Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://bhsd-hqqak.ondigitalocean.app

Overview

General Information

Sample URL:http://bhsd-hqqak.ondigitalocean.app
Analysis ID:1391077
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 2640 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3196 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2004,i,3388246705185068811,9127368990878862355,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6552 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhsd-hqqak.ondigitalocean.app MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://bhsd-hqqak.ondigitalocean.appAvira URL Cloud: detection malicious, Label: malware
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal48.win@19/0@16/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2004,i,3388246705185068811,9127368990878862355,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhsd-hqqak.ondigitalocean.app
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2004,i,3388246705185068811,9127368990878862355,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bhsd-hqqak.ondigitalocean.app100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
173.194.77.101
truefalse
    high
    accounts.google.com
    64.233.185.84
    truefalse
      high
      www.google.com
      172.217.215.147
      truefalse
        high
        clients.l.google.com
        173.194.219.100
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            bhsd-hqqak.ondigitalocean.app
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  172.217.215.147
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  64.233.185.84
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  173.194.219.100
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  Joe Sandbox version:40.0.0 Tourmaline
                  Analysis ID:1391077
                  Start date and time:2024-02-12 20:35:53 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 1m 55s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://bhsd-hqqak.ondigitalocean.app
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@19/0@16/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • URL browsing timeout or error
                  • URL not reachable
                  • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 172.253.124.94, 34.104.35.123, 23.63.206.91, 20.114.59.183
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, e16604.g.akamaiedge.net, sls.update.microsoft.com, clientservices.googleapis.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://bhsd-hqqak.ondigitalocean.app
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 12, 2024 20:36:38.574424982 CET49675443192.168.2.4173.222.162.32
                  Feb 12, 2024 20:36:46.900460958 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:46.900552988 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:46.900633097 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:46.906258106 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:46.906287909 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:46.906666994 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:46.906752110 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:46.906836033 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:46.907144070 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:46.907172918 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.171541929 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.171758890 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.171772957 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.172272921 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.172333002 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.173715115 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.173759937 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.174635887 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.174900055 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.174974918 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.175065041 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.175096989 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.175297022 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.175303936 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.176579952 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.176656008 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.177438021 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.177546978 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.177721977 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.177738905 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.276473999 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.276576996 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.378206968 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.378607035 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.378707886 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.378902912 CET49729443192.168.2.4173.194.219.100
                  Feb 12, 2024 20:36:47.378930092 CET44349729173.194.219.100192.168.2.4
                  Feb 12, 2024 20:36:47.412355900 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.412841082 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:47.412914038 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.413402081 CET49730443192.168.2.464.233.185.84
                  Feb 12, 2024 20:36:47.413423061 CET4434973064.233.185.84192.168.2.4
                  Feb 12, 2024 20:36:48.183016062 CET49675443192.168.2.4173.222.162.32
                  Feb 12, 2024 20:36:50.900023937 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:50.900058985 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:50.900125980 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:50.900739908 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:50.900760889 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.125706911 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.126260042 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:51.126280069 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.127716064 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.127818108 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:51.129965067 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:51.130070925 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.182740927 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:36:51.182756901 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:36:51.229614019 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:37:01.110657930 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:37:01.110861063 CET44349737172.217.215.147192.168.2.4
                  Feb 12, 2024 20:37:01.110929012 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:37:03.019762039 CET49737443192.168.2.4172.217.215.147
                  Feb 12, 2024 20:37:03.019828081 CET44349737172.217.215.147192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 12, 2024 20:36:46.780124903 CET5926853192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:46.780867100 CET5799053192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:46.782351971 CET4947153192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:46.782588959 CET5736153192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:46.898040056 CET53592681.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:46.898624897 CET53579901.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:46.899174929 CET53619931.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:46.899719954 CET53494711.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:46.900085926 CET53573611.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:47.544785976 CET53584421.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:48.600652933 CET5549153192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:48.600990057 CET5913053192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:48.721925974 CET53591301.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:48.721987009 CET53554911.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:48.723042965 CET6304453192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:48.844536066 CET53630441.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:48.884124041 CET5528253192.168.2.48.8.8.8
                  Feb 12, 2024 20:36:48.884676933 CET6285053192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:48.988168001 CET53552828.8.8.8192.168.2.4
                  Feb 12, 2024 20:36:49.002211094 CET53628501.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:49.933480978 CET5946553192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:49.934057951 CET5501653192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:50.055066109 CET53550161.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:50.055757999 CET53594651.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:50.777051926 CET6490453192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:50.778285980 CET5812153192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:50.894961119 CET53649041.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:50.895756006 CET53581211.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:55.070789099 CET5896853192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:55.074134111 CET6238653192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:55.192545891 CET53589681.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:55.194142103 CET53623861.1.1.1192.168.2.4
                  Feb 12, 2024 20:36:55.228081942 CET6548453192.168.2.41.1.1.1
                  Feb 12, 2024 20:36:55.349704981 CET53654841.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 12, 2024 20:36:46.780124903 CET192.168.2.41.1.1.10x9b81Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.780867100 CET192.168.2.41.1.1.10x3067Standard query (0)clients2.google.com65IN (0x0001)false
                  Feb 12, 2024 20:36:46.782351971 CET192.168.2.41.1.1.10x382aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.782588959 CET192.168.2.41.1.1.10xb7f4Standard query (0)accounts.google.com65IN (0x0001)false
                  Feb 12, 2024 20:36:48.600652933 CET192.168.2.41.1.1.10xe975Standard query (0)bhsd-hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.600990057 CET192.168.2.41.1.1.10xf19fStandard query (0)bhsd-hqqak.ondigitalocean.app65IN (0x0001)false
                  Feb 12, 2024 20:36:48.723042965 CET192.168.2.41.1.1.10xc74fStandard query (0)bhsd-hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.884124041 CET192.168.2.48.8.8.80xf288Standard query (0)google.comA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.884676933 CET192.168.2.41.1.1.10x457bStandard query (0)google.comA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.933480978 CET192.168.2.41.1.1.10xc7e0Standard query (0)bhsd-hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.934057951 CET192.168.2.41.1.1.10x25bStandard query (0)bhsd-hqqak.ondigitalocean.app65IN (0x0001)false
                  Feb 12, 2024 20:36:50.777051926 CET192.168.2.41.1.1.10xbd09Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.778285980 CET192.168.2.41.1.1.10x6e8aStandard query (0)www.google.com65IN (0x0001)false
                  Feb 12, 2024 20:36:55.070789099 CET192.168.2.41.1.1.10xc1bfStandard query (0)bhsd-hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:55.074134111 CET192.168.2.41.1.1.10x98e3Standard query (0)bhsd-hqqak.ondigitalocean.app65IN (0x0001)false
                  Feb 12, 2024 20:36:55.228081942 CET192.168.2.41.1.1.10x9f30Standard query (0)bhsd-hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.100A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.139A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.113A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.102A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.138A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898040056 CET1.1.1.1192.168.2.40x9b81No error (0)clients.l.google.com173.194.219.101A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:46.898624897 CET1.1.1.1192.168.2.40x3067No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 12, 2024 20:36:46.899719954 CET1.1.1.1192.168.2.40x382aNo error (0)accounts.google.com64.233.185.84A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.721925974 CET1.1.1.1192.168.2.40xf19fName error (3)bhsd-hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                  Feb 12, 2024 20:36:48.721987009 CET1.1.1.1192.168.2.40xe975Name error (3)bhsd-hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.844536066 CET1.1.1.1192.168.2.40xc74fName error (3)bhsd-hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.101A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.113A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.139A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.102A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.138A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:48.988168001 CET8.8.8.8192.168.2.40xf288No error (0)google.com173.194.77.100A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.138A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.100A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.139A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.102A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.113A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:49.002211094 CET1.1.1.1192.168.2.40x457bNo error (0)google.com108.177.122.101A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.055066109 CET1.1.1.1192.168.2.40x25bName error (3)bhsd-hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                  Feb 12, 2024 20:36:50.055757999 CET1.1.1.1192.168.2.40xc7e0Name error (3)bhsd-hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.147A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.103A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.99A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.105A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.104A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.894961119 CET1.1.1.1192.168.2.40xbd09No error (0)www.google.com172.217.215.106A (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:50.895756006 CET1.1.1.1192.168.2.40x6e8aNo error (0)www.google.com65IN (0x0001)false
                  Feb 12, 2024 20:36:55.192545891 CET1.1.1.1192.168.2.40xc1bfName error (3)bhsd-hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                  Feb 12, 2024 20:36:55.194142103 CET1.1.1.1192.168.2.40x98e3Name error (3)bhsd-hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                  Feb 12, 2024 20:36:55.349704981 CET1.1.1.1192.168.2.40x9f30Name error (3)bhsd-hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                  • clients2.google.com
                  • accounts.google.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.449729173.194.219.1004433196C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-02-12 19:36:47 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-117.0.5938.132
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-02-12 19:36:47 UTC732INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-OICgi45YPBDAz7rOVfBqlg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 12 Feb 2024 19:36:47 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 6251
                  X-Daystart: 41807
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2024-02-12 19:36:47 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 35 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 31 38 30 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6251" elapsed_seconds="41807"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2024-02-12 19:36:47 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2024-02-12 19:36:47 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44973064.233.185.844433196C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-02-12 19:36:47 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                  2024-02-12 19:36:47 UTC1OUTData Raw: 20
                  Data Ascii:
                  2024-02-12 19:36:47 UTC1799INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 12 Feb 2024 19:36:47 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-exaDF-t0rgcN9eJFxSw0tQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Cross-Origin-Opener-Policy: same-origin
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                  reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQBiIR6O889WrmMTWHDmwzJGALjXF_I"
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2024-02-12 19:36:47 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2024-02-12 19:36:47 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:20:36:41
                  Start date:12/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:20:36:45
                  Start date:12/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2004,i,3388246705185068811,9127368990878862355,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:20:36:47
                  Start date:12/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhsd-hqqak.ondigitalocean.app
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly