Edit tour

Windows Analysis Report
http://trkmyclk.xyz/favicon.ico

Overview

General Information

Sample URL:http://trkmyclk.xyz/favicon.ico
Analysis ID:1318986
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Performs DNS queries to domains with low reputation

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6728 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 6892 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1916,i,8711639873716081779,4172404627762788310,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 5456 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trkmyclk.xyz/favicon.ico MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://trkmyclk.xyz/favicon.icoAvira URL Cloud: detection malicious, Label: malware
Source: http://trkmyclk.xyz/favicon.icoHTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_6728_493555524Jump to behavior

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: trkmyclk.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: trkmyclk.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: trkmyclk.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: trkmyclk.xyz
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: trkmyclk.xyzConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: trkmyclk.xyzConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=Ad49MVGiijyX5dxPFAKxKYso-rIS24Ht-Pxs5fU9hHrAzfASnm-jqdQE1g; NID=511=WyMJovC2uA2AEbHQkGfP-KDdYCeg5Q7Mv6gxYT-qeugtrnXImrhmp1SixwS4ydh_E8Z0hdfCLAXvg2WUqsBSfqpx5SFvCCoeGeevqlEfkoxYi9FTISb8Cu7rr5rf9PyyNbLqf2QbxG7ja7jAB6UJQd5CPvMGcYUasORCRKRL1-arNYzfADAWHJvBLXml-Km_uewDreOyJ-MjxAI-i38Tl6LXI3zB; 1P_JAR=2023-09-25-08
Source: classification engineClassification label: mal52.troj.win@18/2@10/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\chrome_BITS_6728_493555524Jump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1916,i,8711639873716081779,4172404627762788310,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trkmyclk.xyz/favicon.ico
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1916,i,8711639873716081779,4172404627762788310,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_6728_493555524Jump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1318986 URL: http://trkmyclk.xyz/favicon.ico Startdate: 03/10/2023 Architecture: WINDOWS Score: 52 25 Antivirus / Scanner detection for submitted sample 2->25 27 Performs DNS queries to domains with low reputation 2->27 6 chrome.exe 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.1 unknown unknown 6->14 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 trkmyclk.xyz 11->18 21 www.google.com 142.251.16.106, 443, 49798, 49844 GOOGLEUS United States 11->21 23 4 other IPs or domains 11->23 signatures7 29 Performs DNS queries to domains with low reputation 18->29

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://trkmyclk.xyz/favicon.ico100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.253.122.84
truefalse
    high
    www.google.com
    142.251.16.106
    truefalse
      high
      clients.l.google.com
      172.253.62.113
      truefalse
        high
        trkmyclk.xyz
        34.74.68.195
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://trkmyclk.xyz/favicon.icofalse
                unknown
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  http://trkmyclk.xyz/favicon.icofalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    172.253.122.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    172.253.62.113
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    34.74.68.195
                    trkmyclk.xyzUnited States
                    15169GOOGLEUSfalse
                    142.251.16.106
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.1
                    Joe Sandbox Version:38.0.0 Ammolite
                    Analysis ID:1318986
                    Start date and time:2023-10-03 21:06:16 +02:00
                    Joe Sandbox Product:CloudBasic
                    Overall analysis duration:0h 2m 48s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://trkmyclk.xyz/favicon.ico
                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                    Number of analysed new started processes analysed:22
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal52.troj.win@18/2@10/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                    • Excluded IPs from analysis (whitelisted): 142.251.16.94, 34.104.35.123, 172.253.63.94
                    • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, client.wns.windows.com, edgedl.me.gvt1.com, update.googleapis.com, tse1.mm.bing.net, ctldl.windowsupdate.com, clientservices.googleapis.com, displaycatalog.mp.microsoft.com, g.bing.com, arc.msn.com
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://trkmyclk.xyz/favicon.ico
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows icon resource - 3 icons, 16x16, 2 colors, 32x32, 2 colors
                    Category:downloaded
                    Size (bytes):1350
                    Entropy (8bit):1.2317806892233787
                    Encrypted:false
                    SSDEEP:12:nkp671x55555555555555UstaJ9999999999999999999999999999999999999f:nKCMJv
                    MD5:B42E43BE08B0D6FF829351B2E6EAB0E1
                    SHA1:1F3E281DF34D18172B47F7C104B1874F96D3C002
                    SHA-256:E8C241FD2B540E006DED11341DFB6694A041B1A98FD699495FB60737306C2A4D
                    SHA-512:1DD4D3DBBBA7C1974FF914662FC53792E63039337887FB15CCF341152564DEEF92437F218482BE951B2A6E58CB1FCA153B56187A471F7D492A04FD8C85E3A82E
                    Malicious:false
                    Reputation:low
                    URL:http://trkmyclk.xyz/favicon.ico
                    Preview:..................6... ......0.......00......0.......(....... ...........@...........................................................................................................................................................(... ...@.......................................................................................................................................................................................................................................................................................................(...0...`.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows icon resource - 3 icons, 16x16, 2 colors, 32x32, 2 colors
                    Category:dropped
                    Size (bytes):1350
                    Entropy (8bit):1.2317806892233787
                    Encrypted:false
                    SSDEEP:12:nkp671x55555555555555UstaJ9999999999999999999999999999999999999f:nKCMJv
                    MD5:B42E43BE08B0D6FF829351B2E6EAB0E1
                    SHA1:1F3E281DF34D18172B47F7C104B1874F96D3C002
                    SHA-256:E8C241FD2B540E006DED11341DFB6694A041B1A98FD699495FB60737306C2A4D
                    SHA-512:1DD4D3DBBBA7C1974FF914662FC53792E63039337887FB15CCF341152564DEEF92437F218482BE951B2A6E58CB1FCA153B56187A471F7D492A04FD8C85E3A82E
                    Malicious:false
                    Reputation:low
                    Preview:..................6... ......0.......00......0.......(....... ...........@...........................................................................................................................................................(... ...@.......................................................................................................................................................................................................................................................................................................(...0...`.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 68
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 3, 2023 21:07:03.851771116 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:03.851803064 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:03.851872921 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:03.855451107 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:03.855463028 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:03.855925083 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:03.855958939 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:03.856004000 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:03.856167078 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:03.856177092 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.105758905 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.106237888 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.106265068 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.108773947 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.108839035 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.110605001 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.111510992 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.111601114 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.111804962 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.111886978 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.112271070 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.112334967 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.112965107 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.113024950 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.114058018 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.114073992 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.114432096 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.114496946 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.114619970 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.114646912 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.169217110 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.169264078 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.338232040 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.338670015 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.338727951 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.338865042 CEST49793443192.168.2.3172.253.62.113
                    Oct 3, 2023 21:07:04.338879108 CEST44349793172.253.62.113192.168.2.3
                    Oct 3, 2023 21:07:04.345693111 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.345871925 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.345952988 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.346473932 CEST49791443192.168.2.3172.253.122.84
                    Oct 3, 2023 21:07:04.346487999 CEST44349791172.253.122.84192.168.2.3
                    Oct 3, 2023 21:07:04.899142027 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:04.899980068 CEST4979580192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.016622066 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.016762972 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.016979933 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.019069910 CEST804979534.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.019157887 CEST4979580192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.133433104 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.133495092 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.133534908 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.133605003 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.355433941 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.471709967 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.472044945 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.472363949 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:05.588735104 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.588860989 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.588875055 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:05.590476036 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:08.185765982 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.185811043 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.185882092 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.186250925 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.186266899 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.402926922 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.435067892 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.435105085 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.436630964 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.436748981 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.516252995 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.516607046 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.560857058 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:08.560879946 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:08.607716084 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:18.395574093 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:18.395726919 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:18.395901918 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:19.842727900 CEST49798443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:07:19.842787981 CEST44349798142.251.16.106192.168.2.3
                    Oct 3, 2023 21:07:50.025227070 CEST4979580192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:50.134625912 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:50.143477917 CEST804979534.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:50.251622915 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:07:50.603256941 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:07:50.721307039 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:05.134746075 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:05.134906054 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:05.137115955 CEST804979534.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:05.137177944 CEST4979580192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:05.590380907 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:05.590519905 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:06.033159971 CEST4979580192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:06.033230066 CEST4979780192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:06.034044027 CEST4979480192.168.2.334.74.68.195
                    Oct 3, 2023 21:08:06.150739908 CEST804979434.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:06.150825977 CEST804979534.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:06.150888920 CEST804979734.74.68.195192.168.2.3
                    Oct 3, 2023 21:08:08.042937040 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:08.043021917 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.043108940 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:08.043279886 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:08.043312073 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.263160944 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.263523102 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:08.263611078 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.264055967 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.264548063 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:08.264638901 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:08.307446003 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:18.288928986 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:18.289009094 CEST44349844142.251.16.106192.168.2.3
                    Oct 3, 2023 21:08:18.289088011 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:19.840039968 CEST49844443192.168.2.3142.251.16.106
                    Oct 3, 2023 21:08:19.840111971 CEST44349844142.251.16.106192.168.2.3
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 3, 2023 21:07:03.742422104 CEST5578953192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:03.742657900 CEST5242553192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:03.742984056 CEST5035753192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:03.743242025 CEST5059853192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:03.848433971 CEST53503578.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:03.849822044 CEST53557898.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:03.850136995 CEST53505988.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:03.850389004 CEST53524258.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:03.853167057 CEST53527268.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:04.500884056 CEST53526438.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:04.791729927 CEST5853853192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:04.791991949 CEST5472353192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:04.897419930 CEST53585388.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:04.898533106 CEST53547238.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:05.244678020 CEST5866353192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:05.245070934 CEST6131953192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:05.350944042 CEST53586638.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:05.351310968 CEST53613198.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:08.034275055 CEST4963353192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:08.034588099 CEST6520753192.168.2.38.8.8.8
                    Oct 3, 2023 21:07:08.141196012 CEST53652078.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:08.141829967 CEST53496338.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:21.652709961 CEST53565708.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:28.350661993 CEST53573158.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:39.102041960 CEST53573098.8.8.8192.168.2.3
                    Oct 3, 2023 21:07:57.519992113 CEST53497278.8.8.8192.168.2.3
                    Oct 3, 2023 21:08:03.343620062 CEST53633848.8.8.8192.168.2.3
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Oct 3, 2023 21:07:03.742422104 CEST192.168.2.38.8.8.80xbc56Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.742657900 CEST192.168.2.38.8.8.80xa7a7Standard query (0)clients2.google.com65IN (0x0001)false
                    Oct 3, 2023 21:07:03.742984056 CEST192.168.2.38.8.8.80x49bcStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.743242025 CEST192.168.2.38.8.8.80x358eStandard query (0)accounts.google.com65IN (0x0001)false
                    Oct 3, 2023 21:07:04.791729927 CEST192.168.2.38.8.8.80xa9a8Standard query (0)trkmyclk.xyzA (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:04.791991949 CEST192.168.2.38.8.8.80xb8e5Standard query (0)trkmyclk.xyz65IN (0x0001)false
                    Oct 3, 2023 21:07:05.244678020 CEST192.168.2.38.8.8.80x32e0Standard query (0)trkmyclk.xyzA (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:05.245070934 CEST192.168.2.38.8.8.80xe71eStandard query (0)trkmyclk.xyz65IN (0x0001)false
                    Oct 3, 2023 21:07:08.034275055 CEST192.168.2.38.8.8.80xdaf6Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.034588099 CEST192.168.2.38.8.8.80xe85cStandard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Oct 3, 2023 21:07:03.848433971 CEST8.8.8.8192.168.2.30x49bcNo error (0)accounts.google.com172.253.122.84A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.113A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.102A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.100A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.101A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.139A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.849822044 CEST8.8.8.8192.168.2.30xbc56No error (0)clients.l.google.com172.253.62.138A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:03.850389004 CEST8.8.8.8192.168.2.30xa7a7No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Oct 3, 2023 21:07:04.897419930 CEST8.8.8.8192.168.2.30xa9a8No error (0)trkmyclk.xyz34.74.68.195A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:05.350944042 CEST8.8.8.8192.168.2.30x32e0No error (0)trkmyclk.xyz34.74.68.195A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141196012 CEST8.8.8.8192.168.2.30xe85cNo error (0)www.google.com65IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
                    Oct 3, 2023 21:07:08.141829967 CEST8.8.8.8192.168.2.30xdaf6No error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
                    • accounts.google.com
                    • clients2.google.com
                    • trkmyclk.xyz
                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.2.349791172.253.122.84443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.2.349793172.253.62.113443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    2192.168.2.34979434.74.68.19580C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    Oct 3, 2023 21:07:05.016979933 CEST87OUTGET /favicon.ico HTTP/1.1
                    Host: trkmyclk.xyz
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Oct 3, 2023 21:07:05.133495092 CEST88INHTTP/1.1 200 OK
                    Server: nginx
                    Date: Tue, 03 Oct 2023 19:07:05 GMT
                    Content-Type: image/x-icon
                    Content-Length: 1350
                    Last-Modified: Sun, 06 Nov 2016 12:08:02 GMT
                    Connection: keep-alive
                    ETag: "581f1d22-546"
                    Expires: Thu, 02 Nov 2023 19:07:05 GMT
                    Cache-Control: max-age=2592000
                    Accept-Ranges: bytes
                    Data Raw: 00 00 01 00 03 00 10 10 02 00 01 00 01 00 b0 00 00 00 36 00 00 00 20 20 02 00 01 00 01 00 30 01 00 00 e6 00 00 00 30 30 02 00 01 00 01 00 30 03 00 00 16 02 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 28 00 00 00 30 00 00 00 60 00 00 00 01 00 01 00 00 00 00 00 80 01 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff
                    Data Ascii: 6 0000( @( @(0`
                    Oct 3, 2023 21:07:05.133534908 CEST89INData Raw: ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00
                    Data Ascii:
                    Oct 3, 2023 21:07:50.134625912 CEST4140OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    3192.168.2.34979734.74.68.19580C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    Oct 3, 2023 21:07:05.472363949 CEST90OUTGET /favicon.ico HTTP/1.1
                    Host: trkmyclk.xyz
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept: */*
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Oct 3, 2023 21:07:05.588860989 CEST91INHTTP/1.1 200 OK
                    Server: nginx
                    Date: Tue, 03 Oct 2023 19:07:05 GMT
                    Content-Type: image/x-icon
                    Content-Length: 1350
                    Last-Modified: Sun, 06 Nov 2016 12:08:02 GMT
                    Connection: keep-alive
                    ETag: "581f1d22-546"
                    Expires: Thu, 02 Nov 2023 19:07:05 GMT
                    Cache-Control: max-age=2592000
                    Accept-Ranges: bytes
                    Data Raw: 00 00 01 00 03 00 10 10 02 00 01 00 01 00 b0 00 00 00 36 00 00 00 20 20 02 00 01 00 01 00 30 01 00 00 e6 00 00 00 30 30 02 00 01 00 01 00 30 03 00 00 16 02 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 01 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 ff ff 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 01 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 28 00 00 00 30 00 00 00 60 00 00 00 01 00 01 00 00 00 00 00 80 01 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff
                    Data Ascii: 6 0000( @( @(0`
                    Oct 3, 2023 21:07:05.588875055 CEST91INData Raw: ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00 00 ff ff ff ff ff ff 00
                    Data Ascii:
                    Oct 3, 2023 21:07:50.603256941 CEST4140OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    4192.168.2.34979534.74.68.19580C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    Oct 3, 2023 21:07:50.025227070 CEST4140OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.2.349791172.253.122.84443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-10-03 19:07:04 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: CONSENT=PENDING+904; AEC=Ad49MVGiijyX5dxPFAKxKYso-rIS24Ht-Pxs5fU9hHrAzfASnm-jqdQE1g; NID=511=WyMJovC2uA2AEbHQkGfP-KDdYCeg5Q7Mv6gxYT-qeugtrnXImrhmp1SixwS4ydh_E8Z0hdfCLAXvg2WUqsBSfqpx5SFvCCoeGeevqlEfkoxYi9FTISb8Cu7rr5rf9PyyNbLqf2QbxG7ja7jAB6UJQd5CPvMGcYUasORCRKRL1-arNYzfADAWHJvBLXml-Km_uewDreOyJ-MjxAI-i38Tl6LXI3zB; 1P_JAR=2023-09-25-08
                    2023-10-03 19:07:04 UTC0OUTData Raw: 20
                    Data Ascii:
                    2023-10-03 19:07:04 UTC2INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Tue, 03 Oct 2023 19:07:04 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Content-Security-Policy: script-src 'report-sample' 'nonce-GdniofnUj2ZtiXXnvL06qQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Cross-Origin-Opener-Policy: same-origin
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-10-03 19:07:04 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2023-10-03 19:07:04 UTC4INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.2.349793172.253.62.113443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-10-03 19:07:04 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-115.0.5790.171
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-10-03 19:07:04 UTC1INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-5bO3cD2Wd6fFKowdy7snEA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Tue, 03 Oct 2023 19:07:04 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6119
                    X-Daystart: 43624
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-10-03 19:07:04 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 31 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 33 36 32 34 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6119" elapsed_seconds="43624"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2023-10-03 19:07:04 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2023-10-03 19:07:04 UTC2INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0020406080100MB

                    Click to jump to process

                    Target ID:0
                    Start time:21:07:01
                    Start date:03/10/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff65c530000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:1
                    Start time:21:07:01
                    Start date:03/10/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1928 --field-trial-handle=1916,i,8711639873716081779,4172404627762788310,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff65c530000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:21:07:03
                    Start date:03/10/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trkmyclk.xyz/favicon.ico
                    Imagebase:0x7ff65c530000
                    File size:3'219'224 bytes
                    MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly