Edit tour

Windows Analysis Report
http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff

Overview

General Information

Sample URL:http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1
Analysis ID:1392282
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5780 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6496 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2248,i,3572864948199786362,8392863427031885256,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 5176 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49727 version: TLS 1.0
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49727 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownTCP traffic detected without corresponding DNS query: 52.159.126.152
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.134Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=UBeNCkZ3L8yXcx8qh4JFUXkwkNC9IrdiRdbjSTjqSiFh8WrRcbKr_rOJbgHY6TA4RT-6ps0bhemfwCPBsLMgPT7-gTcWqHvZvZbafOpkqRy0dLyYG9AjP2vbUBomarnc9pcZVlhHkUeUaWMurD0GGXyW05_B_1IyUNYEELmyqRg
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.159.126.152:443 -> 192.168.2.6:49728 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@18/0@8/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2248,i,3572864948199786362,8392863427031885256,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2248,i,3572864948199786362,8392863427031885256,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1392282 URL: http://edgedl.me.gvt1.com/e... Startdate: 14/02/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.6, 443, 49706, 49712 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 clients.l.google.com 142.251.15.101, 443, 49713 GOOGLEUS United States 10->17 19 accounts.google.com 64.233.176.84, 443, 49712 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.253.126.139
truefalse
    high
    accounts.google.com
    64.233.176.84
    truefalse
      high
      www.google.com
      64.233.185.103
      truefalse
        high
        clients.l.google.com
        142.251.15.101
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.251.15.101
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  64.233.176.84
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  64.233.185.103
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.6
                  Joe Sandbox version:40.0.0 Tourmaline
                  Analysis ID:1392282
                  Start date and time:2024-02-14 16:29:42 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 2m 8s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:7
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:UNKNOWN
                  Classification:unknown0.win@18/0@8/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • URL browsing timeout or error
                  • URL not reachable
                  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 64.233.177.94, 34.104.35.123, 23.221.242.90, 13.85.23.86, 192.229.211.108, 72.21.81.240, 20.3.187.198, 20.166.126.56
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 83
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 14, 2024 16:30:31.780112028 CET49674443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:31.781912088 CET49673443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:32.123913050 CET49672443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:37.089224100 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.089246035 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.089366913 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.089930058 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.090018034 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.090076923 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.092155933 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.092171907 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.092327118 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.092385054 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.311476946 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.312380075 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.312396049 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.313637972 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.313893080 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.316551924 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.316551924 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.316564083 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.316642046 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.316756010 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.316958904 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.316975117 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.317755938 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.317816019 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.318660021 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.318727016 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.319683075 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.319766998 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.319925070 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.319932938 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.497685909 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.497688055 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.497697115 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.533551931 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.533586025 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.533662081 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.535073042 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.535087109 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.535100937 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.535231113 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.535304070 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.536510944 CET49713443192.168.2.6142.251.15.101
                  Feb 14, 2024 16:30:37.536519051 CET44349713142.251.15.101192.168.2.6
                  Feb 14, 2024 16:30:37.553590059 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.553699017 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.553706884 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.553987026 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.554053068 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.555088043 CET49712443192.168.2.664.233.176.84
                  Feb 14, 2024 16:30:37.555099010 CET4434971264.233.176.84192.168.2.6
                  Feb 14, 2024 16:30:37.912488937 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.912568092 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.916582108 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.916591883 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.917040110 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.918663979 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.918747902 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.918756962 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:37.919014931 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:37.965897083 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:38.038454056 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:38.038645983 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:38.038706064 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:38.038822889 CET49716443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:38.038840055 CET4434971652.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:39.414000988 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.414083004 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.414155960 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.414444923 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.414459944 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.631166935 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.631458998 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.631495953 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.632585049 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.632654905 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.638052940 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.638130903 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.686069965 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:39.686089039 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:39.731851101 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:41.387670040 CET49673443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:41.387671947 CET49674443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:41.730942011 CET49672443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:43.241305113 CET44349706173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:43.241447926 CET49706443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:44.786014080 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:44.786046982 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:44.786144972 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:44.788489103 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:44.788503885 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.156864882 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.157001972 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.159513950 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.159539938 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.159775019 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.161515951 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.161653042 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.161663055 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.161685944 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.201905966 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.286895037 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.286994934 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:45.287122965 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.287902117 CET49722443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:45.287931919 CET4434972252.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:49.642879963 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:49.642961979 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:49.643012047 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:51.246068954 CET49718443192.168.2.664.233.185.103
                  Feb 14, 2024 16:30:51.246107101 CET4434971864.233.185.103192.168.2.6
                  Feb 14, 2024 16:30:54.658862114 CET49706443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:54.658957005 CET49706443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:54.659415007 CET49727443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:54.659440041 CET44349727173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:54.659502983 CET49727443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:54.660823107 CET49727443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:54.660831928 CET44349727173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:54.808903933 CET44349706173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:54.808924913 CET44349706173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:54.971518040 CET44349727173.222.162.64192.168.2.6
                  Feb 14, 2024 16:30:54.971607924 CET49727443192.168.2.6173.222.162.64
                  Feb 14, 2024 16:30:55.539093018 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.539140940 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.539222956 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.540164948 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.540179014 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.916760921 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.916834116 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.921464920 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.921473980 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.921804905 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.924105883 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.924200058 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.924204111 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:55.924369097 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:55.965899944 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:56.044018984 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:56.044234037 CET4434972852.159.126.152192.168.2.6
                  Feb 14, 2024 16:30:56.044291019 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:56.044524908 CET49728443192.168.2.652.159.126.152
                  Feb 14, 2024 16:30:56.044538975 CET4434972852.159.126.152192.168.2.6
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 14, 2024 16:30:36.483079910 CET53602481.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:36.548090935 CET5222053192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:36.548683882 CET5681353192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:36.549706936 CET5467653192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:36.550116062 CET5664253192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:36.665637016 CET53522201.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:36.666771889 CET53568131.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:36.667146921 CET53546761.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:36.667515993 CET53566421.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:37.739156961 CET53603951.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:39.294859886 CET5821253192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:39.295046091 CET5970353192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:39.412410975 CET53582121.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:39.412514925 CET53597031.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:52.826756954 CET5509553192.168.2.68.8.8.8
                  Feb 14, 2024 16:30:52.827102900 CET5360753192.168.2.61.1.1.1
                  Feb 14, 2024 16:30:52.933695078 CET53550958.8.8.8192.168.2.6
                  Feb 14, 2024 16:30:52.944535971 CET53536071.1.1.1192.168.2.6
                  Feb 14, 2024 16:30:53.954478025 CET53648751.1.1.1192.168.2.6
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 14, 2024 16:30:36.548090935 CET192.168.2.61.1.1.10xbecbStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.548683882 CET192.168.2.61.1.1.10x5afcStandard query (0)clients2.google.com65IN (0x0001)false
                  Feb 14, 2024 16:30:36.549706936 CET192.168.2.61.1.1.10xe919Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.550116062 CET192.168.2.61.1.1.10xda31Standard query (0)accounts.google.com65IN (0x0001)false
                  Feb 14, 2024 16:30:39.294859886 CET192.168.2.61.1.1.10xb301Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.295046091 CET192.168.2.61.1.1.10x8881Standard query (0)www.google.com65IN (0x0001)false
                  Feb 14, 2024 16:30:52.826756954 CET192.168.2.68.8.8.80x2366Standard query (0)google.comA (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.827102900 CET192.168.2.61.1.1.10xac5dStandard query (0)google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.101A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.102A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.100A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.113A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.138A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.665637016 CET1.1.1.1192.168.2.60xbecbNo error (0)clients.l.google.com142.251.15.139A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:36.666771889 CET1.1.1.1192.168.2.60x5afcNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 14, 2024 16:30:36.667146921 CET1.1.1.1192.168.2.60xe919No error (0)accounts.google.com64.233.176.84A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.103A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.105A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.104A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.106A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.147A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412410975 CET1.1.1.1192.168.2.60xb301No error (0)www.google.com64.233.185.99A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:39.412514925 CET1.1.1.1192.168.2.60x8881No error (0)www.google.com65IN (0x0001)false
                  Feb 14, 2024 16:30:52.593365908 CET1.1.1.1192.168.2.60x73b9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Feb 14, 2024 16:30:52.593365908 CET1.1.1.1192.168.2.60x73b9No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.139A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.113A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.100A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.101A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.138A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.933695078 CET8.8.8.8192.168.2.60x2366No error (0)google.com172.253.126.102A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.113A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.139A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.101A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.100A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.138A (IP address)IN (0x0001)false
                  Feb 14, 2024 16:30:52.944535971 CET1.1.1.1192.168.2.60xac5dNo error (0)google.com142.250.105.102A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.64971264.233.176.844436496C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-02-14 15:30:37 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: NID=511=UBeNCkZ3L8yXcx8qh4JFUXkwkNC9IrdiRdbjSTjqSiFh8WrRcbKr_rOJbgHY6TA4RT-6ps0bhemfwCPBsLMgPT7-gTcWqHvZvZbafOpkqRy0dLyYG9AjP2vbUBomarnc9pcZVlhHkUeUaWMurD0GGXyW05_B_1IyUNYEELmyqRg
                  2024-02-14 15:30:37 UTC1OUTData Raw: 20
                  Data Ascii:
                  2024-02-14 15:30:37 UTC1799INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Wed, 14 Feb 2024 15:30:37 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-Nt7d9jNNR-P4Hf-iijkaXQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Cross-Origin-Opener-Policy: same-origin
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmJw05BiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQBiIR6OuTs3r2MTOPF36WtGALXQF-0"
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2024-02-14 15:30:37 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2024-02-14 15:30:37 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.649713142.251.15.1014436496C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-02-14 15:30:37 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-117.0.5938.134
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-02-14 15:30:37 UTC732INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-RuZwY2naDnaz4ngsH54jLg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Wed, 14 Feb 2024 15:30:37 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 6253
                  X-Daystart: 27037
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2024-02-14 15:30:37 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 35 33 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 37 30 33 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6253" elapsed_seconds="27037"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2024-02-14 15:30:37 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2024-02-14 15:30:37 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination Port
                  2192.168.2.64971652.159.126.152443
                  TimestampBytes transferredDirectionData
                  2024-02-14 15:30:37 UTC70OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 34 0d 0a 4d 53 2d 43 56 3a 20 2b 64 6e 4b 76 2b 6e 56 61 30 2b 55 4a 33 31 67 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 30 39 61 30 33 32 64 62 61 62 33 37 37 38 0d 0a 0d 0a
                  Data Ascii: CNT 1 CON 304MS-CV: +dnKv+nVa0+UJ31g.1Context: 809a032dbab3778
                  2024-02-14 15:30:37 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                  2024-02-14 15:30:37 UTC1063OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 34 30 0d 0a 4d 53 2d 43 56 3a 20 2b 64 6e 4b 76 2b 6e 56 61 30 2b 55 4a 33 31 67 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 30 39 61 30 33 32 64 62 61 62 33 37 37 38 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 6f 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 72 30 4e 6d 6d 66 37 38 70 32 39 4d 48 72 4b 73 61 78 56 4d 79 65 68 30 70 6c 7a 2b 35 77 59 75 4e 34 68 32 46 35 72 57 57 4c 43 5a 68 66 4c 4b 4d 4e 43 45 62 70 30 65 61 62 61 41 38 6f 36 34 63 4c 59 67 62 76 4b 54 77 45 2b 4b 61 57 71 73 46 31 38 36 64 2b 48 73 6d 59 54 36 35 6e 59 63 30 32 79 71 30 33 38 56 30 31 7a 42 55
                  Data Ascii: ATH 2 CON\DEVICE 1040MS-CV: +dnKv+nVa0+UJ31g.2Context: 809a032dbab3778<device><compact-ticket>t=EwCoAupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATr0Nmmf78p29MHrKsaxVMyeh0plz+5wYuN4h2F5rWWLCZhfLKMNCEbp0eabaA8o64cLYgbvKTwE+KaWqsF186d+HsmYT65nYc02yq038V01zBU
                  2024-02-14 15:30:37 UTC217OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 36 0d 0a 4d 53 2d 43 56 3a 20 2b 64 6e 4b 76 2b 6e 56 61 30 2b 55 4a 33 31 67 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 30 39 61 30 33 32 64 62 61 62 33 37 37 38 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                  Data Ascii: BND 3 CON\WNS 0 196MS-CV: +dnKv+nVa0+UJ31g.3Context: 809a032dbab3778<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                  2024-02-14 15:30:38 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                  Data Ascii: 202 1 CON 58
                  2024-02-14 15:30:38 UTC58INData Raw: 4d 53 2d 43 56 3a 20 51 34 79 4a 7a 51 62 38 7a 45 53 54 59 35 45 48 73 66 54 56 68 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                  Data Ascii: MS-CV: Q4yJzQb8zESTY5EHsfTVhg.0Payload parsing failed.


                  Session IDSource IPSource PortDestination IPDestination Port
                  3192.168.2.64972252.159.126.152443
                  TimestampBytes transferredDirectionData
                  2024-02-14 15:30:45 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 74 34 45 39 36 54 4a 49 35 45 57 58 39 78 43 41 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 32 31 37 30 37 39 35 34 32 61 34 32 30 65 66 0d 0a 0d 0a
                  Data Ascii: CNT 1 CON 305MS-CV: t4E96TJI5EWX9xCA.1Context: 2217079542a420ef
                  2024-02-14 15:30:45 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                  2024-02-14 15:30:45 UTC1064OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 34 31 0d 0a 4d 53 2d 43 56 3a 20 74 34 45 39 36 54 4a 49 35 45 57 58 39 78 43 41 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 32 31 37 30 37 39 35 34 32 61 34 32 30 65 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 6f 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 72 30 4e 6d 6d 66 37 38 70 32 39 4d 48 72 4b 73 61 78 56 4d 79 65 68 30 70 6c 7a 2b 35 77 59 75 4e 34 68 32 46 35 72 57 57 4c 43 5a 68 66 4c 4b 4d 4e 43 45 62 70 30 65 61 62 61 41 38 6f 36 34 63 4c 59 67 62 76 4b 54 77 45 2b 4b 61 57 71 73 46 31 38 36 64 2b 48 73 6d 59 54 36 35 6e 59 63 30 32 79 71 30 33 38 56 30 31 7a 42
                  Data Ascii: ATH 2 CON\DEVICE 1041MS-CV: t4E96TJI5EWX9xCA.2Context: 2217079542a420ef<device><compact-ticket>t=EwCoAupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATr0Nmmf78p29MHrKsaxVMyeh0plz+5wYuN4h2F5rWWLCZhfLKMNCEbp0eabaA8o64cLYgbvKTwE+KaWqsF186d+HsmYT65nYc02yq038V01zB
                  2024-02-14 15:30:45 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 74 34 45 39 36 54 4a 49 35 45 57 58 39 78 43 41 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 32 31 37 30 37 39 35 34 32 61 34 32 30 65 66 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: t4E96TJI5EWX9xCA.3Context: 2217079542a420ef<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                  2024-02-14 15:30:45 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                  Data Ascii: 202 1 CON 58
                  2024-02-14 15:30:45 UTC58INData Raw: 4d 53 2d 43 56 3a 20 44 36 57 31 67 74 6a 39 59 55 36 75 5a 65 36 56 32 7a 39 50 30 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                  Data Ascii: MS-CV: D6W1gtj9YU6uZe6V2z9P0Q.0Payload parsing failed.


                  Session IDSource IPSource PortDestination IPDestination Port
                  4192.168.2.64972852.159.126.152443
                  TimestampBytes transferredDirectionData
                  2024-02-14 15:30:55 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4c 2b 30 41 73 31 53 31 52 55 6d 31 6a 6d 57 39 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 64 36 38 62 64 36 35 33 37 31 39 65 32 38 0d 0a 0d 0a
                  Data Ascii: CNT 1 CON 305MS-CV: L+0As1S1RUm1jmW9.1Context: 96d68bd653719e28
                  2024-02-14 15:30:55 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                  2024-02-14 15:30:55 UTC1064OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 34 31 0d 0a 4d 53 2d 43 56 3a 20 4c 2b 30 41 73 31 53 31 52 55 6d 31 6a 6d 57 39 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 64 36 38 62 64 36 35 33 37 31 39 65 32 38 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 6f 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 72 30 4e 6d 6d 66 37 38 70 32 39 4d 48 72 4b 73 61 78 56 4d 79 65 68 30 70 6c 7a 2b 35 77 59 75 4e 34 68 32 46 35 72 57 57 4c 43 5a 68 66 4c 4b 4d 4e 43 45 62 70 30 65 61 62 61 41 38 6f 36 34 63 4c 59 67 62 76 4b 54 77 45 2b 4b 61 57 71 73 46 31 38 36 64 2b 48 73 6d 59 54 36 35 6e 59 63 30 32 79 71 30 33 38 56 30 31 7a 42
                  Data Ascii: ATH 2 CON\DEVICE 1041MS-CV: L+0As1S1RUm1jmW9.2Context: 96d68bd653719e28<device><compact-ticket>t=EwCoAupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATr0Nmmf78p29MHrKsaxVMyeh0plz+5wYuN4h2F5rWWLCZhfLKMNCEbp0eabaA8o64cLYgbvKTwE+KaWqsF186d+HsmYT65nYc02yq038V01zB
                  2024-02-14 15:30:55 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 4c 2b 30 41 73 31 53 31 52 55 6d 31 6a 6d 57 39 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 64 36 38 62 64 36 35 33 37 31 39 65 32 38 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: L+0As1S1RUm1jmW9.3Context: 96d68bd653719e28<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                  2024-02-14 15:30:56 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                  Data Ascii: 202 1 CON 58
                  2024-02-14 15:30:56 UTC58INData Raw: 4d 53 2d 43 56 3a 20 55 71 61 4d 77 47 77 4d 7a 55 61 74 74 50 4e 38 44 54 51 49 6a 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                  Data Ascii: MS-CV: UqaMwGwMzUattPN8DTQIjA.0Payload parsing failed.


                  01020s020406080100

                  Click to jump to process

                  01020s0.0020406080100MB

                  Click to jump to process

                  Target ID:0
                  Start time:16:30:32
                  Start date:14/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:16:30:33
                  Start date:14/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2248,i,3572864948199786362,8392863427031885256,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:16:30:38
                  Start date:14/02/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/hfnkpimlhhgieaddgfemjhofmfblmnib/1.8a5afad7477cb081d06ca5f3823914ff2de18b4d454f71f9353958e1fb3556d7/1.d42b2c689c7b9a1ea98e044f8e8c56ef174d5459b7976152f1a9147200ee34c0/4b21c27a1d9f64f414726c570f344d0e937cdf70a239e644c7f12ba3d0d19ff2.puff
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly