Edit tour

Windows Analysis Report
https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1

Overview

General Information

Sample URL:https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1
Analysis ID:1309172
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5504 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 3420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2340,i,948603337675666231,5668153619294458144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 2120 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: classification engineClassification label: unknown0.win@18/6@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2340,i,948603337675666231,5668153619294458144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2340,i,948603337675666231,5668153619294458144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1309172 URL: https://forumflowequipment.... Startdate: 15/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 8 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 forumflowequipment.com 84.32.84.32, 443, 49710, 49711 NTT-LT-ASLT Lithuania 10->17 19 clients.l.google.com 142.251.32.78, 443, 49708 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=10%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
forumflowequipment.com
84.32.84.32
truefalse
    unknown
    accounts.google.com
    142.251.41.77
    truefalse
      high
      www.google.com
      172.217.1.4
      truefalse
        high
        clients.l.google.com
        142.251.32.78
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.251.41.77
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                142.251.32.78
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                84.32.84.32
                forumflowequipment.comLithuania
                33922NTT-LT-ASLTfalse
                172.217.1.4
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.1
                Joe Sandbox Version:38.0.0 Beryl
                Analysis ID:1309172
                Start date and time:2023-09-15 20:33:53 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 1m 50s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:3
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:UNKNOWN
                Classification:unknown0.win@18/6@8/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • URL browsing timeout or error
                • URL not reachable
                • Excluded IPs from analysis (whitelisted): 142.251.33.163, 34.104.35.123, 142.251.41.35, 204.79.197.200, 13.107.21.200
                • Excluded domains from analysis (whitelisted): www.bing.com, edgedl.me.gvt1.com, dual-a-0001.a-msedge.net, www-bing-com.dual-a-0001.a-msedge.net, clientservices.googleapis.com, www.gstatic.com, www-www.bing.com.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: https://forumflowequipment.com/&amp;c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&amp;typo=1
                No simulations
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2675
                Entropy (8bit):4.009907902181272
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA1o9ehwiZUklqehrBA3:8JdXlRBE
                MD5:4A2EBA3977A03BBCA42D5C6031AF3106
                SHA1:4821C838F82A339D17C4787BAA6DA34CD0638180
                SHA-256:17C7CA4C17BB349DB85CFA3B0696365F4EB604EC45823A769F676EB44B2D30FF
                SHA-512:F1B2676B5F786D76281F59C45DE787068F303ADDA4A6FA5918201F7A504F70BF031D08067235AF77311551C18477A595A73E891F64E1ADC90EDC5399B2BF6FFB
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):4.02779716783459
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA1t9eh/iZUkAQkqehUBA2:8JdXlRN9Q5
                MD5:527754FC6E80E36909A38A4A725A1274
                SHA1:91022CB6B47702617992A5FAB722890E21E32BB4
                SHA-256:E70C2D4C4047FB2AA301FE64C99ACC48A4F2A65259264B245732E29E3A3DC997
                SHA-512:01CCE8CBA69085773C26A302A80567C3D972DC445505AA76F628928453DE5C9C09EBEEDBA812A4E113CFF83DB705F5AFA12CA36FA09519D37E656DEBACAE4550
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2691
                Entropy (8bit):4.040168146696727
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA14J9eh7sFiZUkmgqeh7syBABX:8JdXlRjnA
                MD5:64954C6456D9DC40ED857768EC33570E
                SHA1:FAB993D8EBE8B4C385B7430533BF52E538981001
                SHA-256:BB89649C0B7AA79A0EB320F7332799DCA29BA14BD2BA9A6A76239E28AE764AB8
                SHA-512:BEF020C7BB13FF90E715A6DE8C24242217EC7D9E86FC5EB5C887DBE3DC8B4725D62038664A83B1916C218DC4878418A624792BE6B7E54DEB74DFCEEC85762100
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):4.0252364627841555
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA1u9ehDiZUkwqehIBAR:8JdXlRw6
                MD5:4E4DC1DE6698D34A2029F13F37C3766F
                SHA1:E47E93AAE73A18F1B3AF9D72185B9815D3A28698
                SHA-256:D91B76C014B5F006753DEFBD4E36F0313DC64AA05D05B16616F8B992949578F2
                SHA-512:FD9CEC7AD3541B35734CFE59F2461D6C1DD016A6D5FE01EF15377B75BA7093535504558DE4F13E657240055D3FE48BCEDBC96565FF4B490A548806582F63F01E
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):4.013772536632816
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA1c9ehBiZUk1W1qeh+BAC:8JdXlRQ9e
                MD5:DADCBF3EDC0443568CD82C4470CD4588
                SHA1:36C0A4B36E8EF00E25504D095BA7DACE2F8CBD0A
                SHA-256:522419EA4DDB0174F363CEFB96F111ECA7889A248E7742E9B2B5113FAC64B521
                SHA-512:5A46F1DC26AB64A089FC8C68257882EAC0DF378B401B3547AB92AEB84F0E788CC90E71CD44C2418A6C91DE47C263DC4AFE890A13ADDEE352FB393328585E7509
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):4.028866796101373
                Encrypted:false
                SSDEEP:48:8JdcdfIlRmHtidAKZdA1duTn9ehOuTbbiZUk5OjqehOuTbABAyT+:8JdXlRVTqTbxWOvTbAPT
                MD5:D6438E82D3D66D5F27737BB4082613A3
                SHA1:9461950E32EF0031F0594E5557525A71D048531C
                SHA-256:7EB125C620643357BE4DA33D8C31746146BF3A291E2655E5C2FB1C9FF9703920
                SHA-512:289CEEE869DACA4E002F19528B337BF57CCDCE7715A173D9EBD2C5680D3FFF70B5613EAE8F32646259D48D1C970E9E173E74006136568D89AF4399EB52562872
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L./WW.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;/WW...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;/WW...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;/WW............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............j.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 60
                • 443 (HTTPS)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Sep 15, 2023 20:34:47.708229065 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.708257914 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.708316088 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.708786011 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.708817959 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.708955050 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.709130049 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.709141016 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.710716963 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.710726023 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.969459057 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.969984055 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.970052004 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.971538067 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.971632957 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.973097086 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.975328922 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.975358963 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.975696087 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.975737095 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.975763083 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.975831985 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.976296902 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:47.976326942 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:47.976365089 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.976421118 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.977391005 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.977447033 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:47.977643967 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:47.977654934 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:48.016412973 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:48.032072067 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:48.218820095 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:48.219784021 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:48.219974995 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:48.224633932 CEST49708443192.168.2.4142.251.32.78
                Sep 15, 2023 20:34:48.224648952 CEST44349708142.251.32.78192.168.2.4
                Sep 15, 2023 20:34:48.230402946 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:48.230537891 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:48.230606079 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:48.231651068 CEST49709443192.168.2.4142.251.41.77
                Sep 15, 2023 20:34:48.231667042 CEST44349709142.251.41.77192.168.2.4
                Sep 15, 2023 20:34:48.833580017 CEST49710443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:48.833647966 CEST4434971084.32.84.32192.168.2.4
                Sep 15, 2023 20:34:48.833736897 CEST49710443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:48.833923101 CEST49710443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:48.833944082 CEST4434971084.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.112677097 CEST49711443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.112725019 CEST4434971184.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.112827063 CEST49711443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.113409042 CEST49711443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.113428116 CEST4434971184.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.440172911 CEST4434971084.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.440284967 CEST4434971084.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.440362930 CEST49710443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.528860092 CEST49710443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.528922081 CEST4434971084.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.533351898 CEST49712443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.533406973 CEST4434971284.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.533489943 CEST49712443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.535629988 CEST49712443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.535646915 CEST4434971284.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.723227978 CEST4434971184.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.723371983 CEST4434971184.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.723434925 CEST49711443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.770287991 CEST49711443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.770325899 CEST4434971184.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.772264957 CEST49713443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.772300005 CEST4434971384.32.84.32192.168.2.4
                Sep 15, 2023 20:34:49.772367954 CEST49713443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.772921085 CEST49713443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:49.772933006 CEST4434971384.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.142343044 CEST4434971284.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.142410994 CEST4434971284.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.142518997 CEST49712443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:50.142725945 CEST49712443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:50.142751932 CEST4434971284.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.379484892 CEST4434971384.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.379575014 CEST4434971384.32.84.32192.168.2.4
                Sep 15, 2023 20:34:50.379652977 CEST49713443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:50.555361032 CEST49713443192.168.2.484.32.84.32
                Sep 15, 2023 20:34:50.555412054 CEST4434971384.32.84.32192.168.2.4
                Sep 15, 2023 20:34:51.690903902 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:51.690948963 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:51.691075087 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:51.691525936 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:51.691540003 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:51.942763090 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:51.988002062 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:52.057950020 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:52.057970047 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:52.059313059 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:52.059393883 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:52.061682940 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:52.061754942 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:52.112894058 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:34:52.112916946 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:34:52.159785986 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:35:01.930861950 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:35:01.930963039 CEST44349716172.217.1.4192.168.2.4
                Sep 15, 2023 20:35:01.931020975 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:35:02.453721046 CEST49716443192.168.2.4172.217.1.4
                Sep 15, 2023 20:35:02.453803062 CEST44349716172.217.1.4192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Sep 15, 2023 20:34:47.598834038 CEST6031653192.168.2.48.8.8.8
                Sep 15, 2023 20:34:47.599294901 CEST5181653192.168.2.48.8.8.8
                Sep 15, 2023 20:34:47.599886894 CEST5139153192.168.2.48.8.8.8
                Sep 15, 2023 20:34:47.600240946 CEST4978553192.168.2.48.8.8.8
                Sep 15, 2023 20:34:47.697415113 CEST53513918.8.8.8192.168.2.4
                Sep 15, 2023 20:34:47.697767019 CEST53603168.8.8.8192.168.2.4
                Sep 15, 2023 20:34:47.699219942 CEST53497858.8.8.8192.168.2.4
                Sep 15, 2023 20:34:47.699615002 CEST53518168.8.8.8192.168.2.4
                Sep 15, 2023 20:34:47.700159073 CEST53633628.8.8.8192.168.2.4
                Sep 15, 2023 20:34:48.455482006 CEST53625508.8.8.8192.168.2.4
                Sep 15, 2023 20:34:48.713219881 CEST6480353192.168.2.48.8.8.8
                Sep 15, 2023 20:34:48.714183092 CEST6482953192.168.2.48.8.8.8
                Sep 15, 2023 20:34:48.831976891 CEST53648298.8.8.8192.168.2.4
                Sep 15, 2023 20:34:48.832830906 CEST53648038.8.8.8192.168.2.4
                Sep 15, 2023 20:34:50.929955959 CEST53520868.8.8.8192.168.2.4
                Sep 15, 2023 20:34:51.586590052 CEST5486353192.168.2.48.8.8.8
                Sep 15, 2023 20:34:51.587101936 CEST5539853192.168.2.48.8.8.8
                Sep 15, 2023 20:34:51.678225994 CEST53553988.8.8.8192.168.2.4
                Sep 15, 2023 20:34:51.683698893 CEST53548638.8.8.8192.168.2.4
                Sep 15, 2023 20:35:05.491620064 CEST53523598.8.8.8192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Sep 15, 2023 20:34:47.598834038 CEST192.168.2.48.8.8.80xe9abStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:47.599294901 CEST192.168.2.48.8.8.80x5871Standard query (0)clients2.google.com65IN (0x0001)false
                Sep 15, 2023 20:34:47.599886894 CEST192.168.2.48.8.8.80xeb1bStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:47.600240946 CEST192.168.2.48.8.8.80x4f1aStandard query (0)accounts.google.com65IN (0x0001)false
                Sep 15, 2023 20:34:48.713219881 CEST192.168.2.48.8.8.80x2d70Standard query (0)forumflowequipment.comA (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:48.714183092 CEST192.168.2.48.8.8.80xd050Standard query (0)forumflowequipment.com65IN (0x0001)false
                Sep 15, 2023 20:34:51.586590052 CEST192.168.2.48.8.8.80xbe15Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:51.587101936 CEST192.168.2.48.8.8.80x2cd4Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Sep 15, 2023 20:34:47.697415113 CEST8.8.8.8192.168.2.40xeb1bNo error (0)accounts.google.com142.251.41.77A (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:47.697767019 CEST8.8.8.8192.168.2.40xe9abNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Sep 15, 2023 20:34:47.697767019 CEST8.8.8.8192.168.2.40xe9abNo error (0)clients.l.google.com142.251.32.78A (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:47.699615002 CEST8.8.8.8192.168.2.40x5871No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Sep 15, 2023 20:34:48.832830906 CEST8.8.8.8192.168.2.40x2d70No error (0)forumflowequipment.com84.32.84.32A (IP address)IN (0x0001)false
                Sep 15, 2023 20:34:51.678225994 CEST8.8.8.8192.168.2.40x2cd4No error (0)www.google.com65IN (0x0001)false
                Sep 15, 2023 20:34:51.683698893 CEST8.8.8.8192.168.2.40xbe15No error (0)www.google.com172.217.1.4A (IP address)IN (0x0001)false
                • accounts.google.com
                • clients2.google.com
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.449709142.251.41.77443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-09-15 18:34:47 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g
                2023-09-15 18:34:47 UTC0OUTData Raw: 20
                Data Ascii:
                2023-09-15 18:34:48 UTC2INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Fri, 15 Sep 2023 18:34:48 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Cross-Origin-Opener-Policy: same-origin
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-9m6S2zvZcT46-TRUK1BC_g' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-09-15 18:34:48 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2023-09-15 18:34:48 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.449708142.251.32.78443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-09-15 18:34:47 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-115.0.5790.171
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                2023-09-15 18:34:48 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-dNYQkwyfULYtenl5Ejud7Q' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Fri, 15 Sep 2023 18:34:48 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6101
                X-Daystart: 41688
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-09-15 18:34:48 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 30 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 31 36 38 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6101" elapsed_seconds="41688"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2023-09-15 18:34:48 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2023-09-15 18:34:48 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                05101520s020406080100

                Click to jump to process

                05101520s0.0020406080100MB

                Click to jump to process

                Target ID:0
                Start time:20:34:44
                Start date:15/09/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff7c94b0000
                File size:3'219'224 bytes
                MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:20:34:45
                Start date:15/09/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2484 --field-trial-handle=2340,i,948603337675666231,5668153619294458144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff7c94b0000
                File size:3'219'224 bytes
                MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:20:34:47
                Start date:15/09/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://forumflowequipment.com/&c=E,1,f_FK1IMq8cRiDtjkPIJshof-GJF-qtdgUzu2bdmrWPeCZNN5yVrVaRqJberCHZM2GRGkElotgPjZBCHMj8YKaNLY0D2P46SsdKogRNVa1dk,&typo=1
                Imagebase:0x7ff7c94b0000
                File size:3'219'224 bytes
                MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly