16.075789928 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:49:16.076596975 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:49:16.932682037 CEST4972380192.168.2.5178.159.37.73
              Jul 26, 2023 19:49:16.994947910 CEST8049723178.159.37.73192.168.2.5
              Jul 26, 2023 19:49:22.873435974 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:22.873589039 CEST44349730172.217.16.164192.168.2.5
              Jul 26, 2023 19:49:22.873841047 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:22.936882019 CEST49730443192.168.2.5172.217.16.164
              Jul 26, 2023 19:49:22.936964035 CEST44349730172.217.16.164192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              Jul 26, 2023 19:48:08.618550062 CEST5148453192.168.2.58.8.8.8
              Jul 26, 2023 19:48:08.619554996 CEST6344653192.168.2.58.8.8.8
              Jul 26, 2023 19:48:08.647372961 CEST53634468.8.8.8192.168.2.5
              Jul 26, 2023 19:48:08.651391029 CEST53514848.8.8.8192.168.2.5
              Jul 26, 2023 19:48:12.614984989 CEST5922053192.168.2.58.8.8.8
              Jul 26, 2023 19:48:12.639883995 CEST53592208.8.8.8192.168.2.5
              Jul 26, 2023 19:49:12.789576054 CEST6372853192.168.2.58.8.8.8
              Jul 26, 2023 19:49:12.818367958 CEST53637288.8.8.8192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jul 26, 2023 19:48:08.618550062 CEST192.168.2.58.8.8.80x61c0Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Jul 26, 2023 19:48:08.619554996 CEST192.168.2.58.8.8.80xf1fdStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Jul 26, 2023 19:48:12.614984989 CEST192.168.2.58.8.8.80x9a7aStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Jul 26, 2023 19:49:12.789576054 CEST192.168.2.58.8.8.80xd995Standard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jul 26, 2023 19:48:08.647372961 CEST8.8.8.8192.168.2.50xf1fdNo error (0)accounts.google.com142.251.36.237A (IP address)IN (0x0001)false
              Jul 26, 2023 19:48:08.651391029 CEST8.8.8.8192.168.2.50x61c0No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Jul 26, 2023 19:48:08.651391029 CEST8.8.8.8192.168.2.50x61c0No error (0)clients.l.google.com142.251.36.174A (IP address)IN (0x0001)false
              Jul 26, 2023 19:48:12.639883995 CEST8.8.8.8192.168.2.50x9a7aNo error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
              Jul 26, 2023 19:49:12.818367958 CEST8.8.8.8192.168.2.50xd995No error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
              • clients2.google.com
              • accounts.google.com
              • 178.159.37.73
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.549720142.251.36.174443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.549719142.251.36.237443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              2192.168.2.549723178.159.37.7380C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              Jul 26, 2023 19:48:09.675050020 CEST454OUTGET / HTTP/1.1
              Host: 178.159.37.73
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jul 26, 2023 19:48:09.755511999 CEST454INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Wed, 26 Jul 2023 17:48:09 GMT
              Content-Type: text/html; charset=UTF-8
              Content-Length: 13
              Connection: keep-alive
              Cache-Control: no-cache, no-store, must-revalidate
              Expires: 0
              Pragma: no-cache
              Vary: Accept-Encoding
              Data Raw: 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64
              Data Ascii: 404 Not Found
              Jul 26, 2023 19:48:09.982395887 CEST455OUTGET /favicon.ico HTTP/1.1
              Host: 178.159.37.73
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://178.159.37.73/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jul 26, 2023 19:48:10.044811010 CEST455INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Wed, 26 Jul 2023 17:48:09 GMT
              Content-Type: text/html
              Content-Length: 548
              Connection: keep-alive
              Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
              Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
              Jul 26, 2023 19:48:10.993954897 CEST456OUTGET / HTTP/1.1
              Host: 178.159.37.73
              Connection: keep-alive
              Cache-Control: max-age=0
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Referer: http://178.159.37.73/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jul 26, 2023 19:48:11.073647022 CEST456INHTTP/1.1 404 Not Found
              Server: nginx
              Date: Wed, 26 Jul 2023 17:48:11 GMT
              Content-Type: text/html; charset=UTF-8
              Content-Length: 13
              Connection: keep-alive
              Cache-Control: no-cache, no-store, must-revalidate
              Expires: 0
              Pragma: no-cache
              Vary: Accept-Encoding
              Data Raw: 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64
              Data Ascii: 404 Not Found
              Jul 26, 2023 19:48:56.086394072 CEST466OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortProcess
              3192.168.2.549722178.159.37.7380C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              Jul 26, 2023 19:48:54.679924965 CEST465OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.549720142.251.36.174443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-07-26 17:48:09 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-07-26 17:48:09 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-1IekKBD7zoWpEOczsYnPBA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 26 Jul 2023 17:48:09 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 6050
              X-Daystart: 38889
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-07-26 17:48:09 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 35 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 38 38 38 39 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6050" elapsed_seconds="38889"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-07-26 17:48:09 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-07-26 17:48:09 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.549719142.251.36.237443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-07-26 17:48:09 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-07-26 17:48:09 UTC1OUTData Raw: 20
              Data Ascii:
              2023-07-26 17:48:09 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 26 Jul 2023 17:48:09 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Content-Security-Policy: script-src 'report-sample' 'nonce-Z9i1P3BYpWcfChNp_zoTcg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Cross-Origin-Opener-Policy: same-origin
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-07-26 17:48:09 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-07-26 17:48:09 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:19:48:05
              Start date:26/07/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff7d31b0000
              File size:2'851'656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:1
              Start time:19:48:06
              Start date:26/07/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1632,i,10970043307928765264,5024773461406919374,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff7d31b0000
              File size:2'851'656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:19:48:08
              Start date:26/07/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://178.159.37.73
              Imagebase:0x7ff7d31b0000
              File size:2'851'656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly