Edit tour

Windows Analysis Report
https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330

Overview

General Information

Sample URL:https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-0
Analysis ID:1361816
Infos:
Errors
  • URL not reachable

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1084 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4696 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2344 --field-trial-handle=2428,i,2270692946507266797,10037903936560076564,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2992 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.205.142.165:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.205.142.165:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49721 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.205.142.165
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330 HTTP/1.1Host: tracking.buttondown.emailConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Uo+fVbPHOLzFTXb&MD=u5M37oY4 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 23.205.142.165:443 -> 192.168.2.5:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.205.142.165:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: unknown1.win@17/6@8/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2344 --field-trial-handle=2428,i,2270692946507266797,10037903936560076564,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2344 --field-trial-handle=2428,i,2270692946507266797,10037903936560076564,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1361816 URL: https://tracking.buttondown... Startdate: 14/12/2023 Architecture: WINDOWS Score: 1 5 chrome.exe 8 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.5, 443, 49703, 49705 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.217.164, 443, 49713 GOOGLEUS United States 10->17 19 accounts.google.com 172.217.3.77, 443, 49705 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=3300%Avira URL Cloudsafe
https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=3300%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.3.77
truefalse
    high
    www.google.com
    142.250.217.164
    truefalse
      high
      clients.l.google.com
      192.178.50.46
      truefalse
        high
        d1yws0jclnpzob.cloudfront.net
        108.157.162.89
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            tracking.buttondown.email
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.217.164
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    192.178.50.46
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    108.157.162.89
                    d1yws0jclnpzob.cloudfront.netUnited States
                    16509AMAZON-02USfalse
                    172.217.3.77
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.5
                    Joe Sandbox version:38.0.0 Ammolite
                    Analysis ID:1361816
                    Start date and time:2023-12-14 01:26:11 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 1m 53s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:6
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:UNKNOWN
                    Classification:unknown1.win@17/6@8/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    Cookbook Comments:
                    • URL browsing timeout or error
                    • URL not reachable
                    • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 192.178.50.67, 34.104.35.123, 104.91.175.157, 23.193.106.15, 192.229.211.108
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com
                    • Not all processes where analyzed, report is missing behavior information
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Dec 13 23:27:02 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2677
                    Entropy (8bit):3.9756426939503697
                    Encrypted:false
                    SSDEEP:48:8qgdqTWiFHDidAKZdA19ehwiZUklqehJy+3:8cT3Cy
                    MD5:290651A79B415F1F712BB7FA0E4C5234
                    SHA1:27F238883C0528268C16E2C28353E2C371893693
                    SHA-256:3CF5B9404C118E8AF265D98217E97ABA91F8D41C913C3CCD18A7C2DD1B3BAA4B
                    SHA-512:1E3CA43F04E4522ED69E99C46D22C4484891FE9E9E329768C9A3A0FE8FF79E7D3996A4B2595CE02DA9B7D5F1FF54594D2B48DE59348F1093FB1E6363624F5A67
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......%B$...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Wb............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Dec 13 23:27:02 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2679
                    Entropy (8bit):3.9911928229629074
                    Encrypted:false
                    SSDEEP:48:86dqTWiFHDidAKZdA1weh/iZUkAQkqehyy+2:8zT99Qjy
                    MD5:E34D3644E0DE2BE401C4193A60B0DCDD
                    SHA1:62771BB0ECB04CF5A190ADAF722A5702191F6CB1
                    SHA-256:06A4CF3AE00537167A0E8F7F647E31BADF476D83D9C94B3038C384545F03EF5C
                    SHA-512:43BC4C7841857BEB12B186476E255E79748049D106336B16EB177C5FC05C81244511D1F92F509C7135D3C72A6F8F37C9E2FFC16730985593F467C043FFC0B305
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.......B$...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Wb............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2693
                    Entropy (8bit):4.003163831466344
                    Encrypted:false
                    SSDEEP:48:8xjdqTWisHDidAKZdA14tseh7sFiZUkmgqeh7sky+BX:8xET2nmy
                    MD5:58F781995171D4BDC31CCC31CB71A09C
                    SHA1:275FFD609ECA1AA8C8997FED4340E2832871C443
                    SHA-256:EE820802DA5C94173D16154F78595B2F34CD8FD657868C5138FB31FA0F0B8A60
                    SHA-512:80A1A2D97D22AD830ABBF3F0FA452F2541A2FC4489D6425067011046AE41E1FDD8D12EE3B0A09E11EC4E2EB15FB115EC39D20AC22AC18D9A1C26A97F433A27C2
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Dec 13 23:27:02 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.989425689035601
                    Encrypted:false
                    SSDEEP:48:8ddqTWiFHDidAKZdA1vehDiZUkwqeh+y+R:86T+8y
                    MD5:06C54A627432C704B428CF81F928F4AE
                    SHA1:B7659AD81203963283D52153673BED5ADA3597B5
                    SHA-256:A1F6B0BCA2EB7F15ADA4D09C95AB22531B5A731DFE0FDC51CBB8563E86C69920
                    SHA-512:C00C13A4D04AAB6D792224227478CABF482647C21BFD872E5E180BEBB6738029AC73DF16035AAC37D6A7432DEE7438193CAC0634CFED7B93C1ADB09D6E68FF5C
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....z..B$...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Wb............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Dec 13 23:27:02 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.9788457635776813
                    Encrypted:false
                    SSDEEP:48:8ldqTWiFHDidAKZdA1hehBiZUk1W1qeh4y+C:8STO9Yy
                    MD5:8AE549768E960A9D1BC1CA3B21AD1A96
                    SHA1:6E7C5EFD8B0680ECDD27380D88E6C6F96686F537
                    SHA-256:20BB32B10EAC0D58BCE57A67A03B7F46A52BCCBBCBA55B60758DC7890E2938E9
                    SHA-512:E918808D286EF00B514B742D67CCFE126831C86CBD7A32B470721F7B72C8B01A7DF528881AB5B51EF6F1457AC88C4860316F13A869340650638A1B14BC7B3968
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.......B$...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Wb............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Dec 13 23:27:02 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2683
                    Entropy (8bit):3.9896673518881407
                    Encrypted:false
                    SSDEEP:48:87OdqTWiFHDidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbmy+yT+:87vTwT/TbxWOvTbmy7T
                    MD5:C146BC1F4C6C297F1C4B9F6B7DEC717B
                    SHA1:1BF1989C630E43F59EDEB6D92E39A26963807978
                    SHA-256:F7E3AE1D1546303EEBEAF65DAE7FE1A17511D34987E7B538BBF718CFC06460C5
                    SHA-512:FE566C238F919FDD86F68924E3614D0409DA8D49963C108161D2E8E4647F9315B016003CCB8D00BDE83E3F44654FE895C593356697D047FD72FEF6C5DC3195F9
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,.......B$...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.W].....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.W].....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W].....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W]............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Wb............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........V.G3.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 92
                    • 443 (HTTPS)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 14, 2023 01:26:57.195966959 CET49675443192.168.2.523.1.237.91
                    Dec 14, 2023 01:26:57.195972919 CET49674443192.168.2.523.1.237.91
                    Dec 14, 2023 01:26:57.289799929 CET49673443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:01.268671036 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.268704891 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.268762112 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.269177914 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.269212008 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.269259930 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.269527912 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.269540071 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.269756079 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.269769907 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.560337067 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.560695887 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.560717106 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.561856985 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.561918974 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.562792063 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.562845945 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.563018084 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.563029051 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.563782930 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.563961983 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.563985109 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.564312935 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.564369917 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.564922094 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.564990044 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.565826893 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.565893888 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.566077948 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.566083908 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.731465101 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.762721062 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.840111971 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.840257883 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.840343952 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.840766907 CET49706443192.168.2.5192.178.50.46
                    Dec 14, 2023 01:27:01.840780973 CET44349706192.178.50.46192.168.2.5
                    Dec 14, 2023 01:27:01.853698969 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.854259968 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:01.854406118 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.854937077 CET49705443192.168.2.5172.217.3.77
                    Dec 14, 2023 01:27:01.854948997 CET44349705172.217.3.77192.168.2.5
                    Dec 14, 2023 01:27:02.375577927 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.375672102 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.375773907 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.376626015 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.376662016 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.376704931 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.377001047 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.377018929 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.377217054 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.377228022 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.648909092 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.649270058 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.649282932 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.650145054 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.650213957 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.651120901 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.651175976 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.651329041 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.651334047 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.683562040 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.683912992 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.683936119 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.684954882 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.685019016 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.685385942 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.685452938 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.700870037 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.732214928 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.732225895 CET44349709108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.778887987 CET49709443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.937125921 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.937494040 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.937572956 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.937745094 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.937745094 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:02.937757015 CET44349710108.157.162.89192.168.2.5
                    Dec 14, 2023 01:27:02.937805891 CET49710443192.168.2.5108.157.162.89
                    Dec 14, 2023 01:27:05.462465048 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.462500095 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.462589979 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.463114977 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.463126898 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.737591982 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.739054918 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.739067078 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.740124941 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.740282059 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.743886948 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.743957043 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.792558908 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.792572021 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:05.839431047 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:05.953704119 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:05.953763008 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:05.953850985 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:05.957066059 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:05.957103968 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.215631962 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.215738058 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.217753887 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.217772007 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.218010902 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.261334896 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.267518997 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.312769890 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.460922956 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.460993052 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.461100101 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.471345901 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.471414089 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.471455097 CET49714443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.471472025 CET4434971423.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.521327019 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.521382093 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.521473885 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.522639990 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.522654057 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.777604103 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.777717113 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.781095982 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.781105995 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.781481981 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.782938957 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:06.808191061 CET49675443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:06.808192968 CET49674443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:06.828746080 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:06.901973963 CET49673443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:07.060502052 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:07.060687065 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:07.060748100 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:07.062660933 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:07.062681913 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:07.062695026 CET49715443192.168.2.523.205.142.165
                    Dec 14, 2023 01:27:07.062700987 CET4434971523.205.142.165192.168.2.5
                    Dec 14, 2023 01:27:08.318592072 CET4434970323.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:08.318717003 CET49703443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:15.715478897 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:15.715552092 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:15.715656996 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:17.332492113 CET49713443192.168.2.5142.250.217.164
                    Dec 14, 2023 01:27:17.332525969 CET44349713142.250.217.164192.168.2.5
                    Dec 14, 2023 01:27:17.428992987 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:17.429040909 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:17.429126024 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:17.431574106 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:17.431587934 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:17.921688080 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:17.921794891 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.033026934 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.033052921 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.033363104 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.073709011 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.572587013 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.610486984 CET49703443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:18.610619068 CET49703443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:18.611033916 CET49721443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:18.611062050 CET4434972123.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:18.611139059 CET49721443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:18.611390114 CET49721443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:18.611402035 CET4434972123.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:18.616741896 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.793035984 CET4434970323.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:18.793164968 CET4434970323.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:18.891621113 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891650915 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891658068 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891669989 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891705990 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891766071 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.891793013 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891808987 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891819000 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:18.891824961 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:18.891880035 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:19.004640102 CET4434972123.1.237.91192.168.2.5
                    Dec 14, 2023 01:27:19.004829884 CET49721443192.168.2.523.1.237.91
                    Dec 14, 2023 01:27:19.190934896 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:19.190964937 CET4434971613.85.23.86192.168.2.5
                    Dec 14, 2023 01:27:19.190980911 CET49716443192.168.2.513.85.23.86
                    Dec 14, 2023 01:27:19.190989017 CET4434971613.85.23.86192.168.2.5
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 14, 2023 01:27:01.142054081 CET5947753192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:01.142457008 CET6534053192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:01.143033981 CET5959253192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:01.143335104 CET6233053192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:01.251549006 CET53619511.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:01.267858028 CET53594771.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:01.268178940 CET53623301.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:01.268253088 CET53595921.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:01.268341064 CET53653401.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:02.011274099 CET53570731.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:02.242957115 CET6003953192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:02.243156910 CET5910053192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:02.373641968 CET53600391.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:02.373667002 CET53591001.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:05.315639973 CET5695953192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:05.316418886 CET5229253192.168.2.51.1.1.1
                    Dec 14, 2023 01:27:05.442394972 CET53569591.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:05.456238031 CET53522921.1.1.1192.168.2.5
                    Dec 14, 2023 01:27:20.169315100 CET53538841.1.1.1192.168.2.5
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Dec 14, 2023 01:27:01.142054081 CET192.168.2.51.1.1.10x21aaStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:01.142457008 CET192.168.2.51.1.1.10xd50eStandard query (0)clients2.google.com65IN (0x0001)false
                    Dec 14, 2023 01:27:01.143033981 CET192.168.2.51.1.1.10xc98dStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:01.143335104 CET192.168.2.51.1.1.10xa6bStandard query (0)accounts.google.com65IN (0x0001)false
                    Dec 14, 2023 01:27:02.242957115 CET192.168.2.51.1.1.10x92c6Standard query (0)tracking.buttondown.emailA (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:02.243156910 CET192.168.2.51.1.1.10x974cStandard query (0)tracking.buttondown.email65IN (0x0001)false
                    Dec 14, 2023 01:27:05.315639973 CET192.168.2.51.1.1.10x3824Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:05.316418886 CET192.168.2.51.1.1.10xc21dStandard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Dec 14, 2023 01:27:01.267858028 CET1.1.1.1192.168.2.50x21aaNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Dec 14, 2023 01:27:01.267858028 CET1.1.1.1192.168.2.50x21aaNo error (0)clients.l.google.com192.178.50.46A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:01.268253088 CET1.1.1.1192.168.2.50xc98dNo error (0)accounts.google.com172.217.3.77A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:01.268341064 CET1.1.1.1192.168.2.50xd50eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373641968 CET1.1.1.1192.168.2.50x92c6No error (0)tracking.buttondown.emaild1yws0jclnpzob.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373641968 CET1.1.1.1192.168.2.50x92c6No error (0)d1yws0jclnpzob.cloudfront.net108.157.162.89A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373641968 CET1.1.1.1192.168.2.50x92c6No error (0)d1yws0jclnpzob.cloudfront.net108.157.162.129A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373641968 CET1.1.1.1192.168.2.50x92c6No error (0)d1yws0jclnpzob.cloudfront.net108.157.162.66A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373641968 CET1.1.1.1192.168.2.50x92c6No error (0)d1yws0jclnpzob.cloudfront.net108.157.162.93A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:02.373667002 CET1.1.1.1192.168.2.50x974cNo error (0)tracking.buttondown.emaild1yws0jclnpzob.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                    Dec 14, 2023 01:27:05.442394972 CET1.1.1.1192.168.2.50x3824No error (0)www.google.com142.250.217.164A (IP address)IN (0x0001)false
                    Dec 14, 2023 01:27:05.456238031 CET1.1.1.1192.168.2.50xc21dNo error (0)www.google.com65IN (0x0001)false
                    • accounts.google.com
                    • clients2.google.com
                    • tracking.buttondown.email
                    • fs.microsoft.com
                    • slscr.update.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.549705172.217.3.774434696C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:01 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
                    2023-12-14 00:27:01 UTC1OUTData Raw: 20
                    Data Ascii:
                    2023-12-14 00:27:01 UTC1627INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Thu, 14 Dec 2023 00:27:01 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Cross-Origin-Opener-Policy: same-origin
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Content-Security-Policy: script-src 'report-sample' 'nonce-cbVPOrJ6OOPC9amMXAWZZA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-12-14 00:27:01 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2023-12-14 00:27:01 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.549706192.178.50.464434696C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:01 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-117.0.5938.132
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-12-14 00:27:01 UTC732INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-a-YjPqeTPpI7eVWPIC425w' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Thu, 14 Dec 2023 00:27:01 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6190
                    X-Daystart: 59221
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-12-14 00:27:01 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 39 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 39 32 32 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6190" elapsed_seconds="59221"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2023-12-14 00:27:01 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2023-12-14 00:27:01 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.549710108.157.162.894434696C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:02 UTC887OUTGET /CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330 HTTP/1.1
                    Host: tracking.buttondown.email
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2023-12-14 00:27:02 UTC300INHTTP/1.1 400 Bad Request
                    Content-Length: 0
                    Connection: close
                    Date: Thu, 14 Dec 2023 00:27:02 GMT
                    X-Cache: Error from cloudfront
                    Via: 1.1 a76bcba13e5cb08b0c42b2b314a7e412.cloudfront.net (CloudFront)
                    X-Amz-Cf-Pop: MIA3-P3
                    X-Amz-Cf-Id: l36ZVX_Y2mACX5w-8LUGx9vQuECzwfUJw_ZDEjoIeqHQGXKek2me4g==


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.54971423.205.142.165443
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:06 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2023-12-14 00:27:06 UTC495INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/073D)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus-z1
                    Cache-Control: public, max-age=231774
                    Date: Thu, 14 Dec 2023 00:27:06 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.54971523.205.142.165443
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:06 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2023-12-14 00:27:07 UTC531INHTTP/1.1 200 OK
                    Content-Type: application/octet-stream
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=231802
                    Date: Thu, 14 Dec 2023 00:27:06 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2023-12-14 00:27:07 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.54971613.85.23.86443
                    TimestampBytes transferredDirectionData
                    2023-12-14 00:27:18 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=Uo+fVbPHOLzFTXb&MD=u5M37oY4 HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                    Host: slscr.update.microsoft.com
                    2023-12-14 00:27:18 UTC560INHTTP/1.1 200 OK
                    Cache-Control: no-cache
                    Pragma: no-cache
                    Content-Type: application/octet-stream
                    Expires: -1
                    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                    ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                    MS-CorrelationId: 31d2e9f7-3484-480c-a5ca-0b9bd410c476
                    MS-RequestId: 765f69bb-a883-4810-95a9-87487efbd25c
                    MS-CV: JaycoLl8k0CJmCQv.0
                    X-Microsoft-SLSClientCache: 2880
                    Content-Disposition: attachment; filename=environment.cab
                    X-Content-Type-Options: nosniff
                    Date: Thu, 14 Dec 2023 00:27:18 GMT
                    Connection: close
                    Content-Length: 24490
                    2023-12-14 00:27:18 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                    Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                    2023-12-14 00:27:18 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                    Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                    05101520s020406080100

                    Click to jump to process

                    05101520s0.0050100MB

                    Click to jump to process

                    Target ID:0
                    Start time:01:26:56
                    Start date:14/12/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:01:26:59
                    Start date:14/12/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2344 --field-trial-handle=2428,i,2270692946507266797,10037903936560076564,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:01:27:01
                    Start date:14/12/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly