Edit tour

Windows Analysis Report
http://ipv4.icanhazip.com

Overview

General Information

Sample URL:http://ipv4.icanhazip.com
Analysis ID:1316659
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1808 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 5648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1892,i,10894587477284569266,11563532355544574047,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 6324 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ipv4.icanhazip.com MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://ipv4.icanhazip.com/HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_1808_1440924176Jump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ipv4.icanhazip.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ipv4.icanhazip.comConnection: keep-alivesec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ipv4.icanhazip.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: __cf_bm=PAl5K4bshrUjH74IBxXZpsZ8fhjO.nE7lhNhZEgmbLU-1695997704-0-AU5F25apROMJpmai/G/PFbcdfZ/EcGDOtH3jAieTkU3rQ+/o0cQQb/FeYbbQzWNl3Od8IBW75ECiC81CMMlBYXA=
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ipv4.icanhazip.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: __cf_bm=PAl5K4bshrUjH74IBxXZpsZ8fhjO.nE7lhNhZEgmbLU-1695997704-0-AU5F25apROMJpmai/G/PFbcdfZ/EcGDOtH3jAieTkU3rQ+/o0cQQb/FeYbbQzWNl3Od8IBW75ECiC81CMMlBYXA=
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g; 1P_JAR=2023-09-25-09; NID=511=SzLVLHQSmPvgkoqmP-MsqjETq9dQ36QVm_qf2IzzhOCW0fFPsDTYGrt2nIMcjA4Ms9EAqvkswXpgrdTrGbklWuF9VUuI4kQoyRxzZJXmXGR4c2GB7bEOL6aT4Siga3gbRX-33znuEESDzU4kk1UQHyGVPHjVG8C7MD74EeDyBWQ
Source: classification engineClassification label: clean0.win@19/3@12/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_1808_1440924176Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1892,i,10894587477284569266,11563532355544574047,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ipv4.icanhazip.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1892,i,10894587477284569266,11563532355544574047,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_1808_1440924176Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1316659 URL: http://ipv4.icanhazip.com Startdate: 29/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 192.168.2.5 unknown unknown 5->15 17 239.255.255.250 unknown Reserved 5->17 10 chrome.exe 5->10         started        process4 dnsIp5 19 clients.l.google.com 142.250.72.142, 443, 49779 GOOGLEUS United States 10->19 21 accounts.google.com 142.251.40.45, 443, 49781 GOOGLEUS United States 10->21 23 4 other IPs or domains 10->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ipv4.icanhazip.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
ipv4.icanhazip.com
104.18.115.97
truefalse
    high
    accounts.google.com
    142.251.40.45
    truefalse
      high
      www.google.com
      172.217.12.132
      truefalse
        high
        clients.l.google.com
        142.250.72.142
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://ipv4.icanhazip.com/false
              high
              https://ipv4.icanhazip.com/favicon.icofalse
                high
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    https://ipv4.icanhazip.com/false
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      142.251.40.45
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      172.217.12.132
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      104.18.115.97
                      ipv4.icanhazip.comUnited States
                      13335CLOUDFLARENETUSfalse
                      142.250.72.142
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      104.18.114.97
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      IP
                      192.168.2.1
                      192.168.2.5
                      Joe Sandbox Version:38.0.0 Beryl
                      Analysis ID:1316659
                      Start date and time:2023-09-29 16:27:39 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 2m 48s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:http://ipv4.icanhazip.com
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:17
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean0.win@19/3@12/8
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 142.250.217.131, 34.104.35.123, 142.250.176.3
                      • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, edgedl.me.gvt1.com, update.googleapis.com, tse1.mm.bing.net, ctldl.windowsupdate.com, clientservices.googleapis.com, arc.msn.com
                      • Not all processes where analyzed, report is missing behavior information
                      • VT rate limit hit for: http://ipv4.icanhazip.com
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text
                      Category:downloaded
                      Size (bytes):15
                      Entropy (8bit):3.0062389286533895
                      Encrypted:false
                      SSDEEP:3:MXgMgRDSv:MwMgRDc
                      MD5:84CC503AD9F87B6DC92B73F4FC129567
                      SHA1:73EA3032152FB36D860BCA9BE95B5FB03C878DB6
                      SHA-256:69917A0C74C5CFAC65FD5AA23FB79411093A93D1DB2B92A3382773EEDDC57C33
                      SHA-512:FAC3BE28FC724FFDA8EF3B76F1CC2A5A1C9CE3F9EFC2DC7E4F2DB997C75C00EB3D00DB9E35EDFDC89B42E8D4CE96E4513502B9453692D66A358E5B4E2CBFD4C0
                      Malicious:false
                      Reputation:low
                      URL:https://ipv4.icanhazip.com/
                      Preview:102.129.145.97.
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text
                      Category:dropped
                      Size (bytes):15
                      Entropy (8bit):3.0062389286533895
                      Encrypted:false
                      SSDEEP:3:MXgMgRDSv:MwMgRDc
                      MD5:84CC503AD9F87B6DC92B73F4FC129567
                      SHA1:73EA3032152FB36D860BCA9BE95B5FB03C878DB6
                      SHA-256:69917A0C74C5CFAC65FD5AA23FB79411093A93D1DB2B92A3382773EEDDC57C33
                      SHA-512:FAC3BE28FC724FFDA8EF3B76F1CC2A5A1C9CE3F9EFC2DC7E4F2DB997C75C00EB3D00DB9E35EDFDC89B42E8D4CE96E4513502B9453692D66A358E5B4E2CBFD4C0
                      Malicious:false
                      Reputation:low
                      Preview:102.129.145.97.
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text
                      Category:downloaded
                      Size (bytes):15
                      Entropy (8bit):3.0062389286533895
                      Encrypted:false
                      SSDEEP:3:MXgMgRDSv:MwMgRDc
                      MD5:84CC503AD9F87B6DC92B73F4FC129567
                      SHA1:73EA3032152FB36D860BCA9BE95B5FB03C878DB6
                      SHA-256:69917A0C74C5CFAC65FD5AA23FB79411093A93D1DB2B92A3382773EEDDC57C33
                      SHA-512:FAC3BE28FC724FFDA8EF3B76F1CC2A5A1C9CE3F9EFC2DC7E4F2DB997C75C00EB3D00DB9E35EDFDC89B42E8D4CE96E4513502B9453692D66A358E5B4E2CBFD4C0
                      Malicious:false
                      Reputation:low
                      URL:https://ipv4.icanhazip.com/favicon.ico
                      Preview:102.129.145.97.
                      No static file info

                      Download Network PCAP: filteredfull

                      • Total Packets: 80
                      • 443 (HTTPS)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      Sep 29, 2023 16:28:22.869128942 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:22.869215012 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:22.869291067 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:22.869659901 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:22.869697094 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:22.869743109 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:22.870646954 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:22.870665073 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:22.870858908 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:22.870882988 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.269859076 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.270225048 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.270258904 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.270745039 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.270823956 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.271471024 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.271531105 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.273384094 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.273441076 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.273694992 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.273705959 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.304059029 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.304366112 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.304397106 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.306349039 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.306420088 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.307713032 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.307802916 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.308007002 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.308017969 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.318535089 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.349526882 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.633919001 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.634042025 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.634119034 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.634736061 CEST49779443192.168.2.4142.250.72.142
                      Sep 29, 2023 16:28:23.634774923 CEST44349779142.250.72.142192.168.2.4
                      Sep 29, 2023 16:28:23.718173027 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.720347881 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:23.720397949 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.720990896 CEST49781443192.168.2.4142.251.40.45
                      Sep 29, 2023 16:28:23.721016884 CEST44349781142.251.40.45192.168.2.4
                      Sep 29, 2023 16:28:24.064830065 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.064874887 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.064919949 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.065274954 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.065290928 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.409368992 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.409874916 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.409893990 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.411529064 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.411593914 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.412856102 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.412940025 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.413281918 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.413294077 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.453314066 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.772412062 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.772499084 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.772550106 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.777987957 CEST49782443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.778008938 CEST44349782104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.984534025 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.984621048 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:24.984713078 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.985089064 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:24.985121012 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.316829920 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.354737043 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.354784012 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.355397940 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.356059074 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.356161118 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.356198072 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.402451992 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.410659075 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.689373016 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.689457893 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:25.689526081 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.709316015 CEST49783443192.168.2.4104.18.114.97
                      Sep 29, 2023 16:28:25.709336996 CEST44349783104.18.114.97192.168.2.4
                      Sep 29, 2023 16:28:26.125140905 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.125186920 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.125257015 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.125794888 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.125819921 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.460849047 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.461143017 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.461189032 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.462615013 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.462678909 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.463068962 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.463152885 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.463248014 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.463264942 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.503918886 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.828362942 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.828550100 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:26.828655958 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.829045057 CEST49785443192.168.2.4104.18.115.97
                      Sep 29, 2023 16:28:26.829076052 CEST44349785104.18.115.97192.168.2.4
                      Sep 29, 2023 16:28:27.233198881 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.233248949 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.233309031 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.233551979 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.233570099 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.605016947 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.605324984 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.605400085 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.606854916 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.606937885 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.608095884 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.608186960 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.656961918 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:27.656986952 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:27.703843117 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:37.621114969 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:37.621216059 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:28:37.621390104 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:38.805340052 CEST49786443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:28:38.805392027 CEST44349786172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.102418900 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:27.102500916 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.102624893 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:27.102946043 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:27.102993011 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.480616093 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.480912924 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:27.480974913 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.481297016 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.481637955 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:27.481884003 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:27.522985935 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:37.464061022 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:37.464157104 CEST44349804172.217.12.132192.168.2.4
                      Sep 29, 2023 16:29:37.464231014 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:39.089648008 CEST49804443192.168.2.4172.217.12.132
                      Sep 29, 2023 16:29:39.089728117 CEST44349804172.217.12.132192.168.2.4
                      TimestampSource PortDest PortSource IPDest IP
                      Sep 29, 2023 16:28:22.688791990 CEST5133353192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:22.688997984 CEST5852853192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:22.689241886 CEST5237553192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:22.689431906 CEST5024453192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:22.858597040 CEST53523758.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:22.860620022 CEST53513338.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:22.866775990 CEST53585288.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:22.867481947 CEST53547478.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:22.869373083 CEST53502448.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:23.855696917 CEST53528848.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:23.879456997 CEST5017453192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:23.879901886 CEST5920953192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:23.890233994 CEST6004853192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:23.890311956 CEST4975353192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:24.053632021 CEST53501748.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:24.053956032 CEST53592098.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:24.064308882 CEST53600488.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:24.064338923 CEST53497538.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:25.950253010 CEST6363753192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:25.950783014 CEST5254653192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:26.122646093 CEST53525468.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:26.123889923 CEST53636378.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:27.048576117 CEST6368453192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:27.048677921 CEST6298853192.168.2.48.8.8.8
                      Sep 29, 2023 16:28:27.219904900 CEST53636848.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:27.219964027 CEST53629888.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:40.794998884 CEST53512448.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:47.735028028 CEST53653938.8.8.8192.168.2.4
                      Sep 29, 2023 16:28:58.682493925 CEST53557188.8.8.8192.168.2.4
                      Sep 29, 2023 16:29:16.590672970 CEST53613288.8.8.8192.168.2.4
                      Sep 29, 2023 16:29:22.394656897 CEST53502968.8.8.8192.168.2.4
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Sep 29, 2023 16:28:22.688791990 CEST192.168.2.48.8.8.80x7b04Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:22.688997984 CEST192.168.2.48.8.8.80x7636Standard query (0)clients2.google.com65IN (0x0001)false
                      Sep 29, 2023 16:28:22.689241886 CEST192.168.2.48.8.8.80x991aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:22.689431906 CEST192.168.2.48.8.8.80xb93eStandard query (0)accounts.google.com65IN (0x0001)false
                      Sep 29, 2023 16:28:23.879456997 CEST192.168.2.48.8.8.80x609aStandard query (0)ipv4.icanhazip.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:23.879901886 CEST192.168.2.48.8.8.80xe349Standard query (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:23.890233994 CEST192.168.2.48.8.8.80xef34Standard query (0)ipv4.icanhazip.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:23.890311956 CEST192.168.2.48.8.8.80xa40cStandard query (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:25.950253010 CEST192.168.2.48.8.8.80x6db1Standard query (0)ipv4.icanhazip.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:25.950783014 CEST192.168.2.48.8.8.80x9ad8Standard query (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:27.048576117 CEST192.168.2.48.8.8.80x2965Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:27.048677921 CEST192.168.2.48.8.8.80x170dStandard query (0)www.google.com65IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Sep 29, 2023 16:28:22.858597040 CEST8.8.8.8192.168.2.40x991aNo error (0)accounts.google.com142.251.40.45A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:22.860620022 CEST8.8.8.8192.168.2.40x7b04No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Sep 29, 2023 16:28:22.860620022 CEST8.8.8.8192.168.2.40x7b04No error (0)clients.l.google.com142.250.72.142A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:22.866775990 CEST8.8.8.8192.168.2.40x7636No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Sep 29, 2023 16:28:24.053632021 CEST8.8.8.8192.168.2.40x609aNo error (0)ipv4.icanhazip.com104.18.115.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:24.053632021 CEST8.8.8.8192.168.2.40x609aNo error (0)ipv4.icanhazip.com104.18.114.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:24.053956032 CEST8.8.8.8192.168.2.40xe349No error (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:24.064308882 CEST8.8.8.8192.168.2.40xef34No error (0)ipv4.icanhazip.com104.18.114.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:24.064308882 CEST8.8.8.8192.168.2.40xef34No error (0)ipv4.icanhazip.com104.18.115.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:24.064338923 CEST8.8.8.8192.168.2.40xa40cNo error (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:26.122646093 CEST8.8.8.8192.168.2.40x9ad8No error (0)ipv4.icanhazip.com65IN (0x0001)false
                      Sep 29, 2023 16:28:26.123889923 CEST8.8.8.8192.168.2.40x6db1No error (0)ipv4.icanhazip.com104.18.115.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:26.123889923 CEST8.8.8.8192.168.2.40x6db1No error (0)ipv4.icanhazip.com104.18.114.97A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:27.219904900 CEST8.8.8.8192.168.2.40x2965No error (0)www.google.com172.217.12.132A (IP address)IN (0x0001)false
                      Sep 29, 2023 16:28:27.219964027 CEST8.8.8.8192.168.2.40x170dNo error (0)www.google.com65IN (0x0001)false
                      • clients2.google.com
                      • accounts.google.com
                      • ipv4.icanhazip.com
                      • https:
                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.449779142.250.72.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-09-29 14:28:23 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                      Host: clients2.google.com
                      Connection: keep-alive
                      X-Goog-Update-Interactivity: fg
                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                      X-Goog-Update-Updater: chromecrx-115.0.5790.171
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                      2023-09-29 14:28:23 UTC1INHTTP/1.1 200 OK
                      Content-Security-Policy: script-src 'report-sample' 'nonce-CNOZPuR6I_kR8NXAmo_JQw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Fri, 29 Sep 2023 14:28:23 GMT
                      Content-Type: text/xml; charset=UTF-8
                      X-Daynum: 6115
                      X-Daystart: 26903
                      X-Content-Type-Options: nosniff
                      X-Frame-Options: SAMEORIGIN
                      X-XSS-Protection: 1; mode=block
                      Server: GSE
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-09-29 14:28:23 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 31 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 36 39 30 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                      Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6115" elapsed_seconds="26903"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                      2023-09-29 14:28:23 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                      Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                      2023-09-29 14:28:23 UTC3INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.449781142.251.40.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-09-29 14:28:23 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                      Host: accounts.google.com
                      Connection: keep-alive
                      Content-Length: 1
                      Origin: https://www.google.com
                      Content-Type: application/x-www-form-urlencoded
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                      Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g; 1P_JAR=2023-09-25-09; NID=511=SzLVLHQSmPvgkoqmP-MsqjETq9dQ36QVm_qf2IzzhOCW0fFPsDTYGrt2nIMcjA4Ms9EAqvkswXpgrdTrGbklWuF9VUuI4kQoyRxzZJXmXGR4c2GB7bEOL6aT4Siga3gbRX-33znuEESDzU4kk1UQHyGVPHjVG8C7MD74EeDyBWQ
                      2023-09-29 14:28:23 UTC1OUTData Raw: 20
                      Data Ascii:
                      2023-09-29 14:28:23 UTC3INHTTP/1.1 200 OK
                      Content-Type: application/json; charset=utf-8
                      Access-Control-Allow-Origin: https://www.google.com
                      Access-Control-Allow-Credentials: true
                      X-Content-Type-Options: nosniff
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Fri, 29 Sep 2023 14:28:23 GMT
                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                      Content-Security-Policy: script-src 'report-sample' 'nonce-TwFbi3a2XA7UssPdWmriIA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                      Cross-Origin-Opener-Policy: same-origin
                      Server: ESF
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-09-29 14:28:23 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                      Data Ascii: 11["gaia.l.a.r",[]]
                      2023-09-29 14:28:23 UTC4INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      2192.168.2.449782104.18.114.97443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-09-29 14:28:24 UTC4OUTGET / HTTP/1.1
                      Host: ipv4.icanhazip.com
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      sec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                      2023-09-29 14:28:24 UTC5INHTTP/1.1 200 OK
                      Date: Fri, 29 Sep 2023 14:28:24 GMT
                      Content-Type: text/plain
                      Content-Length: 15
                      Connection: close
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Methods: GET
                      Set-Cookie: __cf_bm=PAl5K4bshrUjH74IBxXZpsZ8fhjO.nE7lhNhZEgmbLU-1695997704-0-AU5F25apROMJpmai/G/PFbcdfZ/EcGDOtH3jAieTkU3rQ+/o0cQQb/FeYbbQzWNl3Od8IBW75ECiC81CMMlBYXA=; path=/; expires=Fri, 29-Sep-23 14:58:24 GMT; domain=.icanhazip.com; HttpOnly; Secure; SameSite=None
                      Server: cloudflare
                      CF-RAY: 80e4e9963b1c2f07-LAX
                      alt-svc: h3=":443"; ma=86400
                      2023-09-29 14:28:24 UTC5INData Raw: 31 30 32 2e 31 32 39 2e 31 34 35 2e 39 37 0a
                      Data Ascii: 102.129.145.97


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      3192.168.2.449783104.18.114.97443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-09-29 14:28:25 UTC6OUTGET /favicon.ico HTTP/1.1
                      Host: ipv4.icanhazip.com
                      Connection: keep-alive
                      sec-ch-ua: "Not/A)Brand";v="99", "Google Chrome";v="115", "Chromium";v="115"
                      sec-ch-ua-mobile: ?0
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                      sec-ch-ua-platform: "Windows"
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: image
                      Referer: https://ipv4.icanhazip.com/
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                      Cookie: __cf_bm=PAl5K4bshrUjH74IBxXZpsZ8fhjO.nE7lhNhZEgmbLU-1695997704-0-AU5F25apROMJpmai/G/PFbcdfZ/EcGDOtH3jAieTkU3rQ+/o0cQQb/FeYbbQzWNl3Od8IBW75ECiC81CMMlBYXA=
                      2023-09-29 14:28:25 UTC6INHTTP/1.1 200 OK
                      Date: Fri, 29 Sep 2023 14:28:25 GMT
                      Content-Type: text/plain
                      Content-Length: 15
                      Connection: close
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Methods: GET
                      Server: cloudflare
                      CF-RAY: 80e4e99be8fd0925-LAX
                      alt-svc: h3=":443"; ma=86400
                      2023-09-29 14:28:25 UTC7INData Raw: 31 30 32 2e 31 32 39 2e 31 34 35 2e 39 37 0a
                      Data Ascii: 102.129.145.97


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      4192.168.2.449785104.18.115.97443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-09-29 14:28:26 UTC7OUTGET /favicon.ico HTTP/1.1
                      Host: ipv4.icanhazip.com
                      Connection: keep-alive
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                      Accept: */*
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: cors
                      Sec-Fetch-Dest: empty
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                      Cookie: __cf_bm=PAl5K4bshrUjH74IBxXZpsZ8fhjO.nE7lhNhZEgmbLU-1695997704-0-AU5F25apROMJpmai/G/PFbcdfZ/EcGDOtH3jAieTkU3rQ+/o0cQQb/FeYbbQzWNl3Od8IBW75ECiC81CMMlBYXA=
                      2023-09-29 14:28:26 UTC7INHTTP/1.1 200 OK
                      Date: Fri, 29 Sep 2023 14:28:26 GMT
                      Content-Type: text/plain
                      Content-Length: 15
                      Connection: close
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Methods: GET
                      Server: cloudflare
                      CF-RAY: 80e4e9a30db90924-LAX
                      alt-svc: h3=":443"; ma=86400
                      2023-09-29 14:28:26 UTC7INData Raw: 31 30 32 2e 31 32 39 2e 31 34 35 2e 39 37 0a
                      Data Ascii: 102.129.145.97


                      020406080s020406080100

                      Click to jump to process

                      020406080s0.0020406080100MB

                      Click to jump to process

                      Target ID:0
                      Start time:16:28:21
                      Start date:29/09/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                      Imagebase:0x7ff632090000
                      File size:3'219'224 bytes
                      MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:1
                      Start time:16:28:21
                      Start date:29/09/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1892,i,10894587477284569266,11563532355544574047,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff632090000
                      File size:3'219'224 bytes
                      MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:2
                      Start time:16:28:23
                      Start date:29/09/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ipv4.icanhazip.com
                      Imagebase:0x7ff632090000
                      File size:3'219'224 bytes
                      MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      No disassembly