Edit tour

Windows Analysis Report
http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D

Overview

General Information

Sample URL:http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
Analysis ID:1355439
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Creates files inside the system directory
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1352 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6696 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2348 --field-trial-handle=2288,i,12330104661967520940,682847274094739711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 1248 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49720 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.204.156.130:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.156.130:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49720 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.156.130
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LZv65tGxLmkuks1&MD=ZGv4X2os HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LZv65tGxLmkuks1&MD=ZGv4X2os HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 23.204.156.130:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.156.130:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49724 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1352_445491951Jump to behavior
Source: classification engineClassification label: unknown1.win@17/9@8/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2348 --field-trial-handle=2288,i,12330104661967520940,682847274094739711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2348 --field-trial-handle=2288,i,12330104661967520940,682847274094739711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1355439 URL: http://status.thawte.com//M... Startdate: 07/12/2023 Architecture: WINDOWS Score: 1 5 chrome.exe 20 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49685, 49703 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.217.228, 443, 49711, 49726 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.64.141, 443, 49704 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.64.141
truefalse
    high
    www.google.com
    142.250.217.228
    truefalse
      high
      clients.l.google.com
      192.178.50.46
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          status.thawte.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.64.141
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                192.178.50.46
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.217.228
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.5
                Joe Sandbox version:38.0.0 Ammolite
                Analysis ID:1355439
                Start date and time:2023-12-07 15:02:03 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 2s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:UNKNOWN
                Classification:unknown1.win@17/9@8/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • URL not reachable
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 192.178.50.35, 34.104.35.123, 23.56.6.73, 72.21.81.240, 192.229.211.108
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:dropped
                Size (bytes):471
                Entropy (8bit):7.2065006082985725
                Encrypted:false
                SSDEEP:6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ
                MD5:E09531B89414706804DA63BADE235FF4
                SHA1:48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09
                SHA-256:F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377
                SHA-512:65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE
                Malicious:false
                Reputation:low
                Preview:0..........0.....+.....0......0...0.........2...,......$.]....20231206234938Z0s0q0I0...+........s...b..A.C....O...A.....2...,......$.].......R.)6e...xU..X....20231206233302Z....20231213223302Z0...*.H.............K..!...)._.fge')....&{../.*.%......[8.{)..5T..\..|I..g87/..[....Sg.<.q.@.`.h...].dy.....-..|.C.....N]sDA..eo..}....iU...".N..?*..s..U@.p/k&............ .. ...r..j.B.(.y..R..n....I.t6Zsp....G.k.K.Y...+.v..5..)...*..Cw;U+........8..-.X.`.].N.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 7 13:02:57 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.972149567753829
                Encrypted:false
                SSDEEP:48:8bNdaST6ejEHu0idAKZdA19ehwiZUklqehHy+3:8eSOqcoy
                MD5:372E38A7771A95087C4DD1482BCAF738
                SHA1:305E1A700622D5E59F3EDB3403889B373AE0813E
                SHA-256:FF00689C5AB7B0E72C792AFD4D691CABFC51C5EFCB0A18DF0A2C01CB6C39AAD4
                SHA-512:B5D5DC890E4606CBF82D5C136C7CCAE84A55E75A5429CEF6B3F1CC17330C8AA182CC854DADAC759A35A1AE42C8EF0E843C4796BC14BB12BFF74D7DF69E979AA2
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....p....)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W]p...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 7 13:02:57 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):3.988931836991867
                Encrypted:false
                SSDEEP:48:8mNdaST6ejEHu0idAKZdA1weh/iZUkAQkqehYy+2:8LSOqu9QBy
                MD5:06D19139703889E57381B3A2C8DD2C67
                SHA1:D072597207AEC772E8C4D9020498D6C90DCD1E70
                SHA-256:FD270550B3B6A90E169F74187622CAA460C51C3EDC56C12BB6E6B66FBF0120B5
                SHA-512:71244C98BC772E56A578AF4CCA3CA5294909D314A5E3A4F186DCB3A2BD59121BFEA8F0626DE36F32914F77E5FCBFE4AB4B16B8AFF372983609BAB276502EC28D
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....M....)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W]p...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2693
                Entropy (8bit):4.001093785032837
                Encrypted:false
                SSDEEP:48:8xkdaST6ejsHu0idAKZdA14tseh7sFiZUkmgqeh7sqy+BX:8xNSOq+n0y
                MD5:9B81BA8340D2402C456F5520C69316F9
                SHA1:B84550BCEECF121046EC619A2CAFD51C10D6158B
                SHA-256:A1DFAEA1BD30B8220103F80ECB34A86B54AB1BC8C63F4E4ECD1B53D77EAB6140
                SHA-512:853FB18264DCA3990C7D821B454E98B542B67D7F36FD0270DED8338D2206266BE1C0DA77A0637BABA05302D29A8A808CE7BB33116AC9F822B9C711793C8BB229
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 7 13:02:57 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.986952209134305
                Encrypted:false
                SSDEEP:48:8hNdaST6ejEHu0idAKZdA1vehDiZUkwqeh8y+R:8ESOq1yy
                MD5:C457C407B78C41B3889A222F04EBE467
                SHA1:4A83385D5F3FA599A838BEA05044F8C2F754726B
                SHA-256:37A0D70B750CFCB03C2CF9AE4E95B0909F074E12ED0BE00A07C8E282393A64D3
                SHA-512:B5207497B77B9F613EB29F5E737AF57A0D0AFD51159700516738CB630EEAA6C7837C8522C57C0E04386B75AF87E93736A10E4FB06A1FFF232D189B35ABDD1B0A
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....&...)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W]p...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 7 13:02:57 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.978511677888848
                Encrypted:false
                SSDEEP:48:8amNdaST6ejEHu0idAKZdA1hehBiZUk1W1qehWy+C:8KSOql92y
                MD5:357F28BC245334E64C8E8FB585092911
                SHA1:33DFFBCDF8DF3E1E9213755E0FA3BB297C5010BF
                SHA-256:456FE3AF4D7BB4639F8535D357862FDE89CC44FEDA2A12236A8A844BEEB9C81C
                SHA-512:BEB88A3A8C1066DCC72B7A18977903833F5F8D736DB78CD72A48D756BB9E059E8B3420CCCA192D93F4C3CD1B8B87A9A498343BD93CDB154E253988C95017391D
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.........)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W]p...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 7 13:02:57 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2683
                Entropy (8bit):3.9887634869831534
                Encrypted:false
                SSDEEP:48:8+NdaST6ejEHu0idAKZdA1duT+ehOuTbbiZUk5OjqehOuTb0y+yT+:8TSOq5T/TbxWOvTb0y7T
                MD5:900373A2C0816EBF8B3CE34F4B3A4DB5
                SHA1:1A0994E68135F232657D5C7F191A6E63566A6DC7
                SHA-256:79EBD9DBD080618E6A6051B36CF1FAE40DC20BDC3210EB28D039303A34285D69
                SHA-512:03FAA7B14F90F3AED80C644A90AA25C35E0F21DB673C25A4027279E66CDDFC683A3700B4B6B04933427391B9D056A8B3487E914B0EB48756EDA26150EA786F28
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,........)..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.WZp....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.WZp....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.WZp....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.WZp..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W]p...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............o.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:dropped
                Size (bytes):471
                Entropy (8bit):7.2065006082985725
                Encrypted:false
                SSDEEP:6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ
                MD5:E09531B89414706804DA63BADE235FF4
                SHA1:48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09
                SHA-256:F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377
                SHA-512:65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE
                Malicious:false
                Reputation:low
                Preview:0..........0.....+.....0......0...0.........2...,......$.]....20231206234938Z0s0q0I0...+........s...b..A.C....O...A.....2...,......$.].......R.)6e...xU..X....20231206233302Z....20231213223302Z0...*.H.............K..!...)._.fge')....&{../.*.%......[8.{)..5T..\..|I..g87/..[....Sg.<.q.@.`.h...].dy.....-..|.C.....N]sDA..eo..}....iU...".N..?*..s..U@.p/k&............ .. ...r..j.B.(.y..R..n....I.t6Zsp....G.k.K.Y...+.v..5..)...*..Cw;U+........8..-.X.`.].N.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:data
                Category:downloaded
                Size (bytes):471
                Entropy (8bit):7.2065006082985725
                Encrypted:false
                SSDEEP:6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ
                MD5:E09531B89414706804DA63BADE235FF4
                SHA1:48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09
                SHA-256:F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377
                SHA-512:65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE
                Malicious:false
                Reputation:low
                URL:http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
                Preview:0..........0.....+.....0......0...0.........2...,......$.]....20231206234938Z0s0q0I0...+........s...b..A.C....O...A.....2...,......$.].......R.)6e...xU..X....20231206233302Z....20231213223302Z0...*.H.............K..!...)._.fge')....&{../.*.%......[8.{)..5T..\..|I..g87/..[....Sg.<.q.@.`.h...].dy.....-..|.C.....N]sDA..eo..}....iU...".N..?*..s..U@.p/k&............ .. ...r..j.B.(.y..R..n....I.t6Zsp....G.k.K.Y...+.v..5..)...*..Cw;U+........8..-.X.`.].N.
                No static file info
                Icon Hash:00b29a8e86828200

                Download Network PCAP: filteredfull

                • Total Packets: 95
                • 443 (HTTPS)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Dec 7, 2023 15:02:49.917004108 CET49674443192.168.2.523.1.237.91
                Dec 7, 2023 15:02:49.917020082 CET49675443192.168.2.523.1.237.91
                Dec 7, 2023 15:02:50.026473999 CET49673443192.168.2.523.1.237.91
                Dec 7, 2023 15:02:55.764755964 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:55.764808893 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:55.764888048 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:55.765194893 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:55.765283108 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:55.765362024 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:55.766189098 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:55.766206026 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:55.766428947 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:55.766462088 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.085910082 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.086255074 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.086313009 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.087057114 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.087152004 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.088901997 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.088985920 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.090070963 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.095181942 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.095206976 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.095551968 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.095684052 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.095864058 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.095874071 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.096858978 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.096929073 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.098258018 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.098345041 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.098501921 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.098514080 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.230448961 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.230448008 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.362190008 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.363244057 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.363333941 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.363648891 CET49705443192.168.2.5192.178.50.46
                Dec 7, 2023 15:02:56.363688946 CET44349705192.178.50.46192.168.2.5
                Dec 7, 2023 15:02:56.375889063 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.376173973 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:56.376281023 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.376874924 CET49704443192.168.2.5142.250.64.141
                Dec 7, 2023 15:02:56.376904964 CET44349704142.250.64.141192.168.2.5
                Dec 7, 2023 15:02:58.040376902 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.040435076 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.040513992 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.040935040 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.040955067 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.330024004 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.330367088 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.330430031 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.332068920 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.332180977 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.333447933 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.333559990 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.373454094 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:58.373466015 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:02:58.420639038 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:02:59.526632071 CET49675443192.168.2.523.1.237.91
                Dec 7, 2023 15:02:59.526633978 CET49674443192.168.2.523.1.237.91
                Dec 7, 2023 15:02:59.628803968 CET49673443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:00.529115915 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.529159069 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:00.529242992 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.532367945 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.532386065 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:00.800410032 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:00.800683975 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.804109097 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.804124117 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:00.804553986 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:00.858104944 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.894768953 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:00.936743975 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.049007893 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.049093962 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.049200058 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.049398899 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.049417973 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.049459934 CET49714443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.049467087 CET4434971423.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.058665991 CET4434970323.1.237.91192.168.2.5
                Dec 7, 2023 15:03:01.058772087 CET49703443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:01.103388071 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.103430033 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.103537083 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.104144096 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.104157925 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.361572981 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.361758947 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.363020897 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.363053083 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.363390923 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.364599943 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.408740044 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.612252951 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.612411022 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.612508059 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.613545895 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.613545895 CET49715443192.168.2.523.204.156.130
                Dec 7, 2023 15:03:01.613593102 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:01.613621950 CET4434971523.204.156.130192.168.2.5
                Dec 7, 2023 15:03:08.305449009 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:08.305510998 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:08.305619955 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:10.094424963 CET49711443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:10.094502926 CET44349711142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:10.164587021 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:10.164632082 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:10.164740086 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:10.167124033 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:10.167135954 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:10.664676905 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:10.664792061 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:10.678982019 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:10.679019928 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:10.679486036 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:10.731661081 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.230439901 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.247517109 CET49703443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.248758078 CET49703443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.249744892 CET49720443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.249798059 CET4434972023.1.237.91192.168.2.5
                Dec 7, 2023 15:03:11.249880075 CET49720443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.250719070 CET49720443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.250740051 CET4434972023.1.237.91192.168.2.5
                Dec 7, 2023 15:03:11.272743940 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.430450916 CET4434970323.1.237.91192.168.2.5
                Dec 7, 2023 15:03:11.431746006 CET4434970323.1.237.91192.168.2.5
                Dec 7, 2023 15:03:11.549880028 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549916029 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549925089 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549947977 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549971104 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549978971 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.549989939 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.550013065 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.550050974 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.550085068 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.550544024 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.550637960 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.550642967 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.550656080 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.550729036 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.632666111 CET4434972023.1.237.91192.168.2.5
                Dec 7, 2023 15:03:11.632837057 CET49720443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:11.867788076 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.867788076 CET49716443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:11.867836952 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:11.867854118 CET4434971613.85.23.86192.168.2.5
                Dec 7, 2023 15:03:21.294608116 CET8049709195.200.45.10192.168.2.5
                Dec 7, 2023 15:03:30.806865931 CET4434972023.1.237.91192.168.2.5
                Dec 7, 2023 15:03:30.807096004 CET49720443192.168.2.523.1.237.91
                Dec 7, 2023 15:03:48.234379053 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.234425068 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:48.234524965 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.235152960 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.235169888 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:48.749973059 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:48.750102997 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.755405903 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.755426884 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:48.755836964 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:48.768706083 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:48.812733889 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.224703074 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.224837065 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.224952936 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.225150108 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.225150108 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.225199938 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.225229979 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.225280046 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.225326061 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.236581087 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.236613035 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:49.236685991 CET49724443192.168.2.513.85.23.86
                Dec 7, 2023 15:03:49.236700058 CET4434972413.85.23.86192.168.2.5
                Dec 7, 2023 15:03:57.955111980 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:57.955204964 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:57.955303907 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:57.956655025 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:57.956693888 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:58.241117954 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:58.241538048 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:58.241578102 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:58.241967916 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:58.242659092 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:03:58.242731094 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:03:58.283001900 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:04:08.219012976 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:04:08.219163895 CET44349726142.250.217.228192.168.2.5
                Dec 7, 2023 15:04:08.219337940 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:04:10.117304087 CET49726443192.168.2.5142.250.217.228
                Dec 7, 2023 15:04:10.117366076 CET44349726142.250.217.228192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Dec 7, 2023 15:02:55.571717978 CET5852753192.168.2.51.1.1.1
                Dec 7, 2023 15:02:55.600485086 CET5630653192.168.2.51.1.1.1
                Dec 7, 2023 15:02:55.604577065 CET5704753192.168.2.51.1.1.1
                Dec 7, 2023 15:02:55.604877949 CET5600553192.168.2.51.1.1.1
                Dec 7, 2023 15:02:55.696245909 CET53629321.1.1.1192.168.2.5
                Dec 7, 2023 15:02:55.697247982 CET53585271.1.1.1192.168.2.5
                Dec 7, 2023 15:02:55.727010012 CET53563061.1.1.1192.168.2.5
                Dec 7, 2023 15:02:55.729518890 CET53560051.1.1.1192.168.2.5
                Dec 7, 2023 15:02:55.730360985 CET53570471.1.1.1192.168.2.5
                Dec 7, 2023 15:02:56.555212975 CET53523111.1.1.1192.168.2.5
                Dec 7, 2023 15:02:57.590269089 CET5864153192.168.2.51.1.1.1
                Dec 7, 2023 15:02:57.590503931 CET5055953192.168.2.51.1.1.1
                Dec 7, 2023 15:02:57.910032034 CET4968553192.168.2.51.1.1.1
                Dec 7, 2023 15:02:57.910985947 CET5594353192.168.2.51.1.1.1
                Dec 7, 2023 15:02:58.035283089 CET53496851.1.1.1192.168.2.5
                Dec 7, 2023 15:02:58.036242008 CET53559431.1.1.1192.168.2.5
                Dec 7, 2023 15:03:13.561676979 CET53634091.1.1.1192.168.2.5
                Dec 7, 2023 15:03:32.530524015 CET53648331.1.1.1192.168.2.5
                Dec 7, 2023 15:03:55.006676912 CET53585101.1.1.1192.168.2.5
                Dec 7, 2023 15:03:55.084480047 CET53619001.1.1.1192.168.2.5
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 7, 2023 15:02:55.571717978 CET192.168.2.51.1.1.10x9dc2Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:55.600485086 CET192.168.2.51.1.1.10x1789Standard query (0)clients2.google.com65IN (0x0001)false
                Dec 7, 2023 15:02:55.604577065 CET192.168.2.51.1.1.10x41b8Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:55.604877949 CET192.168.2.51.1.1.10x9ec8Standard query (0)accounts.google.com65IN (0x0001)false
                Dec 7, 2023 15:02:57.590269089 CET192.168.2.51.1.1.10x308aStandard query (0)status.thawte.comA (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:57.590503931 CET192.168.2.51.1.1.10xba38Standard query (0)status.thawte.com65IN (0x0001)false
                Dec 7, 2023 15:02:57.910032034 CET192.168.2.51.1.1.10xf540Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:57.910985947 CET192.168.2.51.1.1.10xafb4Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 7, 2023 15:02:55.697247982 CET1.1.1.1192.168.2.50x9dc2No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Dec 7, 2023 15:02:55.697247982 CET1.1.1.1192.168.2.50x9dc2No error (0)clients.l.google.com192.178.50.46A (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:55.727010012 CET1.1.1.1192.168.2.50x1789No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Dec 7, 2023 15:02:55.730360985 CET1.1.1.1192.168.2.50x41b8No error (0)accounts.google.com142.250.64.141A (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:58.035283089 CET1.1.1.1192.168.2.50xf540No error (0)www.google.com142.250.217.228A (IP address)IN (0x0001)false
                Dec 7, 2023 15:02:58.036242008 CET1.1.1.1192.168.2.50xafb4No error (0)www.google.com65IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • fs.microsoft.com
                • slscr.update.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.549705192.178.50.464436696C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2023-12-07 14:02:56 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-117.0.5938.132
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-12-07 14:02:56 UTC732INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 73 63 72 69 70 74 2d 73 72 63 20 27 72 65 70 6f 72 74 2d 73 61 6d 70 6c 65 27 20 27 6e 6f 6e 63 65 2d 4a 75 54 71 2d 74 74 6b 57 53 72 31 34 49 51 75 52 5f 68 37 78 51 27 20 27 75 6e 73 61 66 65 2d 69 6e 6c 69 6e 65 27 20 27 73 74 72 69 63 74 2d 64 79 6e 61 6d 69 63 27 20 68 74 74 70 73 3a 20 68 74 74 70 3a 3b 6f 62 6a 65 63 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 72 65 70 6f 72 74 2d 75 72 69 20 68 74 74 70 73 3a 2f 2f 63 73 70 2e 77 69 74 68 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 63 73 70 2f 63 6c 69 65 6e 74 75 70 64 61 74 65 2d 61 75 73 2f 31 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c
                Data Ascii: HTTP/1.1 200 OKContent-Security-Policy: script-src 'report-sample' 'nonce-JuTq-ttkWSr14IQuR_h7xQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1Cache-Control
                2023-12-07 14:02:56 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 38 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 31 37 37 36 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6184" elapsed_seconds="21776"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2023-12-07 14:02:56 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2023-12-07 14:02:56 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.549704142.250.64.1414436696C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2023-12-07 14:02:56 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
                2023-12-07 14:02:56 UTC1OUTData Raw: 20
                Data Ascii:
                2023-12-07 14:02:56 UTC1627INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 73 6f 6e 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 0d 0a 41 63 63 65 73 73 2d 43 6f 6e 74 72 6f 6c 2d 41 6c 6c 6f 77 2d 4f 72 69 67 69 6e 3a 20 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 0d 0a 41 63 63 65 73 73 2d 43 6f 6e 74 72 6f 6c 2d 41 6c 6c 6f 77 2d 43 72 65 64 65 6e 74 69 61 6c 73 3a 20 74 72 75 65 0d 0a 58 2d 43 6f 6e 74 65 6e 74 2d 54 79 70 65 2d 4f 70 74 69 6f 6e 73 3a 20 6e 6f 73 6e 69 66 66 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 2c 20 6e 6f 2d 73 74 6f 72 65 2c 20 6d 61 78 2d 61 67 65 3d 30 2c 20 6d 75 73 74 2d 72 65 76 61 6c 69 64 61 74 65 0d 0a 50 72
                Data Ascii: HTTP/1.1 200 OKContent-Type: application/json; charset=utf-8Access-Control-Allow-Origin: https://www.google.comAccess-Control-Allow-Credentials: trueX-Content-Type-Options: nosniffCache-Control: no-cache, no-store, max-age=0, must-revalidatePr
                2023-12-07 14:02:56 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2023-12-07 14:02:56 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.54971423.204.156.130443
                TimestampBytes transferredDirectionData
                2023-12-07 14:03:00 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2023-12-07 14:03:01 UTC495INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 41 70 69 56 65 72 73 69 6f 6e 3a 20 44 69 73 74 72 69 62 75 74 65 20 31 2e 31 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 61 74 74 61 63 68 6d 65 6e 74 3b 20 66 69 6c 65 6e 61 6d 65 3d 63 6f 6e 66 69 67 2e 6a 73 6f 6e 3b 20 66 69 6c 65 6e 61 6d 65 2a 3d 55 54 46 2d 38 27 27 63 6f 6e 66 69 67 2e 6a 73 6f 6e 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 45 54 61 67 3a 20 22 30 78 36 34 36 36 37 46 37 30 37 46 46 30 37 44 36 32 42 37 33 33 44 42 43 42 37 39 45 46 45 33 38 35 35 45 36 38 38 36 43 39 39 37 35 42 30 43 30 42 34 36 37 44 34 36 32 33 31 42 33 46 41 35 45 37 22 0d 0a 4c 61 73 74 2d 4d 6f 64 69
                Data Ascii: HTTP/1.1 200 OKApiVersion: Distribute 1.1Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.jsonContent-Type: application/octet-streamETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"Last-Modi


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.54971523.204.156.130443
                TimestampBytes transferredDirectionData
                2023-12-07 14:03:01 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2023-12-07 14:03:01 UTC531INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 4c 61 73 74 2d 4d 6f 64 69 66 69 65 64 3a 20 54 75 65 2c 20 31 36 20 4d 61 79 20 32 30 31 37 20 32 32 3a 35 38 3a 30 30 20 47 4d 54 0d 0a 45 54 61 67 3a 20 22 30 78 36 34 36 36 37 46 37 30 37 46 46 30 37 44 36 32 42 37 33 33 44 42 43 42 37 39 45 46 45 33 38 35 35 45 36 38 38 36 43 39 39 37 35 42 30 43 30 42 34 36 37 44 34 36 32 33 31 42 33 46 41 35 45 37 22 0d 0a 41 70 69 56 65 72 73 69 6f 6e 3a 20 44 69 73 74 72 69 62 75 74 65 20 31 2e 31 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 61 74 74 61 63 68 6d 65 6e 74 3b 20 66 69 6c 65 6e 61 6d 65 3d 63 6f 6e 66 69 67
                Data Ascii: HTTP/1.1 200 OKContent-Type: application/octet-streamLast-Modified: Tue, 16 May 2017 22:58:00 GMTETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"ApiVersion: Distribute 1.1Content-Disposition: attachment; filename=config
                2023-12-07 14:03:01 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.54971613.85.23.86443
                TimestampBytes transferredDirectionData
                2023-12-07 14:03:11 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LZv65tGxLmkuks1&MD=ZGv4X2os HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2023-12-07 14:03:11 UTC560INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 50 72 61 67 6d 61 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 45 78 70 69 72 65 73 3a 20 2d 31 0d 0a 4c 61 73 74 2d 4d 6f 64 69 66 69 65 64 3a 20 4d 6f 6e 2c 20 30 31 20 4a 61 6e 20 30 30 30 31 20 30 30 3a 30 30 3a 30 30 20 47 4d 54 0d 0a 45 54 61 67 3a 20 22 58 41 6f 70 61 7a 56 30 30 58 44 57 6e 4a 43 77 6b 6d 45 57 52 76 36 4a 6b 62 6a 52 41 39 51 53 53 5a 32 2b 65 2f 33 4d 7a 45 6b 3d 5f 32 38 38 30 22 0d 0a 4d 53 2d 43 6f 72 72 65 6c 61 74 69 6f 6e 49 64 3a 20 61 35 36 62 36 39 38 37 2d 39 65 64 38 2d 34 35 31 34 2d
                Data Ascii: HTTP/1.1 200 OKCache-Control: no-cachePragma: no-cacheContent-Type: application/octet-streamExpires: -1Last-Modified: Mon, 01 Jan 0001 00:00:00 GMTETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"MS-CorrelationId: a56b6987-9ed8-4514-
                2023-12-07 14:03:11 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                2023-12-07 14:03:11 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.54972413.85.23.86443
                TimestampBytes transferredDirectionData
                2023-12-07 14:03:48 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LZv65tGxLmkuks1&MD=ZGv4X2os HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2023-12-07 14:03:49 UTC560INData Raw: 48 54 54 50 2f 31 2e 31 20 32 30 30 20 4f 4b 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 50 72 61 67 6d 61 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 45 78 70 69 72 65 73 3a 20 2d 31 0d 0a 4c 61 73 74 2d 4d 6f 64 69 66 69 65 64 3a 20 4d 6f 6e 2c 20 30 31 20 4a 61 6e 20 30 30 30 31 20 30 30 3a 30 30 3a 30 30 20 47 4d 54 0d 0a 45 54 61 67 3a 20 22 4d 78 31 52 6f 4a 48 2f 71 45 77 70 57 66 4b 6c 6c 78 37 73 62 73 6c 32 38 41 75 45 52 7a 35 49 59 64 63 73 76 74 54 4a 63 67 4d 3d 5f 32 31 36 30 22 0d 0a 4d 53 2d 43 6f 72 72 65 6c 61 74 69 6f 6e 49 64 3a 20 33 65 66 66 66 34 32 66 2d 62 63 31 32 2d 34 36 36 37 2d
                Data Ascii: HTTP/1.1 200 OKCache-Control: no-cachePragma: no-cacheContent-Type: application/octet-streamExpires: -1Last-Modified: Mon, 01 Jan 0001 00:00:00 GMTETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"MS-CorrelationId: 3efff42f-bc12-4667-
                2023-12-07 14:03:49 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
                Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
                2023-12-07 14:03:49 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
                Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:0
                Start time:15:02:51
                Start date:07/12/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:15:02:52
                Start date:07/12/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2348 --field-trial-handle=2288,i,12330104661967520940,682847274094739711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:15:02:56
                Start date:07/12/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly