Edit tour

Windows Analysis Report
http://ocsp.comodoca.com

Overview

General Information

Sample URL:http://ocsp.comodoca.com
Analysis ID:1311331
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4184 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 5676 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1900,i,14344208870052703514,2652058672083317183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 5376 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ocsp.comodoca.com MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_4184_1728723692Jump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=Ad49MVGiijyX5dxPFAKxKYso-rIS24Ht-Pxs5fU9hHrAzfASnm-jqdQE1g; NID=511=WyMJovC2uA2AEbHQkGfP-KDdYCeg5Q7Mv6gxYT-qeugtrnXImrhmp1SixwS4ydh_E8Z0hdfCLAXvg2WUqsBSfqpx5SFvCCoeGeevqlEfkoxYi9FTISb8Cu7rr5rf9PyyNbLqf2QbxG7ja7jAB6UJQd5CPvMGcYUasORCRKRL1-arNYzfADAWHJvBLXml-Km_uewDreOyJ-MjxAI-i38Tl6LXI3zB
Source: classification engineClassification label: clean0.win@20/4@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_4184_1728723692Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1900,i,14344208870052703514,2652058672083317183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ocsp.comodoca.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1900,i,14344208870052703514,2652058672083317183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\8280d251-6fa4-461e-b9a2-6fbfd610f37d.tmpJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_4184_1728723692Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1311331 URL: http://ocsp.comodoca.com Startdate: 20/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 13 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 172.217.13.100, 443, 49718, 49734 GOOGLEUS United States 10->17 19 accounts.google.com 172.217.13.141, 443, 49713 GOOGLEUS United States 10->19 21 2 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ocsp.comodoca.com0%VirustotalBrowse
http://ocsp.comodoca.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.13.141
truefalse
    high
    www.google.com
    172.217.13.100
    truefalse
      high
      clients.l.google.com
      172.217.13.174
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.217.13.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              172.217.13.141
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              172.217.13.174
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              Joe Sandbox Version:38.0.0 Beryl
              Analysis ID:1311331
              Start date and time:2023-09-20 08:45:54 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 3m 29s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://ocsp.comodoca.com
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:20
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@20/4@6/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.13.99, 34.104.35.123, 104.18.14.101, 104.18.15.101, 204.79.197.200, 13.107.21.200, 172.217.13.195
              • Excluded domains from analysis (whitelisted): www.bing.com, ocsp.comodoca.com.cdn.cloudflare.net, dual-a-0001.a-msedge.net, tse1.mm.bing.net, clientservices.googleapis.com, arc.msn.com, www-www.bing.com.trafficmanager.net, ocsp.comodoca.com, edgedl.me.gvt1.com, login.live.com, www-bing-com.dual-a-0001.a-msedge.net, update.googleapis.com, displaycatalog.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:dropped
              Size (bytes):5
              Entropy (8bit):1.9219280948873623
              Encrypted:false
              SSDEEP:3:w:w
              MD5:4842E206E4CFFF2954901467AD54169E
              SHA1:80C9820FF2EFE8AA3D361DF7011AE6EEE35EC4F0
              SHA-256:2ACAB1228E8935D5DFDD1756B8A19698B6C8B786C90F87993CE9799A67A96E4E
              SHA-512:FF537B1808FCB03CFB52F768FBD7E7BD66BAF6A8558EE5B8F2A02F629E021AA88A1DF7A8750BAE1F04F3B9D86DA56F0BDCBA2FDBC81D366DA6C97EB76ECB6CBA
              Malicious:false
              Reputation:low
              Preview:0....
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:dropped
              Size (bytes):5
              Entropy (8bit):1.9219280948873623
              Encrypted:false
              SSDEEP:3:w:w
              MD5:4842E206E4CFFF2954901467AD54169E
              SHA1:80C9820FF2EFE8AA3D361DF7011AE6EEE35EC4F0
              SHA-256:2ACAB1228E8935D5DFDD1756B8A19698B6C8B786C90F87993CE9799A67A96E4E
              SHA-512:FF537B1808FCB03CFB52F768FBD7E7BD66BAF6A8558EE5B8F2A02F629E021AA88A1DF7A8750BAE1F04F3B9D86DA56F0BDCBA2FDBC81D366DA6C97EB76ECB6CBA
              Malicious:false
              Reputation:low
              Preview:0....
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:dropped
              Size (bytes):5
              Entropy (8bit):1.9219280948873623
              Encrypted:false
              SSDEEP:3:w:w
              MD5:4842E206E4CFFF2954901467AD54169E
              SHA1:80C9820FF2EFE8AA3D361DF7011AE6EEE35EC4F0
              SHA-256:2ACAB1228E8935D5DFDD1756B8A19698B6C8B786C90F87993CE9799A67A96E4E
              SHA-512:FF537B1808FCB03CFB52F768FBD7E7BD66BAF6A8558EE5B8F2A02F629E021AA88A1DF7A8750BAE1F04F3B9D86DA56F0BDCBA2FDBC81D366DA6C97EB76ECB6CBA
              Malicious:false
              Reputation:low
              Preview:0....
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:downloaded
              Size (bytes):5
              Entropy (8bit):1.9219280948873623
              Encrypted:false
              SSDEEP:3:w:w
              MD5:4842E206E4CFFF2954901467AD54169E
              SHA1:80C9820FF2EFE8AA3D361DF7011AE6EEE35EC4F0
              SHA-256:2ACAB1228E8935D5DFDD1756B8A19698B6C8B786C90F87993CE9799A67A96E4E
              SHA-512:FF537B1808FCB03CFB52F768FBD7E7BD66BAF6A8558EE5B8F2A02F629E021AA88A1DF7A8750BAE1F04F3B9D86DA56F0BDCBA2FDBC81D366DA6C97EB76ECB6CBA
              Malicious:false
              Reputation:low
              URL:http://ocsp.comodoca.com/
              Preview:0....
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 46
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Sep 20, 2023 08:46:44.677966118 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.678059101 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.678159952 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.679439068 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.679474115 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.682914972 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.682997942 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.683083057 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.683748960 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.683778048 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.941623926 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.942482948 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.942554951 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.944423914 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.944506884 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.947252989 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.947365999 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.947520971 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:44.947534084 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:44.982585907 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.983196974 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.983279943 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.983789921 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.984030008 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.985253096 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.985327005 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.986619949 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.986713886 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:44.986721992 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:44.993321896 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:45.028759003 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:45.040544033 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:45.040661097 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:45.087090015 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:45.167650938 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:45.167824984 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:45.167896986 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:45.169358969 CEST49713443192.168.2.3172.217.13.141
              Sep 20, 2023 08:46:45.169379950 CEST44349713172.217.13.141192.168.2.3
              Sep 20, 2023 08:46:45.184175968 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:45.184324980 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:45.184386969 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:45.185221910 CEST49715443192.168.2.3172.217.13.174
              Sep 20, 2023 08:46:45.185266972 CEST44349715172.217.13.174192.168.2.3
              Sep 20, 2023 08:46:48.746536970 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.746592999 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:48.746655941 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.746893883 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.746908903 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:48.972253084 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:48.977809906 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.977833033 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:48.979429007 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:48.979513884 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.980792999 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:48.980878115 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:49.028975964 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:49.028996944 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:49.075968027 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:46:59.005049944 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:59.005220890 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:46:59.005295038 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:02.251410007 CEST49718443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:02.251446009 CEST44349718172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.699018002 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:48.699045897 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.699114084 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:48.699415922 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:48.699425936 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.926867008 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.927112103 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:48.927124023 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.927567005 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.927917957 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:48.927995920 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:48.968070984 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:47:58.919122934 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:58.919274092 CEST44349734172.217.13.100192.168.2.3
              Sep 20, 2023 08:47:58.919336081 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:48:24.141829967 CEST49734443192.168.2.3172.217.13.100
              Sep 20, 2023 08:48:24.141874075 CEST44349734172.217.13.100192.168.2.3
              TimestampSource PortDest PortSource IPDest IP
              Sep 20, 2023 08:46:44.578807116 CEST5321053192.168.2.38.8.8.8
              Sep 20, 2023 08:46:44.579173088 CEST6348153192.168.2.38.8.8.8
              Sep 20, 2023 08:46:44.579602957 CEST6126153192.168.2.38.8.8.8
              Sep 20, 2023 08:46:44.579865932 CEST5167453192.168.2.38.8.8.8
              Sep 20, 2023 08:46:44.675666094 CEST53532108.8.8.8192.168.2.3
              Sep 20, 2023 08:46:44.676320076 CEST53612618.8.8.8192.168.2.3
              Sep 20, 2023 08:46:44.676433086 CEST53516748.8.8.8192.168.2.3
              Sep 20, 2023 08:46:44.680039883 CEST53508428.8.8.8192.168.2.3
              Sep 20, 2023 08:46:44.682285070 CEST53634818.8.8.8192.168.2.3
              Sep 20, 2023 08:46:45.355792999 CEST53594898.8.8.8192.168.2.3
              Sep 20, 2023 08:46:48.648083925 CEST6163653192.168.2.38.8.8.8
              Sep 20, 2023 08:46:48.648319006 CEST5969753192.168.2.38.8.8.8
              Sep 20, 2023 08:46:48.741990089 CEST53596978.8.8.8192.168.2.3
              Sep 20, 2023 08:46:48.745554924 CEST53616368.8.8.8192.168.2.3
              Sep 20, 2023 08:47:02.351003885 CEST53637198.8.8.8192.168.2.3
              Sep 20, 2023 08:47:08.992546082 CEST53533048.8.8.8192.168.2.3
              Sep 20, 2023 08:47:19.253418922 CEST53501938.8.8.8192.168.2.3
              Sep 20, 2023 08:47:37.850183964 CEST53651548.8.8.8192.168.2.3
              Sep 20, 2023 08:47:43.905097961 CEST53640978.8.8.8192.168.2.3
              Sep 20, 2023 08:48:24.241982937 CEST53590848.8.8.8192.168.2.3
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 20, 2023 08:46:44.578807116 CEST192.168.2.38.8.8.80x7912Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Sep 20, 2023 08:46:44.579173088 CEST192.168.2.38.8.8.80x58f9Standard query (0)clients2.google.com65IN (0x0001)false
              Sep 20, 2023 08:46:44.579602957 CEST192.168.2.38.8.8.80xcaa6Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Sep 20, 2023 08:46:44.579865932 CEST192.168.2.38.8.8.80xd69eStandard query (0)accounts.google.com65IN (0x0001)false
              Sep 20, 2023 08:46:48.648083925 CEST192.168.2.38.8.8.80x50ceStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 20, 2023 08:46:48.648319006 CEST192.168.2.38.8.8.80x1cbdStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 20, 2023 08:46:44.675666094 CEST8.8.8.8192.168.2.30x7912No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Sep 20, 2023 08:46:44.675666094 CEST8.8.8.8192.168.2.30x7912No error (0)clients.l.google.com172.217.13.174A (IP address)IN (0x0001)false
              Sep 20, 2023 08:46:44.676320076 CEST8.8.8.8192.168.2.30xcaa6No error (0)accounts.google.com172.217.13.141A (IP address)IN (0x0001)false
              Sep 20, 2023 08:46:44.682285070 CEST8.8.8.8192.168.2.30x58f9No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Sep 20, 2023 08:46:48.741990089 CEST8.8.8.8192.168.2.30x1cbdNo error (0)www.google.com65IN (0x0001)false
              Sep 20, 2023 08:46:48.745554924 CEST8.8.8.8192.168.2.30x50ceNo error (0)www.google.com172.217.13.100A (IP address)IN (0x0001)false
              • accounts.google.com
              • clients2.google.com
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349713172.217.13.141443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-09-20 06:46:44 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: CONSENT=PENDING+904; AEC=Ad49MVGiijyX5dxPFAKxKYso-rIS24Ht-Pxs5fU9hHrAzfASnm-jqdQE1g; NID=511=WyMJovC2uA2AEbHQkGfP-KDdYCeg5Q7Mv6gxYT-qeugtrnXImrhmp1SixwS4ydh_E8Z0hdfCLAXvg2WUqsBSfqpx5SFvCCoeGeevqlEfkoxYi9FTISb8Cu7rr5rf9PyyNbLqf2QbxG7ja7jAB6UJQd5CPvMGcYUasORCRKRL1-arNYzfADAWHJvBLXml-Km_uewDreOyJ-MjxAI-i38Tl6LXI3zB
              2023-09-20 06:46:44 UTC0OUTData Raw: 20
              Data Ascii:
              2023-09-20 06:46:45 UTC1INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 20 Sep 2023 06:46:45 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Cross-Origin-Opener-Policy: same-origin
              Content-Security-Policy: script-src 'report-sample' 'nonce-Js0VYAiUr7dhfcPYqVZdAg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-09-20 06:46:45 UTC3INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-09-20 06:46:45 UTC3INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349715172.217.13.174443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-09-20 06:46:44 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-115.0.5790.171
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-09-20 06:46:45 UTC3INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-mklT51QgDYqSsNSZgVreOA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 20 Sep 2023 06:46:45 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 6105
              X-Daystart: 85605
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-09-20 06:46:45 UTC3INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 30 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 38 35 36 30 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6105" elapsed_seconds="85605"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-09-20 06:46:45 UTC4INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-09-20 06:46:45 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              050100s020406080100

              Click to jump to process

              050100s0.0050100MB

              Click to jump to process

              Target ID:0
              Start time:08:46:41
              Start date:20/09/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff67bb30000
              File size:3'219'224 bytes
              MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:1
              Start time:08:46:42
              Start date:20/09/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1900,i,14344208870052703514,2652058672083317183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff67bb30000
              File size:3'219'224 bytes
              MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:08:46:44
              Start date:20/09/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ocsp.comodoca.com
              Imagebase:0x7ff67bb30000
              File size:3'219'224 bytes
              MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly