Edit tour

Windows Analysis Report
https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)

Overview

General Information

Sample URL:https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)
Analysis ID:1297086
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Stores files to the Windows start menu directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5700 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 2612 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1920 --field-trial-handle=1860,i,8341013195567926252,8915628765035333444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 5132 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff) MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_5700_1302001162Jump to behavior
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: chromecache_223.1.drString found in binary or memory: https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg
Source: chromecache_223.1.drString found in binary or memory: https://cfl.dropboxstatic.com/static/images/favicon.ico
Source: chromecache_223.1.drString found in binary or memory: https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/business?_tk=fof
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/help?_tk=fof
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/home?_tk=fof
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/login?_tk=fof
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/plus?_tk=fof
Source: chromecache_223.1.drString found in binary or memory: https://www.dropbox.com/register?_tk=fof
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g
Source: classification engineClassification label: clean0.win@23/8@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1920 --field-trial-handle=1860,i,8341013195567926252,8915628765035333444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1920 --field-trial-handle=1860,i,8341013195567926252,8915628765035333444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_5700_1302001162Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_5700_1302001162Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1297086 URL: https://cfl.dropboxstatic.c... Startdate: 25/08/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 9 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 192.168.2.5 unknown unknown 5->15 17 239.255.255.250 unknown Reserved 5->17 10 chrome.exe 5->10         started        process4 dnsIp5 19 clients.l.google.com 142.250.203.110, 443, 49716 GOOGLEUS United States 10->19 21 www.google.com 172.217.168.68, 443, 49721, 49737 GOOGLEUS United States 10->21 23 3 other IPs or domains 10->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)0%VirustotalBrowse
https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.168.77
truefalse
    high
    www.google.com
    172.217.168.68
    truefalse
      high
      clients.l.google.com
      142.250.203.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          cfl.dropboxstatic.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)false
              high
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  NameSourceMaliciousAntivirus DetectionReputation
                  https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svgchromecache_223.1.drfalse
                    high
                    https://www.dropbox.com/login?_tk=fofchromecache_223.1.drfalse
                      high
                      https://www.dropbox.com/plus?_tk=fofchromecache_223.1.drfalse
                        high
                        https://www.dropbox.com/business?_tk=fofchromecache_223.1.drfalse
                          high
                          https://cfl.dropboxstatic.com/static/images/favicon.icochromecache_223.1.drfalse
                            high
                            https://www.dropbox.com/home?_tk=fofchromecache_223.1.drfalse
                              high
                              https://cfl.dropboxstatic.com/static/metaserver/static/css/error.csschromecache_223.1.drfalse
                                high
                                https://www.dropbox.com/register?_tk=fofchromecache_223.1.drfalse
                                  high
                                  https://www.dropbox.com/help?_tk=fofchromecache_223.1.drfalse
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    172.217.168.68
                                    www.google.comUnited States
                                    15169GOOGLEUSfalse
                                    239.255.255.250
                                    unknownReserved
                                    unknownunknownfalse
                                    172.217.168.77
                                    accounts.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.203.110
                                    clients.l.google.comUnited States
                                    15169GOOGLEUSfalse
                                    IP
                                    192.168.2.1
                                    192.168.2.5
                                    Joe Sandbox Version:38.0.0 Beryl
                                    Analysis ID:1297086
                                    Start date and time:2023-08-25 03:43:22 +02:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:0h 5m 46s
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:browseurl.jbs
                                    Sample URL:https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)
                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                    Number of analysed new started processes analysed:25
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • HDC enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:CLEAN
                                    Classification:clean0.win@23/8@8/6
                                    EGA Information:Failed
                                    HDC Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, svchost.exe
                                    • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123, 104.16.100.29, 104.16.99.29
                                    • Excluded domains from analysis (whitelisted): www.bing.com, kv601.prod.do.dsp.mp.microsoft.com, ris.api.iris.microsoft.com, geover.prod.do.dsp.mp.microsoft.com, fs.microsoft.com, edgedl.me.gvt1.com, geo.prod.do.dsp.mp.microsoft.com, eudb.ris.api.iris.microsoft.com, update.googleapis.com, clientservices.googleapis.com, cfl.dropboxstatic.com.cdn.cloudflare.net, arc.msn.com
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtSetInformationFile calls found.
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2675
                                    Entropy (8bit):4.013098239519765
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA1o9ehwiZUklqehD22BA3:8JdswRR96
                                    MD5:A589A1DEED2E24BEA6758F630FCC8A80
                                    SHA1:E381608F0FD3BABA0194D3ACCC421C67C8560689
                                    SHA-256:DBDE93D0D294D3E09775A36CEF9DDF63FAB9AA16E58F1BF146916030DCC78C7F
                                    SHA-512:AF35D6BE21E36321959C8E652FF5A286B57ADD83C37AB4A7241F5FEA39E9D56A5AF485B9E2E825DFC00B8C9320F7672D97DA9703C62C74F274F7BE604D203934
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2677
                                    Entropy (8bit):4.030753932925722
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA1t9eh/iZUkAQkqeha22BA2:8JdswRRx9Q3
                                    MD5:CC059D611A06F130BB0FE846BD2A235D
                                    SHA1:0D5AC5357A794295EEF21647E4E11C01814ECB91
                                    SHA-256:D87141FDC827ABDB9CF728487412F1AB3FF728B40D4B4E18849C098307EBF4BE
                                    SHA-512:EFF757C3807794CA674BBC43C0F6949C6AC490EF06F3882E8C8AE2B004C570668108158DEF4B3A2FBE322F3AD60F62245BB1334234B1B038AAC0AA246F9DBEAE
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2691
                                    Entropy (8bit):4.042349506542579
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA14J9eh7sFiZUkmgqeh7sI22BABX:8JdswRRnn+
                                    MD5:8213D7E126F0FA9C726EFDF310F6AC29
                                    SHA1:F3D0BDF444A2EA401AA8234136FA13391D26FDF0
                                    SHA-256:D3F6FACCF6E94A7E59829B284C012BA53FA38C6E9B46B49539167770E4AC4157
                                    SHA-512:F504F101FE61EF7DBEFF92E3FDE8EF453CAE9C311389D7A85A1DD4C9641068B0F8B3D58CC41EA6F4100386BFCE156D7DBA00DA9A5A19535432D7C6C46B66BDBA
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2679
                                    Entropy (8bit):4.028557389260979
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA1u9ehDiZUkwqeh222BAR:8JdswRR08
                                    MD5:A5A89FEAC9553CE374E64B4D85531B7B
                                    SHA1:77DF92B8A9150D55D7F7631E178239AF5897014C
                                    SHA-256:66865DC7B0EF421ED88981E18BD4FF68FE2A7A992E60711E4C198D90FF2C8CD7
                                    SHA-512:384B2E1D83AE3D710747E5B718759F972126C199D1B7631285D22872EFD02EB30F582B0F83165DE72D2B42852220B921A8B7F935A8C4C0308A5A1DE6559B5766
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2679
                                    Entropy (8bit):4.0166039229488675
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA1c9ehBiZUk1W1qehs22BAC:8JdswRR094
                                    MD5:F09322DA773237F8D2ADCB42BEC04608
                                    SHA1:7696B83F572B77452F14FA8CD4A382A6ED81D8D7
                                    SHA-256:A9F00ABAEBA8E7BF50F16E4D6BCAB469360BAEC7D9D03CF4BF0BFEBA7B6C4BEC
                                    SHA-512:995360A79945DED5369FC75DCE5EC9C829FFD3298D62463E2EA0B24A3FBE9ED671E24B19D1056EE24A69D80C989A4FF984B5F47EC5002962825B71171092B278
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                                    Category:dropped
                                    Size (bytes):2681
                                    Entropy (8bit):4.0318047295331665
                                    Encrypted:false
                                    SSDEEP:48:8JdcdH1wRmHiWidAKZdA1duTn9ehOuTbbiZUk5OjqehOuTbO22BAyT+:8JdswRRZTqTbxWOvTb+PT
                                    MD5:C4CDC6458CCD96E70C10A466B95EE313
                                    SHA1:F36216E5DBA7BADB162B9A020A65A1B8770AF7C9
                                    SHA-256:D7BDF8DACB7C2F19B00F3E4A22328EACA4AD8F463F8CE531E5D68D8261934E76
                                    SHA-512:8CD860D36C39F64461143E9D2AC3FDFFA53092A83D59EC27B4B75DF4E05FD2453BC4BECD7DFE1FEE20FC2214695F06F8EEAFDE794224DE9F8392B387769B9AF9
                                    Malicious:false
                                    Reputation:low
                                    Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W......E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W................................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W............................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W.............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text, with very long lines (23660)
                                    Category:downloaded
                                    Size (bytes):25569
                                    Entropy (8bit):4.852141811725909
                                    Encrypted:false
                                    SSDEEP:192:r3jEWs6v9CxquuTV/gEzp6mIxUM2r/mb8aQ9aUdKVacuYIct9OTPc7CWDIy2a0LD:r3jjsTx8VqbDwTcuFc/E
                                    MD5:6D887DF3989B69BA3E9B72B4D627D1D1
                                    SHA1:75575EC9AA04709338C2049CC4885FC99E743F15
                                    SHA-256:7A608C782119FE6D168F54D9C77E3E501667250BABEE3FFA9233D34F1980A50C
                                    SHA-512:77C809A44A83A068FCA6B28C0292465F1ADBD8EB7C23B83AC2183988FD099D7D7F1760DBF519241FBDED930766818CB121A9E6E44C852814EE99F6B9197028E6
                                    Malicious:false
                                    Reputation:low
                                    URL:https://cfl.dropboxstatic.com/favicon.ico
                                    Preview:<!DOCTYPE html>.<html>.<head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">.<title>Dropbox - 4xx</title>.<link href="https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css" rel="stylesheet" type="text/css"/>.<link rel="shortcut icon" href="https://cfl.dropboxstatic.com/static/images/favicon.ico"/>.</head>.<body>.<div class="figure">.<img src="https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg" alt="Error: 4xx"/>.</div>.<div id="errorbox">.<div class="not-found"> <h1>Error (4xx)</h1> We can't find the page you're looking for. <div class="not-found--links"> Here are a few links that may be helpful: <ul> <li><a href="https://www.dropbox.com/home?_tk=fof">Home</a></li> <li><a href="https://www.dropbox.com/help?_tk=fof">Help center</a></li> <li><a href="https://www.dropbox.com/login?_tk=fof">Sign in</a></li> <li><a href="https://www.dropbox.com/register?_tk=fof">Get a free account</a></li> <li><a href="https://www.dropbox.com
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text, with CRLF line terminators
                                    Category:downloaded
                                    Size (bytes):548
                                    Entropy (8bit):4.688532577858027
                                    Encrypted:false
                                    SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                                    MD5:370E16C3B7DBA286CFF055F93B9A94D8
                                    SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                                    SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                                    SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                                    Malicious:false
                                    Reputation:low
                                    URL:https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)
                                    Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                                    No static file info

                                    Download Network PCAP: filteredfull

                                    • Total Packets: 47
                                    • 443 (HTTPS)
                                    • 53 (DNS)
                                    TimestampSource PortDest PortSource IPDest IP
                                    Aug 25, 2023 03:44:23.011137962 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.011183977 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.011284113 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.012600899 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.012634993 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.015638113 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.015721083 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.015841961 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.016199112 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.016233921 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.087186098 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.091300011 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.091356039 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.093908072 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.094053984 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.095833063 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.097568989 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.097731113 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.098469973 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.098517895 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.099482059 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.099594116 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.099962950 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.100008011 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.100917101 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.100994110 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.103349924 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.103598118 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.103610992 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.139539003 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.139658928 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.139697075 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.139842987 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.139910936 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.140935898 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.156817913 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.157067060 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:23.157157898 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.166649103 CEST49716443192.168.2.4142.250.203.110
                                    Aug 25, 2023 03:44:23.166699886 CEST44349716142.250.203.110192.168.2.4
                                    Aug 25, 2023 03:44:23.167309046 CEST49715443192.168.2.4172.217.168.77
                                    Aug 25, 2023 03:44:23.167360067 CEST44349715172.217.168.77192.168.2.4
                                    Aug 25, 2023 03:44:26.217227936 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.217304945 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.217407942 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.218606949 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.218638897 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.273147106 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.273628950 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.273669004 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.274976969 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.275127888 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.277344942 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.277556896 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.327357054 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:26.327418089 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:26.374255896 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:36.251157999 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:36.251244068 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:44:36.251347065 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:38.881766081 CEST49721443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:44:38.881810904 CEST44349721172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.555279970 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:26.555370092 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.555481911 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:26.556375980 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:26.556411982 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.609186888 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.609671116 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:26.609707117 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.610532045 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.611057997 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:26.611231089 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:26.664513111 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:38.230556011 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:38.230691910 CEST44349737172.217.168.68192.168.2.4
                                    Aug 25, 2023 03:45:38.230766058 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:39.558231115 CEST49737443192.168.2.4172.217.168.68
                                    Aug 25, 2023 03:45:39.558276892 CEST44349737172.217.168.68192.168.2.4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Aug 25, 2023 03:44:22.959392071 CEST5181653192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:22.960000992 CEST5139153192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:22.960764885 CEST4978553192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:22.961133003 CEST6387253192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:22.982763052 CEST53518168.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:22.989322901 CEST53497858.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:22.995208025 CEST53498178.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:23.002831936 CEST53638728.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:23.014895916 CEST53513918.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:23.286959887 CEST53648038.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:23.899451971 CEST6482953192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:23.900077105 CEST5438853192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:26.185066938 CEST5365353192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:26.186264992 CEST5208653192.168.2.48.8.8.8
                                    Aug 25, 2023 03:44:26.208714008 CEST53536538.8.8.8192.168.2.4
                                    Aug 25, 2023 03:44:26.214795113 CEST53520868.8.8.8192.168.2.4
                                    Aug 25, 2023 03:45:22.112478971 CEST53576768.8.8.8192.168.2.4
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Aug 25, 2023 03:44:22.959392071 CEST192.168.2.48.8.8.80xa2f9Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:22.960000992 CEST192.168.2.48.8.8.80xf433Standard query (0)clients2.google.com65IN (0x0001)false
                                    Aug 25, 2023 03:44:22.960764885 CEST192.168.2.48.8.8.80xc990Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:22.961133003 CEST192.168.2.48.8.8.80xe2bStandard query (0)accounts.google.com65IN (0x0001)false
                                    Aug 25, 2023 03:44:23.899451971 CEST192.168.2.48.8.8.80x632Standard query (0)cfl.dropboxstatic.comA (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:23.900077105 CEST192.168.2.48.8.8.80x50edStandard query (0)cfl.dropboxstatic.com65IN (0x0001)false
                                    Aug 25, 2023 03:44:26.185066938 CEST192.168.2.48.8.8.80x59e0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:26.186264992 CEST192.168.2.48.8.8.80x6fa8Standard query (0)www.google.com65IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Aug 25, 2023 03:44:22.982763052 CEST8.8.8.8192.168.2.40xa2f9No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                    Aug 25, 2023 03:44:22.982763052 CEST8.8.8.8192.168.2.40xa2f9No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:22.989322901 CEST8.8.8.8192.168.2.40xc990No error (0)accounts.google.com172.217.168.77A (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:23.014895916 CEST8.8.8.8192.168.2.40xf433No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                    Aug 25, 2023 03:44:23.935275078 CEST8.8.8.8192.168.2.40x50edNo error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                    Aug 25, 2023 03:44:23.936043978 CEST8.8.8.8192.168.2.40x632No error (0)cfl.dropboxstatic.comcfl.dropboxstatic.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                    Aug 25, 2023 03:44:26.208714008 CEST8.8.8.8192.168.2.40x59e0No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                                    Aug 25, 2023 03:44:26.214795113 CEST8.8.8.8192.168.2.40x6fa8No error (0)www.google.com65IN (0x0001)false
                                    • accounts.google.com
                                    • clients2.google.com
                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                    0192.168.2.449715172.217.168.77443C:\Program Files\Google\Chrome\Application\chrome.exe
                                    TimestampkBytes transferredDirectionData
                                    2023-08-25 01:44:23 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                    Host: accounts.google.com
                                    Connection: keep-alive
                                    Content-Length: 1
                                    Origin: https://www.google.com
                                    Content-Type: application/x-www-form-urlencoded
                                    Sec-Fetch-Site: none
                                    Sec-Fetch-Mode: no-cors
                                    Sec-Fetch-Dest: empty
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                                    Accept-Encoding: gzip, deflate, br
                                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                                    Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g
                                    2023-08-25 01:44:23 UTC0OUTData Raw: 20
                                    Data Ascii:
                                    2023-08-25 01:44:23 UTC2INHTTP/1.1 200 OK
                                    Content-Type: application/json; charset=utf-8
                                    Access-Control-Allow-Origin: https://www.google.com
                                    Access-Control-Allow-Credentials: true
                                    X-Content-Type-Options: nosniff
                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                    Pragma: no-cache
                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                    Date: Fri, 25 Aug 2023 01:44:23 GMT
                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                                    Content-Security-Policy: script-src 'report-sample' 'nonce-Cm59wsyU8cM88b_cJMP54w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                    Cross-Origin-Opener-Policy: same-origin
                                    Server: ESF
                                    X-XSS-Protection: 0
                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                    Accept-Ranges: none
                                    Vary: Accept-Encoding
                                    Connection: close
                                    Transfer-Encoding: chunked
                                    2023-08-25 01:44:23 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                    Data Ascii: 11["gaia.l.a.r",[]]
                                    2023-08-25 01:44:23 UTC4INData Raw: 30 0d 0a 0d 0a
                                    Data Ascii: 0


                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                    1192.168.2.449716142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                                    TimestampkBytes transferredDirectionData
                                    2023-08-25 01:44:23 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                    Host: clients2.google.com
                                    Connection: keep-alive
                                    X-Goog-Update-Interactivity: fg
                                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                    X-Goog-Update-Updater: chromecrx-115.0.5790.171
                                    Sec-Fetch-Site: none
                                    Sec-Fetch-Mode: no-cors
                                    Sec-Fetch-Dest: empty
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                                    Accept-Encoding: gzip, deflate, br
                                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                                    2023-08-25 01:44:23 UTC1INHTTP/1.1 200 OK
                                    Content-Security-Policy: script-src 'report-sample' 'nonce-KQnDGzOYhXy4Icv610BPcw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                    Pragma: no-cache
                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                    Date: Fri, 25 Aug 2023 01:44:23 GMT
                                    Content-Type: text/xml; charset=UTF-8
                                    X-Daynum: 6079
                                    X-Daystart: 67463
                                    X-Content-Type-Options: nosniff
                                    X-Frame-Options: SAMEORIGIN
                                    X-XSS-Protection: 1; mode=block
                                    Server: GSE
                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                    Accept-Ranges: none
                                    Vary: Accept-Encoding
                                    Connection: close
                                    Transfer-Encoding: chunked
                                    2023-08-25 01:44:23 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 37 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 36 37 34 36 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6079" elapsed_seconds="67463"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                    2023-08-25 01:44:23 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                    2023-08-25 01:44:23 UTC2INData Raw: 30 0d 0a 0d 0a
                                    Data Ascii: 0


                                    020406080s020406080100

                                    Click to jump to process

                                    020406080s0.0020406080100MB

                                    Click to jump to process

                                    Target ID:0
                                    Start time:03:44:19
                                    Start date:25/08/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                    Imagebase:0x7ff7c94b0000
                                    File size:3'219'224 bytes
                                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Target ID:1
                                    Start time:03:44:20
                                    Start date:25/08/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1920 --field-trial-handle=1860,i,8341013195567926252,8915628765035333444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                    Imagebase:0x7ff7c94b0000
                                    File size:3'219'224 bytes
                                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Target ID:2
                                    Start time:03:44:23
                                    Start date:25/08/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cfl.dropboxstatic.com/static/fonts/paper-atlasgrotesk/AtlasGrotesk-Medium-Web.woff)
                                    Imagebase:0x7ff7c94b0000
                                    File size:3'219'224 bytes
                                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:true
                                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                    No disassembly