Edit tour

Windows Analysis Report
https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css

Overview

General Information

Sample URL:https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
Analysis ID:1316003
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 284 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 1380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1868,i,13777395388417949586,10569662479068141225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 6280 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.cssHTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_284_1797434839Jump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g; 1P_JAR=2023-09-25-09; NID=511=SzLVLHQSmPvgkoqmP-MsqjETq9dQ36QVm_qf2IzzhOCW0fFPsDTYGrt2nIMcjA4Ms9EAqvkswXpgrdTrGbklWuF9VUuI4kQoyRxzZJXmXGR4c2GB7bEOL6aT4Siga3gbRX-33znuEESDzU4kk1UQHyGVPHjVG8C7MD74EeDyBWQ
Source: classification engineClassification label: clean0.win@18/2@8/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_284_1797434839Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1868,i,13777395388417949586,10569662479068141225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1868,i,13777395388417949586,10569662479068141225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_284_1797434839Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1316003 URL: https://nav.files.bbci.co.u... Startdate: 28/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 accounts.google.com 142.250.65.237, 443, 49777 GOOGLEUS United States 10->17 19 www.google.com 142.251.32.100, 443, 49782, 49799 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.65.237
truefalse
    high
    www.google.com
    142.251.32.100
    truefalse
      high
      clients.l.google.com
      142.251.32.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          nav.files.bbci.co.uk
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.cssfalse
              unknown
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.251.32.110
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  142.251.32.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.65.237
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  Joe Sandbox Version:38.0.0 Beryl
                  Analysis ID:1316003
                  Start date and time:2023-09-28 19:06:10 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 2m 57s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:15
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@18/2@8/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.65.195, 34.104.35.123, 23.197.20.140, 142.251.40.163
                  • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, www.bing.com, client.wns.windows.com, edgedl.me.gvt1.com, e3891.dscf.akamaiedge.net, update.googleapis.com, tse1.mm.bing.net, clientservices.googleapis.com, arc.msn.com, nav.files.bbci.co.uk.edgekey.net
                  • Not all processes where analyzed, report is missing behavior information
                  • VT rate limit hit for: https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (27394)
                  Category:downloaded
                  Size (bytes):27395
                  Entropy (8bit):4.830641786103822
                  Encrypted:false
                  SSDEEP:768:AI3yD5doi9RxAdIbU/+77jlsRXRal9MTjmSVG:AI3yDboi9RxAdIbU/u
                  MD5:6A9A7EBAA960CF3425E3FBB53845F7E6
                  SHA1:97060ACC1D851432AD928F70C019EAE7B6423EF2
                  SHA-256:4652AF8211A5662C6F801D74CA71431AE09E152BADAA9E2FBA7AE572B9E61696
                  SHA-512:722B1DAFA4DE29063B2020EBA560C018D6800A0735B1C19FF307DBDB13E936756ECB3E32A896E7AA990DA597AF9EB70FAE38C681938701957237C80CF4D1CCDE
                  Malicious:false
                  Reputation:low
                  URL:https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
                  Preview:.orbit-ux-v4 .orb-nav-search{float:right}.orbit-ux-v4 .orb-nav-search button{padding:0}.orbit-ux-v4 .orb-nav-search .orb-search__button,.orbit-ux-v4 .orb-nav-search .orbit-search__button{cursor:pointer;border:none;overflow:hidden;text-indent:-999px;display:block;line-height:0;padding-left:0;padding-right:0}.n-no-svg .orbit-ux-v4 .orb-nav-search .orb-search__button,.n-no-svg .orbit-ux-v4 .orb-nav-search .orbit-search__button{width:32px;height:24px}.orbit-ux-v4 .orb-nav-search .ux-v4{display:block;width:20px;height:20px;background-color:rgba(0,0,0,0);background-repeat:no-repeat;background-position:center center;background-size:16px 16px;padding-left:8px;padding-right:8px}@media screen and (max-width: 599px){.orbit-ux-v4 .orb-nav-search .ux-v4{background-position:center 3px}}@media screen and (min-width: 600px){.orbit-ux-v4 .orb-nav-search .ux-v4{background-position:center center;height:30px;padding-left:12px;padding-right:12px}}@media screen and (min-width: 1280px){.orbit-ux-v4 .orb-nav-
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with no line terminators
                  Category:downloaded
                  Size (bytes):9
                  Entropy (8bit):2.94770277922009
                  Encrypted:false
                  SSDEEP:3:OFB:OFB
                  MD5:9E076F5885F5CC16A4B5AEB8DE4ADFF5
                  SHA1:475C848673A3F79FA778F01C2BD5A721D4C41707
                  SHA-256:E3EBAA16DD9D9B9FC107C42183FB6CF9D22927E1AF03DBBDFA0CCC38E4E4AC31
                  SHA-512:4D384838C78C74F56DE20DE3FE125B9FE4D40B7C9FB5D767B647F05AEDE6BF63431F4F08AC464E188E77B227BECC3AB4BA86272F30B53D91B15003D814E06D2E
                  Malicious:false
                  Reputation:low
                  URL:https://nav.files.bbci.co.uk/favicon.ico
                  Preview:Not found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 48
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 28, 2023 19:06:55.819175959 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:55.819197893 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:55.819257975 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:55.820628881 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:55.820641041 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:55.828232050 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:55.828318119 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:55.828392982 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:55.829837084 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:55.829869986 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.043009996 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.045577049 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.045650959 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.046782970 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.046858072 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.049386024 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.049557924 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.049902916 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.049932957 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.092858076 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.093449116 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.093533039 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.094052076 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.094247103 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.095164061 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.096740007 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.096740007 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.096879959 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.097280979 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.097326994 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.104268074 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.151278019 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.260453939 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.260773897 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.260854959 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.261774063 CEST49777443192.168.2.4142.250.65.237
                  Sep 28, 2023 19:06:56.261815071 CEST44349777142.250.65.237192.168.2.4
                  Sep 28, 2023 19:06:56.269706964 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.269984007 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:06:56.270056009 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.270190954 CEST49778443192.168.2.4142.251.32.110
                  Sep 28, 2023 19:06:56.270222902 CEST44349778142.251.32.110192.168.2.4
                  Sep 28, 2023 19:07:00.207912922 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.207952976 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.208007097 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.208307981 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.208319902 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.424477100 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.473745108 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.499689102 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.499705076 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.503613949 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.503717899 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.507611036 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.508059025 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.551858902 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:00.551884890 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:00.598783016 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:10.406815052 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:10.406955957 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:07:10.407075882 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:15.920696974 CEST49782443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:07:15.920747042 CEST44349782142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.327148914 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:00.327187061 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.327269077 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:00.327482939 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:00.327488899 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.527901888 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.535016060 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:00.535046101 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.535660028 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.536093950 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:00.536184072 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:00.584090948 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:10.536111116 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:10.536206961 CEST44349799142.251.32.100192.168.2.4
                  Sep 28, 2023 19:08:10.536283970 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:12.042992115 CEST49799443192.168.2.4142.251.32.100
                  Sep 28, 2023 19:08:12.043019056 CEST44349799142.251.32.100192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 28, 2023 19:06:55.717905045 CEST6409753192.168.2.48.8.8.8
                  Sep 28, 2023 19:06:55.718234062 CEST6421453192.168.2.48.8.8.8
                  Sep 28, 2023 19:06:55.718632936 CEST6174953192.168.2.48.8.8.8
                  Sep 28, 2023 19:06:55.718841076 CEST5123253192.168.2.48.8.8.8
                  Sep 28, 2023 19:06:55.815922022 CEST53513338.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:55.816205025 CEST53512328.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:55.817986965 CEST53617498.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:55.823400021 CEST53640978.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:55.827363968 CEST53642148.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:56.413945913 CEST53523758.8.8.8192.168.2.4
                  Sep 28, 2023 19:06:56.989392042 CEST5205853192.168.2.48.8.8.8
                  Sep 28, 2023 19:06:56.989768028 CEST5426553192.168.2.48.8.8.8
                  Sep 28, 2023 19:07:00.107963085 CEST4975353192.168.2.48.8.8.8
                  Sep 28, 2023 19:07:00.108076096 CEST6369653192.168.2.48.8.8.8
                  Sep 28, 2023 19:07:00.204499006 CEST53497538.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:00.206943989 CEST53636968.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:17.504019022 CEST53629888.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:20.765125036 CEST53635438.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:26.847655058 CEST53526498.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:46.638195038 CEST53539738.8.8.8192.168.2.4
                  Sep 28, 2023 19:07:56.063688040 CEST53643748.8.8.8192.168.2.4
                  Sep 28, 2023 19:08:21.746279955 CEST53559578.8.8.8192.168.2.4
                  TimestampSource IPDest IPChecksumCodeType
                  Sep 28, 2023 19:07:20.765336037 CEST192.168.2.48.8.8.8d02f(Port unreachable)Destination Unreachable
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Sep 28, 2023 19:06:55.717905045 CEST192.168.2.48.8.8.80x883Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Sep 28, 2023 19:06:55.718234062 CEST192.168.2.48.8.8.80xdb79Standard query (0)clients2.google.com65IN (0x0001)false
                  Sep 28, 2023 19:06:55.718632936 CEST192.168.2.48.8.8.80xb3faStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Sep 28, 2023 19:06:55.718841076 CEST192.168.2.48.8.8.80x55d8Standard query (0)accounts.google.com65IN (0x0001)false
                  Sep 28, 2023 19:06:56.989392042 CEST192.168.2.48.8.8.80xdb1bStandard query (0)nav.files.bbci.co.ukA (IP address)IN (0x0001)false
                  Sep 28, 2023 19:06:56.989768028 CEST192.168.2.48.8.8.80x488bStandard query (0)nav.files.bbci.co.uk65IN (0x0001)false
                  Sep 28, 2023 19:07:00.107963085 CEST192.168.2.48.8.8.80xd254Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Sep 28, 2023 19:07:00.108076096 CEST192.168.2.48.8.8.80xca9aStandard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Sep 28, 2023 19:06:55.817986965 CEST8.8.8.8192.168.2.40xb3faNo error (0)accounts.google.com142.250.65.237A (IP address)IN (0x0001)false
                  Sep 28, 2023 19:06:55.823400021 CEST8.8.8.8192.168.2.40x883No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2023 19:06:55.823400021 CEST8.8.8.8192.168.2.40x883No error (0)clients.l.google.com142.251.32.110A (IP address)IN (0x0001)false
                  Sep 28, 2023 19:06:55.827363968 CEST8.8.8.8192.168.2.40xdb79No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2023 19:06:57.086899042 CEST8.8.8.8192.168.2.40x488bNo error (0)nav.files.bbci.co.uknav.files.bbci.co.uk.edgekey.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2023 19:06:57.088764906 CEST8.8.8.8192.168.2.40xdb1bNo error (0)nav.files.bbci.co.uknav.files.bbci.co.uk.edgekey.netCNAME (Canonical name)IN (0x0001)false
                  Sep 28, 2023 19:07:00.204499006 CEST8.8.8.8192.168.2.40xd254No error (0)www.google.com142.251.32.100A (IP address)IN (0x0001)false
                  Sep 28, 2023 19:07:00.206943989 CEST8.8.8.8192.168.2.40xca9aNo error (0)www.google.com65IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.449777142.250.65.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-09-28 17:06:56 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g; 1P_JAR=2023-09-25-09; NID=511=SzLVLHQSmPvgkoqmP-MsqjETq9dQ36QVm_qf2IzzhOCW0fFPsDTYGrt2nIMcjA4Ms9EAqvkswXpgrdTrGbklWuF9VUuI4kQoyRxzZJXmXGR4c2GB7bEOL6aT4Siga3gbRX-33znuEESDzU4kk1UQHyGVPHjVG8C7MD74EeDyBWQ
                  2023-09-28 17:06:56 UTC1OUTData Raw: 20
                  Data Ascii:
                  2023-09-28 17:06:56 UTC1INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 28 Sep 2023 17:06:56 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-1Ufs8P8OX5yOC0J8ASllOg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Cross-Origin-Opener-Policy: same-origin
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-09-28 17:06:56 UTC3INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-09-28 17:06:56 UTC3INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.449778142.251.32.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-09-28 17:06:56 UTC1OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-115.0.5790.171
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  2023-09-28 17:06:56 UTC3INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-3fWGKRSgMOtCLUIg9idj-A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 28 Sep 2023 17:06:56 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 6114
                  X-Daystart: 36416
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-09-28 17:06:56 UTC4INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 31 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 36 34 31 36 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6114" elapsed_seconds="36416"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-09-28 17:06:56 UTC4INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-09-28 17:06:56 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  02040s020406080100

                  Click to jump to process

                  02040s0.0020406080100MB

                  Click to jump to process

                  Target ID:0
                  Start time:19:06:53
                  Start date:28/09/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff632090000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:1
                  Start time:19:06:53
                  Start date:28/09/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1868,i,13777395388417949586,10569662479068141225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff632090000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:19:06:55
                  Start date:28/09/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nav.files.bbci.co.uk/searchbox/653da526c08f643b172a1d3927a7670a/css/box.css
                  Imagebase:0x7ff632090000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly