Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://pool.supportxmr.com

Overview

General Information

Sample URL:http://pool.supportxmr.com
Analysis ID:1302000
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5060 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://pool.supportxmr.com/ MD5: C817D9E0D995276EC89E4C89AFC19694)
    • chrome.exe (PID: 2564 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1908,i,6030857926575452296,11810913791638510973,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: C817D9E0D995276EC89E4C89AFC19694)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://pool.supportxmr.comAvira URL Cloud: detection malicious, Label: malware
Source: http://pool.supportxmr.comVirustotal: Detection: 11%Perma Link
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=108.0.5359.125&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-108.0.5359.125Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=YES+srp.gws-20210525-0-RC1.de+FX+704
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: mal56.win@27/0@5/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://pool.supportxmr.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1908,i,6030857926575452296,11810913791638510973,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1908,i,6030857926575452296,11810913791638510973,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://pool.supportxmr.com11%VirustotalBrowse
http://pool.supportxmr.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
pool-fr.supportxmr.com
141.94.96.71
truefalse
    high
    accounts.google.com
    142.250.185.237
    truefalse
      high
      www.google.com
      172.217.18.4
      truefalse
        high
        clients.l.google.com
        142.250.181.238
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            pool.supportxmr.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=108.0.5359.125&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.181.238
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  172.217.18.4
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  141.94.96.71
                  pool-fr.supportxmr.comGermany
                  680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
                  142.250.185.132
                  unknownUnited States
                  15169GOOGLEUSfalse
                  142.250.185.237
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  Joe Sandbox Version:38.0.0 Beryl
                  Analysis ID:1302000
                  Start date and time:2023-09-02 02:27:51 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 3m 37s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                  Sample URL:http://pool.supportxmr.com
                  Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                  Number of analysed new started processes analysed:15
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal56.win@27/0@5/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, RuntimeBroker.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, usocoreworker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 23.32.185.164, 142.250.184.195, 34.104.35.123, 142.250.184.227
                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, e16604.g.akamaiedge.net, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
                  • Not all processes where analyzed, report is missing behavior information
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 2, 2023 02:28:22.212066889 CEST4971480192.168.2.2141.94.96.71
                  Sep 2, 2023 02:28:22.212925911 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.213027000 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.213129044 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.213500023 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.213572025 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.213673115 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.215909004 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.215955973 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.216233015 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.216284990 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.232389927 CEST8049714141.94.96.71192.168.2.2
                  Sep 2, 2023 02:28:22.232517958 CEST4971480192.168.2.2141.94.96.71
                  Sep 2, 2023 02:28:22.352874994 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.353324890 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.353389978 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.355514050 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.355634928 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.356019020 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.357614994 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.357662916 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.358186960 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.358305931 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.359019041 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.359097958 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.596962929 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.597258091 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.597820997 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.597875118 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.598587990 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.598740101 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.598767996 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.599050045 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.632972956 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.633122921 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.633177996 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.633307934 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.633413076 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.638278961 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.642520905 CEST49715443192.168.2.2142.250.181.238
                  Sep 2, 2023 02:28:22.642569065 CEST44349715142.250.181.238192.168.2.2
                  Sep 2, 2023 02:28:22.656923056 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.657110929 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:22.657299995 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.661653996 CEST49716443192.168.2.2142.250.185.237
                  Sep 2, 2023 02:28:22.661696911 CEST44349716142.250.185.237192.168.2.2
                  Sep 2, 2023 02:28:25.929456949 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:25.929608107 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:25.929747105 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:25.930147886 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:25.930200100 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.013130903 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.013735056 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:26.013818979 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.015186071 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.015382051 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:26.036983013 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:26.037156105 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.077622890 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:26.077672958 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:26.117592096 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:36.030390978 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:36.030535936 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:36.030678988 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:37.123097897 CEST49721443192.168.2.2172.217.18.4
                  Sep 2, 2023 02:28:37.123140097 CEST44349721172.217.18.4192.168.2.2
                  Sep 2, 2023 02:28:52.255321980 CEST8049714141.94.96.71192.168.2.2
                  Sep 2, 2023 02:28:52.255626917 CEST4971480192.168.2.2141.94.96.71
                  Sep 2, 2023 02:28:53.118653059 CEST4971480192.168.2.2141.94.96.71
                  Sep 2, 2023 02:28:53.139127016 CEST8049714141.94.96.71192.168.2.2
                  Sep 2, 2023 02:29:25.985449076 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:25.985533953 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:25.985682011 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:25.986135960 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:25.986180067 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:26.044544935 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:26.045202971 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:26.045248985 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:26.046241999 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:26.047219992 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:26.047494888 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:26.087857008 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:29:36.043781996 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:36.043972969 CEST44349731142.250.185.132192.168.2.2
                  Sep 2, 2023 02:29:36.044204950 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:30:21.048387051 CEST49731443192.168.2.2142.250.185.132
                  Sep 2, 2023 02:30:21.048429966 CEST44349731142.250.185.132192.168.2.2
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 2, 2023 02:28:22.137559891 CEST5682053192.168.2.21.1.1.1
                  Sep 2, 2023 02:28:22.137945890 CEST5990553192.168.2.21.1.1.1
                  Sep 2, 2023 02:28:22.138533115 CEST5558853192.168.2.21.1.1.1
                  Sep 2, 2023 02:28:22.155316114 CEST53568201.1.1.1192.168.2.2
                  Sep 2, 2023 02:28:22.155461073 CEST53599051.1.1.1192.168.2.2
                  Sep 2, 2023 02:28:22.155654907 CEST53555881.1.1.1192.168.2.2
                  Sep 2, 2023 02:28:25.900362015 CEST5251953192.168.2.21.1.1.1
                  Sep 2, 2023 02:28:25.927033901 CEST53525191.1.1.1192.168.2.2
                  Sep 2, 2023 02:29:25.966037035 CEST5422453192.168.2.21.1.1.1
                  Sep 2, 2023 02:29:25.983109951 CEST53542241.1.1.1192.168.2.2
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Sep 2, 2023 02:28:22.137559891 CEST192.168.2.21.1.1.10xf3ebStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.137945890 CEST192.168.2.21.1.1.10x56b4Standard query (0)pool.supportxmr.comA (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.138533115 CEST192.168.2.21.1.1.10xa81dStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:25.900362015 CEST192.168.2.21.1.1.10xd73Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Sep 2, 2023 02:29:25.966037035 CEST192.168.2.21.1.1.10x71acStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Sep 2, 2023 02:28:22.155316114 CEST1.1.1.1192.168.2.20xf3ebNo error (0)accounts.google.com142.250.185.237A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155461073 CEST1.1.1.1192.168.2.20x56b4No error (0)pool.supportxmr.compool-fr.supportxmr.comCNAME (Canonical name)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155461073 CEST1.1.1.1192.168.2.20x56b4No error (0)pool-fr.supportxmr.com141.94.96.71A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155461073 CEST1.1.1.1192.168.2.20x56b4No error (0)pool-fr.supportxmr.com141.94.96.195A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155461073 CEST1.1.1.1192.168.2.20x56b4No error (0)pool-fr.supportxmr.com141.94.96.144A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155654907 CEST1.1.1.1192.168.2.20xa81dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Sep 2, 2023 02:28:22.155654907 CEST1.1.1.1192.168.2.20xa81dNo error (0)clients.l.google.com142.250.181.238A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:28:25.927033901 CEST1.1.1.1192.168.2.20xd73No error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
                  Sep 2, 2023 02:29:25.983109951 CEST1.1.1.1192.168.2.20x71acNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.249716142.250.185.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-09-02 00:28:22 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: CONSENT=YES+srp.gws-20210525-0-RC1.de+FX+704
                  2023-09-02 00:28:22 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-09-02 00:28:22 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Sat, 02 Sep 2023 00:28:22 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Cross-Origin-Opener-Policy: same-origin
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Content-Security-Policy: script-src 'report-sample' 'nonce-MP3q4qsTdc1wuSQThB5KWQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-09-02 00:28:22 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-09-02 00:28:22 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.249715142.250.181.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-09-02 00:28:22 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=108.0.5359.125&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-108.0.5359.125
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-09-02 00:28:22 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-Aw7_uCrtoAyJHNIcHdqyZg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Sat, 02 Sep 2023 00:28:22 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 6087
                  X-Daystart: 62902
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-09-02 00:28:22 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 38 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 36 32 39 30 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6087" elapsed_seconds="62902"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-09-02 00:28:22 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-09-02 00:28:22 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:02:28:17
                  Start date:02/09/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://pool.supportxmr.com/
                  Imagebase:0x7ff651ef0000
                  File size:3'133'720 bytes
                  MD5 hash:C817D9E0D995276EC89E4C89AFC19694
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:1
                  Start time:02:28:19
                  Start date:02/09/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1908,i,6030857926575452296,11810913791638510973,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff651ef0000
                  File size:3'133'720 bytes
                  MD5 hash:C817D9E0D995276EC89E4C89AFC19694
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  No disassembly