Edit tour

Windows Analysis Report
http://connectivitycheck.gstatic.com/generate_204

Overview

General Information

Sample URL:http://connectivitycheck.gstatic.com/generate_204
Analysis ID:1367567
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Creates files inside the system directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5668 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2004,i,1623341756167552409,2863486379579178111,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6364 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://connectivitycheck.gstatic.com/generate_204 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=+v9udulp5OslouA&MD=LmSXysEt HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=+v9udulp5OslouA&MD=LmSXysEt HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_5668_252522949Jump to behavior
Source: classification engineClassification label: clean0.win@16/0@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2004,i,1623341756167552409,2863486379579178111,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://connectivitycheck.gstatic.com/generate_204
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2004,i,1623341756167552409,2863486379579178111,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1367567 URL: http://connectivitycheck.gs... Startdate: 28/12/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49723 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 clients.l.google.com 142.250.113.101, 443, 49731 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.113.84, 443, 49730 GOOGLEUS United States 10->19 21 2 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://connectivitycheck.gstatic.com/generate_2040%Avira URL Cloudsafe
http://connectivitycheck.gstatic.com/generate_2040%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.113.84
truefalse
    high
    www.google.com
    142.250.115.103
    truefalse
      high
      clients.l.google.com
      142.250.113.101
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.115.103
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.113.84
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              142.250.113.101
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:38.0.0 Ammolite
              Analysis ID:1367567
              Start date and time:2023-12-28 06:09:15 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 49s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://connectivitycheck.gstatic.com/generate_204
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/0@6/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.113.94, 34.104.35.123, 208.111.176.128, 192.229.211.108
              • Excluded domains from analysis (whitelisted): connectivitycheck.gstatic.com, fs.microsoft.com, ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 94
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Dec 28, 2023 06:09:56.985229969 CET49675443192.168.2.4173.222.162.32
              Dec 28, 2023 06:09:57.250935078 CET49678443192.168.2.4104.46.162.224
              Dec 28, 2023 06:10:03.176830053 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.176867008 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.176923990 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.178801060 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.178823948 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.178880930 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.179277897 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.179290056 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.179495096 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.179506063 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.442168951 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.442375898 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.442394972 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.442739964 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.442800045 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.443583965 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.443641901 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.444353104 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.444421053 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.444515944 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.444525957 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.445202112 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.445354939 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.445372105 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.446783066 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.446854115 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.447580099 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.447654009 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.447858095 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.447869062 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.499341965 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.499342918 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.698970079 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.699119091 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.699168921 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.699425936 CET49731443192.168.2.4142.250.113.101
              Dec 28, 2023 06:10:03.699440956 CET44349731142.250.113.101192.168.2.4
              Dec 28, 2023 06:10:03.707998991 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.708074093 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.708086014 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.709641933 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:03.709714890 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.709804058 CET49730443192.168.2.4142.250.113.84
              Dec 28, 2023 06:10:03.709814072 CET44349730142.250.113.84192.168.2.4
              Dec 28, 2023 06:10:06.593377113 CET49675443192.168.2.4173.222.162.32
              Dec 28, 2023 06:10:07.412369967 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.412400007 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.412458897 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.413250923 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.413263083 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.664546967 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.664891958 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.664901972 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.665759087 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.665821075 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.667174101 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.667226076 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.719310999 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:07.719321966 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:07.729512930 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:07.729564905 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:07.729648113 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:07.732553005 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:07.732582092 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:07.766139030 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:08.019948006 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.020087004 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.022010088 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.022032022 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.022247076 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.063020945 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.074084997 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.116734982 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.294044971 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.294095039 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.294233084 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.294265985 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.294265985 CET49739443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.294285059 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.294294119 CET44349739184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.333798885 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.333830118 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.334019899 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.334369898 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.334378958 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.617379904 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.617470980 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.619724035 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.619733095 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.619954109 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.621486902 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.668730021 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.894207954 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.894412041 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.894573927 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.895984888 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.895996094 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:08.896043062 CET49740443192.168.2.4184.31.62.93
              Dec 28, 2023 06:10:08.896049023 CET44349740184.31.62.93192.168.2.4
              Dec 28, 2023 06:10:17.676887035 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:17.676949024 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:17.677002907 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:19.229640961 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:19.229680061 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:19.229753971 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:19.231703997 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:19.231724024 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:19.346118927 CET49738443192.168.2.4142.250.115.103
              Dec 28, 2023 06:10:19.346147060 CET44349738142.250.115.103192.168.2.4
              Dec 28, 2023 06:10:19.980269909 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:19.980371952 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:19.983118057 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:19.983139038 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:19.983345985 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.031749010 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:20.454539061 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:20.496745110 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945681095 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945703030 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945708990 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945719004 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945741892 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945771933 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:20.945794106 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945807934 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945811033 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:20.945856094 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:20.945861101 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:20.945902109 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:21.225982904 CET49741443192.168.2.440.68.123.157
              Dec 28, 2023 06:10:21.226010084 CET4434974140.68.123.157192.168.2.4
              Dec 28, 2023 06:10:57.730179071 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:57.730211973 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:57.730283022 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:57.731062889 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:57.731079102 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.131325006 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.131411076 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.135171890 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.135183096 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.135427952 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.148264885 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.188744068 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520363092 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520382881 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520442009 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520498991 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.520513058 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520524979 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:10:58.520544052 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.520581007 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.532773972 CET49747443192.168.2.413.85.23.86
              Dec 28, 2023 06:10:58.532787085 CET4434974713.85.23.86192.168.2.4
              Dec 28, 2023 06:11:07.333101988 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:07.333146095 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.333219051 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:07.333964109 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:07.333978891 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.583172083 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.583468914 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:07.583501101 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.583790064 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.584387064 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:07.584445953 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:07.625448942 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:16.227657080 CET4972380192.168.2.472.21.81.240
              Dec 28, 2023 06:11:16.227827072 CET4972480192.168.2.472.21.81.240
              Dec 28, 2023 06:11:16.348259926 CET804972372.21.81.240192.168.2.4
              Dec 28, 2023 06:11:16.348444939 CET4972380192.168.2.472.21.81.240
              Dec 28, 2023 06:11:16.348539114 CET804972472.21.81.240192.168.2.4
              Dec 28, 2023 06:11:16.348593950 CET4972480192.168.2.472.21.81.240
              Dec 28, 2023 06:11:17.633743048 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:17.633805037 CET44349749142.250.115.103192.168.2.4
              Dec 28, 2023 06:11:17.633865118 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:19.346128941 CET49749443192.168.2.4142.250.115.103
              Dec 28, 2023 06:11:19.346155882 CET44349749142.250.115.103192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Dec 28, 2023 06:10:03.053023100 CET5148153192.168.2.41.1.1.1
              Dec 28, 2023 06:10:03.053189993 CET5008553192.168.2.41.1.1.1
              Dec 28, 2023 06:10:03.053615093 CET6419053192.168.2.41.1.1.1
              Dec 28, 2023 06:10:03.053812027 CET5505753192.168.2.41.1.1.1
              Dec 28, 2023 06:10:03.164021015 CET53630611.1.1.1192.168.2.4
              Dec 28, 2023 06:10:03.174873114 CET53500851.1.1.1192.168.2.4
              Dec 28, 2023 06:10:03.175056934 CET53514811.1.1.1192.168.2.4
              Dec 28, 2023 06:10:03.175143003 CET53550571.1.1.1192.168.2.4
              Dec 28, 2023 06:10:03.175398111 CET53641901.1.1.1192.168.2.4
              Dec 28, 2023 06:10:03.872484922 CET53563641.1.1.1192.168.2.4
              Dec 28, 2023 06:10:04.691340923 CET53553461.1.1.1192.168.2.4
              Dec 28, 2023 06:10:07.285049915 CET5190253192.168.2.41.1.1.1
              Dec 28, 2023 06:10:07.285739899 CET5264853192.168.2.41.1.1.1
              Dec 28, 2023 06:10:07.407254934 CET53519021.1.1.1192.168.2.4
              Dec 28, 2023 06:10:07.407275915 CET53526481.1.1.1192.168.2.4
              Dec 28, 2023 06:10:21.670792103 CET53628301.1.1.1192.168.2.4
              Dec 28, 2023 06:10:27.773552895 CET138138192.168.2.4192.168.2.255
              Dec 28, 2023 06:10:40.440748930 CET53560531.1.1.1192.168.2.4
              Dec 28, 2023 06:11:02.641310930 CET53530601.1.1.1192.168.2.4
              Dec 28, 2023 06:11:03.373784065 CET53528501.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Dec 28, 2023 06:10:03.053023100 CET192.168.2.41.1.1.10xa2e2Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.053189993 CET192.168.2.41.1.1.10x70c0Standard query (0)clients2.google.com65IN (0x0001)false
              Dec 28, 2023 06:10:03.053615093 CET192.168.2.41.1.1.10xf53cStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.053812027 CET192.168.2.41.1.1.10xce3bStandard query (0)accounts.google.com65IN (0x0001)false
              Dec 28, 2023 06:10:07.285049915 CET192.168.2.41.1.1.10x1276Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.285739899 CET192.168.2.41.1.1.10x4f5cStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Dec 28, 2023 06:10:03.174873114 CET1.1.1.1192.168.2.40x70c0No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.101A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.113A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.100A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.138A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.102A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175056934 CET1.1.1.1192.168.2.40xa2e2No error (0)clients.l.google.com142.250.113.139A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:03.175398111 CET1.1.1.1192.168.2.40xf53cNo error (0)accounts.google.com142.250.113.84A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.103A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.106A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.147A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.99A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.105A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407254934 CET1.1.1.1192.168.2.40x1276No error (0)www.google.com142.250.115.104A (IP address)IN (0x0001)false
              Dec 28, 2023 06:10:07.407275915 CET1.1.1.1192.168.2.40x4f5cNo error (0)www.google.com65IN (0x0001)false
              • clients2.google.com
              • accounts.google.com
              • fs.microsoft.com
              • slscr.update.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449731142.250.113.1014435084C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:03 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-117.0.5938.132
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-12-28 05:10:03 UTC732INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-T3IL_VhEPmMpwj4XH0n3NA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Thu, 28 Dec 2023 05:10:03 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 6204
              X-Daystart: 76203
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-12-28 05:10:03 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 30 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 37 36 32 30 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6204" elapsed_seconds="76203"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-12-28 05:10:03 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-12-28 05:10:03 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449730142.250.113.844435084C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:03 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
              2023-12-28 05:10:03 UTC1OUTData Raw: 20
              Data Ascii:
              2023-12-28 05:10:03 UTC1627INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Thu, 28 Dec 2023 05:10:03 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Content-Security-Policy: script-src 'report-sample' 'nonce-Ocl_kH_ojkljCiNrHbx-_Q' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Cross-Origin-Opener-Policy: same-origin
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-12-28 05:10:03 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-12-28 05:10:03 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449739184.31.62.93443
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:08 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2023-12-28 05:10:08 UTC495INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/073D)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=42357
              Date: Thu, 28 Dec 2023 05:10:08 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449740184.31.62.93443
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:08 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2023-12-28 05:10:08 UTC455INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0778)
              X-CID: 11
              Cache-Control: public, max-age=42313
              Date: Thu, 28 Dec 2023 05:10:08 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2023-12-28 05:10:08 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.44974140.68.123.157443
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:20 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=+v9udulp5OslouA&MD=LmSXysEt HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
              Host: slscr.update.microsoft.com
              2023-12-28 05:10:20 UTC560INHTTP/1.1 200 OK
              Cache-Control: no-cache
              Pragma: no-cache
              Content-Type: application/octet-stream
              Expires: -1
              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
              ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
              MS-CorrelationId: b794c5db-e471-48b4-86e0-e0ad77cd3a44
              MS-RequestId: 7d0f4c7b-4b5e-4d18-9a09-07e28c3dbf39
              MS-CV: 6F2qO8BwKEy5/0lk.0
              X-Microsoft-SLSClientCache: 2880
              Content-Disposition: attachment; filename=environment.cab
              X-Content-Type-Options: nosniff
              Date: Thu, 28 Dec 2023 05:10:20 GMT
              Connection: close
              Content-Length: 24490
              2023-12-28 05:10:20 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
              Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
              2023-12-28 05:10:20 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
              Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.44974713.85.23.86443
              TimestampBytes transferredDirectionData
              2023-12-28 05:10:58 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=+v9udulp5OslouA&MD=LmSXysEt HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
              Host: slscr.update.microsoft.com
              2023-12-28 05:10:58 UTC560INHTTP/1.1 200 OK
              Cache-Control: no-cache
              Pragma: no-cache
              Content-Type: application/octet-stream
              Expires: -1
              Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
              ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
              MS-CorrelationId: ad4f9bf5-aa6d-4e61-ad2f-48be72fdbd0c
              MS-RequestId: 9b85e250-c6a0-41f5-8828-c63faccf2a3a
              MS-CV: ew0sSMAHuE+PbcBS.0
              X-Microsoft-SLSClientCache: 2160
              Content-Disposition: attachment; filename=environment.cab
              X-Content-Type-Options: nosniff
              Date: Thu, 28 Dec 2023 05:10:57 GMT
              Connection: close
              Content-Length: 25457
              2023-12-28 05:10:58 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
              Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
              2023-12-28 05:10:58 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
              Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              Target ID:0
              Start time:06:10:00
              Start date:28/12/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:06:10:01
              Start date:28/12/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2004,i,1623341756167552409,2863486379579178111,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:06:10:03
              Start date:28/12/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://connectivitycheck.gstatic.com/generate_204
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly