Edit tour

Windows Analysis Report
https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2

Overview

General Information

Sample URL:https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxq
Analysis ID:1310902
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5540 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 5376 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1664,i,11880802162428837991,10559651048564741493,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 6396 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_5540_1934127436Jump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz HTTP/1.1Host: u1706222.ct.sendgrid.netConnection: keep-alivesec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: u1706222.ct.sendgrid.netConnection: keep-alivesec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwzAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 19 Sep 2023 15:57:26 GMTContent-Type: text/htmlContent-Length: 564Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Dvrtrktau_uydMvoGc1_xfN2ULJBRPHxz6q2oM2aufczSxk8Cchv3g2jlLVO-eHXlJ_BwPi1P-zYcjdR9AuTyG10jrJ2AzQ7yL8SBUliEafdzZn70Pmm-r8GrPXaz7LFgctn_yZRHpJXI09tbP_WroWCmYwT_a7Fwj8gHnQ5nbY; AEC=Ad49MVGGktvnyMQBXjxfVM4VyQMgBORLkDWV_5bpQs3oS50vEqIAFgkFMBQ; CONSENT=PENDING+008; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmRlIAEaBgiA0dCmBg; __Secure-ENID=14.SE=ASWfeSSVBcK3LyggZgGhgI5yIs3Z2wYpfR6yuK81LiYU6I0bFs937AKcakQoHnJkxVLloWnpVW_r8Ar2dupLdGHUm260SY6_u_8bKbtIVuC2UT3_Sjp3_6n5MjyjVSOfngggQke4VZle0rxsEtTK1UwAzXaROx3bb_2_jH9Xta1jpoaREw
Source: classification engineClassification label: clean0.win@18/2@8/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_5540_1934127436Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1664,i,11880802162428837991,10559651048564741493,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1664,i,11880802162428837991,10559651048564741493,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_5540_1934127436Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1310902 URL: https://u1706222.ct.sendgri... Startdate: 19/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 192.168.2.30 unknown unknown 5->15 17 239.255.255.250 unknown Reserved 5->17 10 chrome.exe 5->10         started        process4 dnsIp5 19 u1706222.ct.sendgrid.net 167.89.115.121, 443, 49729, 49730 SENDGRIDUS United States 10->19 21 www.google.com 172.217.13.100, 443, 49731, 49755 GOOGLEUS United States 10->21 23 3 other IPs or domains 10->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.13.141
truefalse
    high
    www.google.com
    172.217.13.100
    truefalse
      high
      clients.l.google.com
      172.217.13.174
      truefalse
        high
        u1706222.ct.sendgrid.net
        167.89.115.121
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://u1706222.ct.sendgrid.net/favicon.icofalse
              high
              https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwzfalse
                high
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    167.89.115.121
                    u1706222.ct.sendgrid.netUnited States
                    11377SENDGRIDUSfalse
                    172.217.13.100
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    172.217.13.141
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    172.217.13.174
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.30
                    192.168.2.1
                    Joe Sandbox Version:38.0.0 Beryl
                    Analysis ID:1310902
                    Start date and time:2023-09-19 17:56:33 +02:00
                    Joe Sandbox Product:CloudBasic
                    Overall analysis duration:0h 2m 56s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz
                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                    Number of analysed new started processes analysed:16
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@18/2@8/7
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
                    • Excluded IPs from analysis (whitelisted): 20.54.24.169, 104.127.77.185, 172.217.13.99, 34.104.35.123, 172.217.13.195
                    • Excluded domains from analysis (whitelisted): www.bing.com, geo.prod.do.dsp.trafficmanager.net, geo.prod.do.dsp.mp.microsoft.com, e12358.d.akamaiedge.net, tse1.mm.bing.net, clientservices.googleapis.com, arc.msn.com, array613.prod.do.dsp.mp.microsoft.com, kv601.prod.do.dsp.mp.microsoft.com, kv601.prod.do.dsp.mp.microsoft.com.edgekey.net, edgedl.me.gvt1.com, update.googleapis.com, displaycatalog.mp.microsoft.com
                    • Not all processes where analyzed, report is missing behavior information
                    • VT rate limit hit for: https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with no line terminators
                    Category:downloaded
                    Size (bytes):291
                    Entropy (8bit):4.477778146874743
                    Encrypted:false
                    SSDEEP:6:qzxUsjMR1X96b2+Ubghxc8le3rn9MGzMd4aa6++Oix9qD:kxBMR1knUkhGXpPoa6++3xMD
                    MD5:F0C66914A58FC74FC98A7C9BB4C288F2
                    SHA1:3E0E43F567138623CABFF91C14100D144AC56949
                    SHA-256:54E173BE753D03B2C163CEBBEE02BE7F4BDC1D6663154D4D60A3833F7BA3436B
                    SHA-512:7AEDAEBA112D43E2B2FF845355199A11A141D637C0306155BE2356AE297DF118D2C0D2768D44C35A1D89841DB428E95686E29E9D15DEADF4233F3713893514BF
                    Malicious:false
                    Reputation:low
                    URL:https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz
                    Preview:<html><head><title>Wrong Link</title></head><body><h1>Wrong Link</h1><p>You have clicked on an invalid link. Please make sure that you have typed the link correctly. If are copying this link from a mail reader please ensure that you have copied all the lines in the link.</p></body></html>
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):564
                    Entropy (8bit):4.72971822420855
                    Encrypted:false
                    SSDEEP:12:TjeRHdHiHZdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH988DTPTPTPTPTPTc
                    MD5:8E325DC2FEA7C8900FC6C4B8C6C394FE
                    SHA1:1B3291D4EEA179C84145B2814CB53E6A506EC201
                    SHA-256:0B52C5338AF355699530A47683420E48C7344E779D3E815FF9943CBFDC153CF2
                    SHA-512:084C608F1F860FB08EF03B155658EA9988B3628D3C0F0E9561FDFF930E5912004CDDBCC43B1FA90C21FE7F5A481AC47C64B8CAA066C2BDF3CF533E152BF96C14
                    Malicious:false
                    Reputation:low
                    URL:https://u1706222.ct.sendgrid.net/favicon.ico
                    Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 68
                    • 443 (HTTPS)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Sep 19, 2023 17:57:23.037506104 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.037600040 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.037672997 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.037826061 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.037843943 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.037909985 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.038117886 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.038151026 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.038423061 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.038451910 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.332925081 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.333086967 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.333151102 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.333190918 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.333267927 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.333301067 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.333853960 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.333930969 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.335103989 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.335105896 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.335211039 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.335211039 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.336416006 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.336510897 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.336951017 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.336982012 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.337107897 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.337208986 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.337234974 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.380650043 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.384716034 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.385426044 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.385457993 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.431613922 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.537391901 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.537579060 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.537666082 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.539540052 CEST49728443192.168.2.5172.217.13.174
                    Sep 19, 2023 17:57:23.539581060 CEST44349728172.217.13.174192.168.2.5
                    Sep 19, 2023 17:57:23.544841051 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.545211077 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:23.545290947 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.546206951 CEST49727443192.168.2.5172.217.13.141
                    Sep 19, 2023 17:57:23.546221972 CEST44349727172.217.13.141192.168.2.5
                    Sep 19, 2023 17:57:25.486531019 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.486582041 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.486668110 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.486975908 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.486989975 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.487703085 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.487761021 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.487814903 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.487947941 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.487963915 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.790292978 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.801934004 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.825992107 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.826016903 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.826186895 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.826239109 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.827254057 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.827331066 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.829293966 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.829423904 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.829588890 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.829607010 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.830138922 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.830228090 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.831269979 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.831496000 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.870289087 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.871290922 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.871361017 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.911297083 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.927226067 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.927331924 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:25.927390099 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.929637909 CEST49729443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:25.929666996 CEST44349729167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:26.058727980 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:26.058901072 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:26.156611919 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:26.156721115 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:26.156809092 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:26.158633947 CEST49730443192.168.2.5167.89.115.121
                    Sep 19, 2023 17:57:26.158662081 CEST44349730167.89.115.121192.168.2.5
                    Sep 19, 2023 17:57:27.259624004 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.259684086 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.259783983 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.260391951 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.260411024 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.483747005 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.484173059 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.484198093 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.485274076 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.485363007 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.796657085 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.797245026 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.838053942 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:27.838139057 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:27.884991884 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:37.462780952 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:37.462857008 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:57:37.462934017 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:40.744401932 CEST49731443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:57:40.744426966 CEST44349731172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.215591908 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:27.215626001 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.215748072 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:27.216375113 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:27.216388941 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.443079948 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.443851948 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:27.443886995 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.444575071 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.445705891 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:27.445806980 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:27.491050959 CEST49755443192.168.2.5172.217.13.100
                    Sep 19, 2023 17:58:37.430303097 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:37.430468082 CEST44349755172.217.13.100192.168.2.5
                    Sep 19, 2023 17:58:37.430572033 CEST49755443192.168.2.5172.217.13.100
                    TimestampSource PortDest PortSource IPDest IP
                    Sep 19, 2023 17:57:22.936233997 CEST6421953192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:22.936567068 CEST5525253192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:22.937063932 CEST6499753192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:22.937321901 CEST6244953192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:23.033134937 CEST53604228.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:23.033447981 CEST53642198.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:23.033484936 CEST53552528.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:23.035062075 CEST53649978.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:23.036506891 CEST53624498.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:23.687011957 CEST53530078.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:25.369009972 CEST5604653192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:25.369354963 CEST5151353192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:25.466939926 CEST53560468.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:25.469073057 CEST53515138.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:27.164680958 CEST5494753192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:27.165328979 CEST5246553192.168.2.58.8.8.8
                    Sep 19, 2023 17:57:27.255800962 CEST53549478.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:27.255887032 CEST53524658.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:40.842190027 CEST53632758.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:47.805288076 CEST53632408.8.8.8192.168.2.5
                    Sep 19, 2023 17:57:58.401904106 CEST53641018.8.8.8192.168.2.5
                    Sep 19, 2023 17:58:16.120711088 CEST53516498.8.8.8192.168.2.5
                    Sep 19, 2023 17:58:22.643099070 CEST53600708.8.8.8192.168.2.5
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Sep 19, 2023 17:57:22.936233997 CEST192.168.2.58.8.8.80x8b51Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:22.936567068 CEST192.168.2.58.8.8.80xabd1Standard query (0)accounts.google.com65IN (0x0001)false
                    Sep 19, 2023 17:57:22.937063932 CEST192.168.2.58.8.8.80xe02dStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:22.937321901 CEST192.168.2.58.8.8.80x70ccStandard query (0)clients2.google.com65IN (0x0001)false
                    Sep 19, 2023 17:57:25.369009972 CEST192.168.2.58.8.8.80xfde2Standard query (0)u1706222.ct.sendgrid.netA (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:25.369354963 CEST192.168.2.58.8.8.80x7866Standard query (0)u1706222.ct.sendgrid.net65IN (0x0001)false
                    Sep 19, 2023 17:57:27.164680958 CEST192.168.2.58.8.8.80x3ee8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:27.165328979 CEST192.168.2.58.8.8.80x5806Standard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Sep 19, 2023 17:57:23.033447981 CEST8.8.8.8192.168.2.50x8b51No error (0)accounts.google.com172.217.13.141A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:23.035062075 CEST8.8.8.8192.168.2.50xe02dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Sep 19, 2023 17:57:23.035062075 CEST8.8.8.8192.168.2.50xe02dNo error (0)clients.l.google.com172.217.13.174A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:23.036506891 CEST8.8.8.8192.168.2.50x70ccNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Sep 19, 2023 17:57:25.466939926 CEST8.8.8.8192.168.2.50xfde2No error (0)u1706222.ct.sendgrid.net167.89.115.121A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:25.466939926 CEST8.8.8.8192.168.2.50xfde2No error (0)u1706222.ct.sendgrid.net167.89.123.122A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:25.466939926 CEST8.8.8.8192.168.2.50xfde2No error (0)u1706222.ct.sendgrid.net167.89.115.54A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:25.466939926 CEST8.8.8.8192.168.2.50xfde2No error (0)u1706222.ct.sendgrid.net167.89.123.16A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:27.255800962 CEST8.8.8.8192.168.2.50x3ee8No error (0)www.google.com172.217.13.100A (IP address)IN (0x0001)false
                    Sep 19, 2023 17:57:27.255887032 CEST8.8.8.8192.168.2.50x5806No error (0)www.google.com65IN (0x0001)false
                    • clients2.google.com
                    • accounts.google.com
                    • u1706222.ct.sendgrid.net
                    • https:
                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.2.549728172.217.13.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-09-19 15:57:23 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-115.0.5790.171
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-09-19 15:57:23 UTC1INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-zVny-U3uVhB8UiZE0az2HQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Tue, 19 Sep 2023 15:57:23 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6105
                    X-Daystart: 32243
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-09-19 15:57:23 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 30 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 32 32 34 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6105" elapsed_seconds="32243"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2023-09-19 15:57:23 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2023-09-19 15:57:23 UTC3INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.2.549727172.217.13.141443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-09-19 15:57:23 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=Dvrtrktau_uydMvoGc1_xfN2ULJBRPHxz6q2oM2aufczSxk8Cchv3g2jlLVO-eHXlJ_BwPi1P-zYcjdR9AuTyG10jrJ2AzQ7yL8SBUliEafdzZn70Pmm-r8GrPXaz7LFgctn_yZRHpJXI09tbP_WroWCmYwT_a7Fwj8gHnQ5nbY; AEC=Ad49MVGGktvnyMQBXjxfVM4VyQMgBORLkDWV_5bpQs3oS50vEqIAFgkFMBQ; CONSENT=PENDING+008; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmRlIAEaBgiA0dCmBg; __Secure-ENID=14.SE=ASWfeSSVBcK3LyggZgGhgI5yIs3Z2wYpfR6yuK81LiYU6I0bFs937AKcakQoHnJkxVLloWnpVW_r8Ar2dupLdGHUm260SY6_u_8bKbtIVuC2UT3_Sjp3_6n5MjyjVSOfngggQke4VZle0rxsEtTK1UwAzXaROx3bb_2_jH9Xta1jpoaREw
                    2023-09-19 15:57:23 UTC1OUTData Raw: 20
                    Data Ascii:
                    2023-09-19 15:57:23 UTC3INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Tue, 19 Sep 2023 15:57:23 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Cross-Origin-Opener-Policy: same-origin
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Content-Security-Policy: script-src 'report-sample' 'nonce-3aNSx0u7a2tyFQv9ZLvKYA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-09-19 15:57:23 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2023-09-19 15:57:23 UTC4INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    2192.168.2.549729167.89.115.121443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-09-19 15:57:25 UTC4OUTGET /ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz HTTP/1.1
                    Host: u1706222.ct.sendgrid.net
                    Connection: keep-alive
                    sec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-09-19 15:57:25 UTC6INHTTP/1.1 400 Bad Request
                    Server: nginx
                    Date: Tue, 19 Sep 2023 15:57:25 GMT
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 291
                    Connection: close
                    X-Robots-Tag: noindex, nofollow
                    2023-09-19 15:57:25 UTC6INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 57 72 6f 6e 67 20 4c 69 6e 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 68 31 3e 57 72 6f 6e 67 20 4c 69 6e 6b 3c 2f 68 31 3e 3c 70 3e 59 6f 75 20 68 61 76 65 20 63 6c 69 63 6b 65 64 20 6f 6e 20 61 6e 20 69 6e 76 61 6c 69 64 20 6c 69 6e 6b 2e 20 20 50 6c 65 61 73 65 20 6d 61 6b 65 20 73 75 72 65 20 74 68 61 74 20 79 6f 75 20 68 61 76 65 20 74 79 70 65 64 20 74 68 65 20 6c 69 6e 6b 20 63 6f 72 72 65 63 74 6c 79 2e 20 20 49 66 20 61 72 65 20 63 6f 70 79 69 6e 67 20 74 68 69 73 20 6c 69 6e 6b 20 66 72 6f 6d 20 61 20 6d 61 69 6c 20 72 65 61 64 65 72 20 70 6c 65 61 73 65 20 65 6e 73 75 72 65 20 74 68 61 74 20 79 6f 75 20 68 61 76 65 20 63 6f 70 69 65 64 20 61 6c 6c 20 74 68 65 20
                    Data Ascii: <html><head><title>Wrong Link</title></head><body><h1>Wrong Link</h1><p>You have clicked on an invalid link. Please make sure that you have typed the link correctly. If are copying this link from a mail reader please ensure that you have copied all the


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    3192.168.2.549730167.89.115.121443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-09-19 15:57:26 UTC6OUTGET /favicon.ico HTTP/1.1
                    Host: u1706222.ct.sendgrid.net
                    Connection: keep-alive
                    sec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-09-19 15:57:26 UTC8INHTTP/1.1 404 Not Found
                    Server: nginx
                    Date: Tue, 19 Sep 2023 15:57:26 GMT
                    Content-Type: text/html
                    Content-Length: 564
                    Connection: close
                    2023-09-19 15:57:26 UTC8INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20
                    Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0020406080100MB

                    Click to jump to process

                    Target ID:0
                    Start time:17:57:21
                    Start date:19/09/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff71d210000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:1
                    Start time:17:57:21
                    Start date:19/09/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1664,i,11880802162428837991,10559651048564741493,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff71d210000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:17:57:24
                    Start date:19/09/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz
                    Imagebase:0x7ff71d210000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly