Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://f005.backblazeb2.com/file/yahoos66/glogin.html

Overview

General Information

Sample URL:https://f005.backblazeb2.com/file/yahoos66/glogin.html
Analysis ID:1369054
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Creates files inside the system directory

Classification

  • System is w10x64
  • chrome.exe (PID: 5432 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5076 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=2012,i,2469558705971810017,14450881415182030102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6536 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f005.backblazeb2.com/file/yahoos66/glogin.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://f005.backblazeb2.com/file/yahoos66/glogin.htmlAvira URL Cloud: detection malicious, Label: phishing
Source: https://f005.backblazeb2.com/file/yahoos66/glogin.htmlSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: https://f005.backblazeb2.com/file/yahoos66/glogin.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 173.223.108.114:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.223.108.114:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 173.223.108.114
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /file/yahoos66/glogin.html HTTP/1.1Host: f005.backblazeb2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: f005.backblazeb2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://f005.backblazeb2.com/file/yahoos66/glogin.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 173.223.108.114:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.223.108.114:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_5432_1207789033Jump to behavior
Source: classification engineClassification label: mal48.win@16/0@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=2012,i,2469558705971810017,14450881415182030102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f005.backblazeb2.com/file/yahoos66/glogin.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=2012,i,2469558705971810017,14450881415182030102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://f005.backblazeb2.com/file/yahoos66/glogin.html100%Avira URL Cloudphishing
https://f005.backblazeb2.com/file/yahoos66/glogin.html100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://f005.backblazeb2.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.116.84
truefalse
    high
    f005.backblazeb2.com
    149.137.136.16
    truefalse
      unknown
      www.google.com
      142.250.113.106
      truefalse
        high
        clients.l.google.com
        142.250.115.113
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            windowsupdatebg.s.llnwi.net
            208.111.176.192
            truefalse
              unknown
              clients2.google.com
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://f005.backblazeb2.com/file/yahoos66/glogin.htmltrue
                  unknown
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    https://f005.backblazeb2.com/favicon.icofalse
                    • Avira URL Cloud: safe
                    unknown
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      142.250.113.106
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      142.250.115.113
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      142.251.116.84
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      149.137.136.16
                      f005.backblazeb2.comUnited States
                      30103ZOOM-VIDEO-COMM-ASUSfalse
                      IP
                      192.168.2.4
                      Joe Sandbox version:38.0.0 Ammolite
                      Analysis ID:1369054
                      Start date and time:2024-01-03 00:15:13 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 2m 50s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:https://f005.backblazeb2.com/file/yahoos66/glogin.html
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:7
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal48.win@16/0@8/6
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 142.251.116.94, 34.104.35.123, 40.127.169.103, 208.111.176.192, 192.229.211.108, 13.95.31.18, 20.3.187.198
                      • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                      • Not all processes where analyzed, report is missing behavior information
                      • VT rate limit hit for: https://f005.backblazeb2.com/file/yahoos66/glogin.html
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      No created / dropped files found
                      No static file info
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 3, 2024 00:15:56.038455963 CET49678443192.168.2.4104.46.162.224
                      Jan 3, 2024 00:15:57.335397959 CET49675443192.168.2.4173.222.162.32
                      Jan 3, 2024 00:16:04.538268089 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.538320065 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.538433075 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.538983107 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.538990021 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.539037943 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.543041945 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.543052912 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.543212891 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.543224096 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.828548908 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.829161882 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.829183102 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.829899073 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.830166101 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.830687046 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.830972910 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.830982924 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.830988884 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.831017017 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.832182884 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.832230091 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.833098888 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.833164930 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.833451986 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.833522081 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.833600044 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.833607912 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:04.835078001 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:04.835083961 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:04.930324078 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:04.930387974 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:05.089663029 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:05.089859009 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:05.090002060 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:05.090117931 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:05.090224028 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:05.091238022 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:05.091238022 CET49730443192.168.2.4142.250.115.113
                      Jan 3, 2024 00:16:05.091264009 CET44349730142.250.115.113192.168.2.4
                      Jan 3, 2024 00:16:05.091814041 CET49729443192.168.2.4142.251.116.84
                      Jan 3, 2024 00:16:05.091820002 CET44349729142.251.116.84192.168.2.4
                      Jan 3, 2024 00:16:05.965162039 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.965200901 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:05.965277910 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.965908051 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.965950012 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:05.966002941 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.966197014 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.966211081 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:05.966434956 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:05.966454029 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.297584057 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.297831059 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.297859907 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.298815012 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.298883915 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.299896955 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.299958944 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.300116062 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.300123930 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.304429054 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.304615974 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.304630041 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.306399107 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.306459904 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.307284117 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.307404995 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.352652073 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.352652073 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.352660894 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.399395943 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.609257936 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.609333038 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.609388113 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.610312939 CET49735443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.610328913 CET44349735149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.652101994 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.692743063 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.811780930 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.811834097 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.811878920 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.812350035 CET49734443192.168.2.4149.137.136.16
                      Jan 3, 2024 00:16:06.812369108 CET44349734149.137.136.16192.168.2.4
                      Jan 3, 2024 00:16:06.945077896 CET49675443192.168.2.4173.222.162.32
                      Jan 3, 2024 00:16:07.925894976 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:07.925937891 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:07.926002026 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:07.927732944 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:07.927748919 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.181571960 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.182035923 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:08.182049036 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.182915926 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.182971954 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:08.186466932 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:08.186522007 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.226299047 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:08.226309061 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:08.273169041 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:09.465696096 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.465725899 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.465806961 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.469079971 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.469091892 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.722203970 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.722362995 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.725109100 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.725115061 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.725393057 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.772078991 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.836874008 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.884727001 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.960968018 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.961010933 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.964385986 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.977555037 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.977555037 CET49739443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:09.977566004 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:09.977574110 CET44349739173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.045407057 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.045433998 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.045521021 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.046339989 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.046351910 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.302135944 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.302198887 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.303622961 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.303628922 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.303822041 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.305330038 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.352741957 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.543596029 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.543740988 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.543797970 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.544913054 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.544924974 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:10.544935942 CET49740443192.168.2.4173.223.108.114
                      Jan 3, 2024 00:16:10.544941902 CET44349740173.223.108.114192.168.2.4
                      Jan 3, 2024 00:16:18.184220076 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:18.184278965 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:16:18.184406996 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:18.896047115 CET49738443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:16:18.896071911 CET44349738142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:07.846563101 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:07.846589088 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:07.846693993 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:07.847858906 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:07.847868919 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:08.100671053 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:08.101032972 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:08.101044893 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:08.101330042 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:08.102936029 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:08.102994919 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:08.147583008 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:14.991451979 CET4972380192.168.2.472.21.81.240
                      Jan 3, 2024 00:17:14.991571903 CET4972480192.168.2.472.21.81.240
                      Jan 3, 2024 00:17:15.112150908 CET804972472.21.81.240192.168.2.4
                      Jan 3, 2024 00:17:15.112190962 CET804972372.21.81.240192.168.2.4
                      Jan 3, 2024 00:17:15.112318993 CET4972380192.168.2.472.21.81.240
                      Jan 3, 2024 00:17:15.112395048 CET4972480192.168.2.472.21.81.240
                      Jan 3, 2024 00:17:18.127991915 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:18.128051043 CET44349749142.250.113.106192.168.2.4
                      Jan 3, 2024 00:17:18.128099918 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:19.140160084 CET49749443192.168.2.4142.250.113.106
                      Jan 3, 2024 00:17:19.140180111 CET44349749142.250.113.106192.168.2.4
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 3, 2024 00:16:04.301476002 CET6082453192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:04.305006027 CET53616071.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:04.309448004 CET5387753192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:04.311645985 CET5178353192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:04.312212944 CET6106653192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:04.424963951 CET53608241.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:04.433836937 CET53538771.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:04.435743093 CET53517831.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:04.436089993 CET53610661.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:05.262746096 CET53524231.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:05.839560032 CET5773253192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:05.840270042 CET6037853192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:05.964449883 CET53603781.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:05.964471102 CET53577321.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:07.794236898 CET6233353192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:07.794572115 CET6451953192.168.2.41.1.1.1
                      Jan 3, 2024 00:16:07.921705008 CET53645191.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:07.922810078 CET53623331.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:22.426980019 CET53636091.1.1.1192.168.2.4
                      Jan 3, 2024 00:16:26.560215950 CET138138192.168.2.4192.168.2.255
                      Jan 3, 2024 00:16:41.461690903 CET53516961.1.1.1192.168.2.4
                      Jan 3, 2024 00:17:03.900154114 CET53516351.1.1.1192.168.2.4
                      Jan 3, 2024 00:17:03.955634117 CET53618531.1.1.1192.168.2.4
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Jan 3, 2024 00:16:04.301476002 CET192.168.2.41.1.1.10xc5afStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.309448004 CET192.168.2.41.1.1.10xb3ebStandard query (0)clients2.google.com65IN (0x0001)false
                      Jan 3, 2024 00:16:04.311645985 CET192.168.2.41.1.1.10x2ac2Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.312212944 CET192.168.2.41.1.1.10x97bcStandard query (0)accounts.google.com65IN (0x0001)false
                      Jan 3, 2024 00:16:05.839560032 CET192.168.2.41.1.1.10xdfedStandard query (0)f005.backblazeb2.comA (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:05.840270042 CET192.168.2.41.1.1.10x93baStandard query (0)f005.backblazeb2.com65IN (0x0001)false
                      Jan 3, 2024 00:16:07.794236898 CET192.168.2.41.1.1.10x66a4Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.794572115 CET192.168.2.41.1.1.10xdd53Standard query (0)www.google.com65IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.113A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.139A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.101A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.100A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.138A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.424963951 CET1.1.1.1192.168.2.40xc5afNo error (0)clients.l.google.com142.250.115.102A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:04.433836937 CET1.1.1.1192.168.2.40xb3ebNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:16:04.435743093 CET1.1.1.1192.168.2.40x2ac2No error (0)accounts.google.com142.251.116.84A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:05.964471102 CET1.1.1.1192.168.2.40xdfedNo error (0)f005.backblazeb2.com149.137.136.16A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.921705008 CET1.1.1.1192.168.2.40xdd53No error (0)www.google.com65IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.106A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.99A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.103A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.104A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.147A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:07.922810078 CET1.1.1.1192.168.2.40x66a4No error (0)www.google.com142.250.113.105A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:20.609956980 CET1.1.1.1192.168.2.40x749fNo error (0)windowsupdatebg.s.llnwi.net208.111.176.192A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:20.609956980 CET1.1.1.1192.168.2.40x749fNo error (0)windowsupdatebg.s.llnwi.net208.111.176.128A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:21.044065952 CET1.1.1.1192.168.2.40x62adNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:16:21.044065952 CET1.1.1.1192.168.2.40x62adNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:34.239945889 CET1.1.1.1192.168.2.40xaf06No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:16:34.239945889 CET1.1.1.1192.168.2.40xaf06No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:16:56.535414934 CET1.1.1.1192.168.2.40x8914No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:16:56.535414934 CET1.1.1.1192.168.2.40x8914No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                      Jan 3, 2024 00:17:16.896123886 CET1.1.1.1192.168.2.40xf05cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                      Jan 3, 2024 00:17:16.896123886 CET1.1.1.1192.168.2.40xf05cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                      • clients2.google.com
                      • accounts.google.com
                      • f005.backblazeb2.com
                      • https:
                      • fs.microsoft.com
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.449730142.250.115.1134435076C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:04 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                      Host: clients2.google.com
                      Connection: keep-alive
                      X-Goog-Update-Interactivity: fg
                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                      X-Goog-Update-Updater: chromecrx-117.0.5938.132
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-01-02 23:16:05 UTC732INHTTP/1.1 200 OK
                      Content-Security-Policy: script-src 'report-sample' 'nonce-RXoxVqqgenaW2UyiXZx7Gg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Tue, 02 Jan 2024 23:16:05 GMT
                      Content-Type: text/xml; charset=UTF-8
                      X-Daynum: 6210
                      X-Daystart: 54965
                      X-Content-Type-Options: nosniff
                      X-Frame-Options: SAMEORIGIN
                      X-XSS-Protection: 1; mode=block
                      Server: GSE
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2024-01-02 23:16:05 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 31 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 34 39 36 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                      Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6210" elapsed_seconds="54965"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                      2024-01-02 23:16:05 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                      Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                      2024-01-02 23:16:05 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.449729142.251.116.844435076C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:04 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                      Host: accounts.google.com
                      Connection: keep-alive
                      Content-Length: 1
                      Origin: https://www.google.com
                      Content-Type: application/x-www-form-urlencoded
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                      2024-01-02 23:16:04 UTC1OUTData Raw: 20
                      Data Ascii:
                      2024-01-02 23:16:05 UTC1627INHTTP/1.1 200 OK
                      Content-Type: application/json; charset=utf-8
                      Access-Control-Allow-Origin: https://www.google.com
                      Access-Control-Allow-Credentials: true
                      X-Content-Type-Options: nosniff
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Tue, 02 Jan 2024 23:16:05 GMT
                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                      Cross-Origin-Opener-Policy: same-origin
                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                      Content-Security-Policy: script-src 'report-sample' 'nonce-azjted3jtUq4OjW9Rwq5Qw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                      Server: ESF
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2024-01-02 23:16:05 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                      Data Ascii: 11["gaia.l.a.r",[]]
                      2024-01-02 23:16:05 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.449735149.137.136.164435076C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:06 UTC688OUTGET /file/yahoos66/glogin.html HTTP/1.1
                      Host: f005.backblazeb2.com
                      Connection: keep-alive
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-01-02 23:16:06 UTC186INHTTP/1.1 403
                      Cache-Control: max-age=0, no-cache, no-store
                      Content-Type: application/json;charset=utf-8
                      Content-Length: 135
                      Date: Tue, 02 Jan 2024 23:16:05 GMT
                      Connection: close
                      2024-01-02 23:16:06 UTC135INData Raw: 7b 0a 20 20 22 63 6f 64 65 22 3a 20 22 61 63 63 6f 75 6e 74 5f 74 72 6f 75 62 6c 65 22 2c 0a 20 20 22 6d 65 73 73 61 67 65 22 3a 20 22 41 63 63 6f 75 6e 74 20 74 72 6f 75 62 6c 65 2e 20 50 6c 65 61 73 65 20 6c 6f 67 20 69 6e 74 6f 20 79 6f 75 72 20 62 32 20 61 63 63 6f 75 6e 74 20 61 74 20 77 77 77 2e 62 61 63 6b 62 6c 61 7a 65 2e 63 6f 6d 2e 22 2c 0a 20 20 22 73 74 61 74 75 73 22 3a 20 34 30 33 0a 7d
                      Data Ascii: { "code": "account_trouble", "message": "Account trouble. Please log into your b2 account at www.backblaze.com.", "status": 403}


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.449734149.137.136.164435076C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:06 UTC621OUTGET /favicon.ico HTTP/1.1
                      Host: f005.backblazeb2.com
                      Connection: keep-alive
                      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                      sec-ch-ua-mobile: ?0
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                      sec-ch-ua-platform: "Windows"
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: image
                      Referer: https://f005.backblazeb2.com/file/yahoos66/glogin.html
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2024-01-02 23:16:06 UTC185INHTTP/1.1 404
                      Cache-Control: max-age=0, no-cache, no-store
                      Content-Type: application/json;charset=UTF-8
                      Content-Length: 86
                      Date: Tue, 02 Jan 2024 23:16:06 GMT
                      Connection: close
                      2024-01-02 23:16:06 UTC86INData Raw: 7b 0a 20 20 22 63 6f 64 65 22 3a 20 22 6e 6f 74 5f 66 6f 75 6e 64 22 2c 0a 20 20 22 6d 65 73 73 61 67 65 22 3a 20 22 2f 61 70 69 2f 74 6f 70 5f 6c 65 76 65 6c 5f 75 72 6c 5f 6d 61 70 70 69 6e 67 22 2c 0a 20 20 22 73 74 61 74 75 73 22 3a 20 34 30 34 0a 7d 0a
                      Data Ascii: { "code": "not_found", "message": "/api/top_level_url_mapping", "status": 404}


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.449739173.223.108.114443
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:09 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      Accept-Encoding: identity
                      User-Agent: Microsoft BITS/7.8
                      Host: fs.microsoft.com
                      2024-01-02 23:16:09 UTC494INHTTP/1.1 200 OK
                      ApiVersion: Distribute 1.1
                      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                      Content-Type: application/octet-stream
                      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                      Server: ECAcc (chd/073D)
                      X-CID: 11
                      X-Ms-ApiVersion: Distribute 1.2
                      X-Ms-Region: prod-eus-z1
                      Cache-Control: public, max-age=63653
                      Date: Tue, 02 Jan 2024 23:16:09 GMT
                      Connection: close
                      X-CID: 2


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.449740173.223.108.114443
                      TimestampBytes transferredDirectionData
                      2024-01-02 23:16:10 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                      Connection: Keep-Alive
                      Accept: */*
                      Accept-Encoding: identity
                      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                      Range: bytes=0-2147483646
                      User-Agent: Microsoft BITS/7.8
                      Host: fs.microsoft.com
                      2024-01-02 23:16:10 UTC530INHTTP/1.1 200 OK
                      Content-Type: application/octet-stream
                      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                      ApiVersion: Distribute 1.1
                      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                      X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                      Cache-Control: public, max-age=63662
                      Date: Tue, 02 Jan 2024 23:16:10 GMT
                      Content-Length: 55
                      Connection: close
                      X-CID: 2
                      2024-01-02 23:16:10 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:00:15:59
                      Start date:03/01/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:2
                      Start time:00:16:02
                      Start date:03/01/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=2012,i,2469558705971810017,14450881415182030102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:3
                      Start time:00:16:04
                      Start date:03/01/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://f005.backblazeb2.com/file/yahoos66/glogin.html
                      Imagebase:0x7ff76e190000
                      File size:3'242'272 bytes
                      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      No disassembly