Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx

Overview

General Information

Sample URL:http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1r
Analysis ID:1447781
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sample execution stops while process was sleeping (likely an evasion)

Classification

  • System is w10x64
  • chrome.exe (PID: 5304 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4248 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2056,i,8146993895664307503,12275233904855355838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • conhost.exe (PID: 6456 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crxHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crxAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: clients2.googleusercontent.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/plain; charset=utf-8Content-Length: 42Date: Mon, 27 May 2024 00:46:55 GMTServer: UploadServerData Raw: 53 53 4c 20 69 73 20 72 65 71 75 69 72 65 64 20 74 6f 20 70 65 72 66 6f 72 6d 20 74 68 69 73 20 6f 70 65 72 61 74 69 6f 6e 2e Data Ascii: SSL is required to perform this operation.
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCross-Origin-Resource-Policy: cross-originContent-Type: text/html; charset=UTF-8X-Content-Type-Options: nosniffDate: Mon, 27 May 2024 00:46:55 GMTServer: sffeContent-Length: 1572X-XSS-Protection: 0Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 34 20 28 4e 6f 74 20 46 6f 75 6e 64 29 21 21 31 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 2a 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 7d 68 74 6d 6c 2c 63 6f 64 65 7b 66 6f 6e 74 3a 31 35 70 78 2f 32 32 70 78 20 61 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 7d 68 74 6d 6c 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 63 6f 6c 6f 72 3a 23 32 32 32 3b 70 61 64 64 69 6e 67 3a 31 35 70 78 7d 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 37 25 20 61 75 74 6f 20 30 3b 6d 61 78 2d 77 69 64 74 68 3a 33 39 30 70 78 3b 6d 69 6e 2d 68 65 69 67 68 74 3a 31 38 30 70 78 3b 70 61 64 64 69 6e 67 3a 33 30 70 78 20 30 20 31 35 70 78 7d 2a 20 3e 20 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 65 72 72 6f 72 73 2f 72 6f 62 6f 74 2e 70 6e 67 29 20 31 30 30 25 20 35 70 78 20 6e 6f 2d 72 65 70 65 61 74 3b 70 61 64 64 69 6e 67 2d 72 69 67 68 74 3a 32 30 35 70 78 7d 70 7b 6d 61 72 67 69 6e 3a 31 31 70 78 20 30 20 32 32 70 78 3b 6f 76 65 72 66 6c 6f 77 3a 68 69 64 64 65 6e 7d 69 6e 73 7b 63 6f 6c 6f 72 3a 23 37 37 37 3b 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 7d 61 20 69 6d 67 7b 62 6f 72 64 65 72 3a 30 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 37 37 32 70 78 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 6e 6f 6e 65 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 6d 61 78 2d 77 69 64 74 68 3a 6e 6f 6e 65 3b 70 61 64 64 69 6e 67 2d 72 69 67 68 74 3a 30 7d 7d 23 6c 6f 67 6f 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 31 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 6e 6f 2d 72 65 70 65 61 74 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 35 70 78 7d 40 6d 65 64 69 61 20 6f 6e 6c 79 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 69 6e 2d 72 65 73 6f 6c 75 74 69 6f 6e 3a 31 39 32 64 70 69 29 7b 23 6c 6f 67 6f 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 6
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@4/4
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:6456:120:WilError_03
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2056,i,8146993895664307503,12275233904855355838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2056,i,8146993895664307503,12275233904855355838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://clients2.googleusercontent.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.184.228
truefalse
    unknown
    googlehosted.l.googleusercontent.com
    142.250.185.129
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        clients2.googleusercontent.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crxfalse
            unknown
            http://clients2.googleusercontent.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.185.129
            googlehosted.l.googleusercontent.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.184.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1447781
            Start date and time:2024-05-27 02:46:01 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 10s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:9
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/4@4/4
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.250.186.174, 173.194.76.84, 34.104.35.123, 93.184.221.240, 52.165.165.26, 192.229.221.95, 13.95.31.18, 52.165.164.15, 216.58.206.67
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, hlb.apr-52dd2-0.edgecastdns.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            InputOutput
            URL: http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0 Model: Perplexity: mixtral-8x7b-instruct
            ```json
            {
              "loginform": false,
              "reasons": [
                "The text 'SSL is required to perform this operation' does not indicate the presence of a login form.",
                "There is no mention of user input fields such as 'username', 'password', or 'submit' in the text."
              ]
            }
            SSL is required to perform this operation. 
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1136)
            Category:downloaded
            Size (bytes):1572
            Entropy (8bit):5.2647442020070505
            Encrypted:false
            SSDEEP:24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xTOS8f:3qD+2+pUAew85zsT9A
            MD5:13FEC0C2FBF5C47C4608CE0C9405E5A7
            SHA1:DAFB6CA27CFD22E88A2D53150C4350FCA3D32A21
            SHA-256:7F25FD0260C4EF8C26A87A5A126634E846BA539C75E5D508103F4D98831654A5
            SHA-512:7B9C5B92CDB7C3CEA0B6B862EBE67F75D92C1F1A8D5AAFE771CA50A724E4AF7F3C1CA280CBC53BF3EA3FB6344C41D1BA06BC032FC9B408C3B30BD301239CD001
            Malicious:false
            Reputation:low
            URL:http://clients2.googleusercontent.com/favicon.ico
            Preview:<!DOCTYPE html>.<html lang=en>. <meta charset=utf-8>. <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">. <title>Error 404 (Not Found)!!1</title>. <style>. *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):42
            Entropy (8bit):3.919119732756684
            Encrypted:false
            SSDEEP:3:PPQKYXWXcNMCOAIL/n:PH6QdCAD
            MD5:18F00553DF0BEF2346134453C797C67F
            SHA1:0484F6D7B478D1FE88E274507CD1565C111DB960
            SHA-256:009862BDE115A3829DF8ACD3587C73B4416C7F35D32DFCC4E2B72906544D7C1A
            SHA-512:CD8144456B2D973861967FFE7BC7720CEF65016DB0E9BA20CFE9145FE9752D90F94A3B92535561F45463282A2A29A89A05A99E69E4D88A1BE6A42FA47921DEC0
            Malicious:false
            Reputation:low
            URL:http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx
            Preview:SSL is required to perform this operation.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            May 27, 2024 02:46:44.246057987 CEST49678443192.168.2.4104.46.162.224
            May 27, 2024 02:46:45.511857033 CEST49675443192.168.2.4173.222.162.32
            May 27, 2024 02:46:54.723781109 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:54.724411964 CEST4973680192.168.2.4142.250.185.129
            May 27, 2024 02:46:54.728914976 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:54.729016066 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:54.729300022 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:54.733772039 CEST8049736142.250.185.129192.168.2.4
            May 27, 2024 02:46:54.733908892 CEST4973680192.168.2.4142.250.185.129
            May 27, 2024 02:46:54.738818884 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:55.357543945 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:55.403398037 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:55.442466021 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:55.454587936 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:55.636373043 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:55.641083002 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:46:55.641175032 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:46:56.805649042 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:56.805732965 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:56.805834055 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:56.806174994 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:56.806205034 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.462948084 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.464967012 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:57.465027094 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.466614008 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.466708899 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:57.715238094 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:57.715637922 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.763184071 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:57.763206959 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:46:57.810075045 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:46:57.853616953 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:57.853662014 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:57.853811979 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:57.856535912 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:57.856553078 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.521630049 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.521716118 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.526998043 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.527034998 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.527430058 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.575721979 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.684258938 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.726507902 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.873769045 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.873935938 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.874015093 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.874068975 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.874095917 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.874095917 CEST49740443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.874106884 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.874118090 CEST44349740184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.939790010 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.939872026 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:58.939965963 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.940352917 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:58.940386057 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.598043919 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.598201990 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.600667953 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.600696087 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.601037979 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.602698088 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.650502920 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.897141933 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.897316933 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.897433996 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.898627996 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.898627996 CEST49741443192.168.2.4184.28.90.27
            May 27, 2024 02:46:59.898695946 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:46:59.898729086 CEST44349741184.28.90.27192.168.2.4
            May 27, 2024 02:47:06.126861095 CEST49672443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.126861095 CEST49672443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.126955032 CEST44349672173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.127002954 CEST44349672173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.127033949 CEST49672443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.127049923 CEST44349672173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.127886057 CEST49742443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.127969027 CEST44349742173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.128253937 CEST49742443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.128253937 CEST49742443192.168.2.4173.222.162.32
            May 27, 2024 02:47:06.128329039 CEST44349742173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.885376930 CEST44349742173.222.162.32192.168.2.4
            May 27, 2024 02:47:06.885483027 CEST49742443192.168.2.4173.222.162.32
            May 27, 2024 02:47:07.369184017 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:47:07.369328976 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:47:07.369406939 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:47:07.473979950 CEST49739443192.168.2.4142.250.184.228
            May 27, 2024 02:47:07.474050999 CEST44349739142.250.184.228192.168.2.4
            May 27, 2024 02:47:26.092022896 CEST44349742173.222.162.32192.168.2.4
            May 27, 2024 02:47:26.092118025 CEST49742443192.168.2.4173.222.162.32
            May 27, 2024 02:47:39.745002031 CEST4973680192.168.2.4142.250.185.129
            May 27, 2024 02:47:39.750221968 CEST8049736142.250.185.129192.168.2.4
            May 27, 2024 02:47:40.654102087 CEST4973580192.168.2.4142.250.185.129
            May 27, 2024 02:47:40.659288883 CEST8049735142.250.185.129192.168.2.4
            May 27, 2024 02:47:55.355963945 CEST4973680192.168.2.4142.250.185.129
            May 27, 2024 02:47:55.361499071 CEST8049736142.250.185.129192.168.2.4
            May 27, 2024 02:47:55.361660957 CEST4973680192.168.2.4142.250.185.129
            May 27, 2024 02:47:56.809189081 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:47:56.809236050 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:56.809307098 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:47:56.809533119 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:47:56.809542894 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:57.463423967 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:57.463723898 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:47:57.463742018 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:57.464867115 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:57.468281984 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:47:57.468364000 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:47:57.510219097 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:48:07.371294022 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:48:07.371442080 CEST44349752142.250.184.228192.168.2.4
            May 27, 2024 02:48:07.371505022 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:48:09.359184027 CEST49752443192.168.2.4142.250.184.228
            May 27, 2024 02:48:09.359204054 CEST44349752142.250.184.228192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            May 27, 2024 02:46:53.171276093 CEST53500951.1.1.1192.168.2.4
            May 27, 2024 02:46:53.230220079 CEST53522541.1.1.1192.168.2.4
            May 27, 2024 02:46:54.265588045 CEST53645231.1.1.1192.168.2.4
            May 27, 2024 02:46:54.708494902 CEST6269153192.168.2.41.1.1.1
            May 27, 2024 02:46:54.714607954 CEST5780653192.168.2.41.1.1.1
            May 27, 2024 02:46:54.715586901 CEST53626911.1.1.1192.168.2.4
            May 27, 2024 02:46:54.723006010 CEST53578061.1.1.1192.168.2.4
            May 27, 2024 02:46:56.751205921 CEST4929153192.168.2.41.1.1.1
            May 27, 2024 02:46:56.751499891 CEST6532053192.168.2.41.1.1.1
            May 27, 2024 02:46:56.758223057 CEST53492911.1.1.1192.168.2.4
            May 27, 2024 02:46:56.803436995 CEST53653201.1.1.1192.168.2.4
            May 27, 2024 02:47:11.358499050 CEST53540231.1.1.1192.168.2.4
            May 27, 2024 02:47:14.755376101 CEST138138192.168.2.4192.168.2.255
            May 27, 2024 02:47:30.370594025 CEST53566911.1.1.1192.168.2.4
            May 27, 2024 02:47:52.226640940 CEST53601141.1.1.1192.168.2.4
            May 27, 2024 02:47:53.451303959 CEST53595481.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            May 27, 2024 02:46:54.708494902 CEST192.168.2.41.1.1.10x7324Standard query (0)clients2.googleusercontent.comA (IP address)IN (0x0001)false
            May 27, 2024 02:46:54.714607954 CEST192.168.2.41.1.1.10x64a6Standard query (0)clients2.googleusercontent.com65IN (0x0001)false
            May 27, 2024 02:46:56.751205921 CEST192.168.2.41.1.1.10x368eStandard query (0)www.google.comA (IP address)IN (0x0001)false
            May 27, 2024 02:46:56.751499891 CEST192.168.2.41.1.1.10x2113Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            May 27, 2024 02:46:54.715586901 CEST1.1.1.1192.168.2.40x7324No error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:46:54.715586901 CEST1.1.1.1192.168.2.40x7324No error (0)googlehosted.l.googleusercontent.com142.250.185.129A (IP address)IN (0x0001)false
            May 27, 2024 02:46:54.723006010 CEST1.1.1.1192.168.2.40x64a6No error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:46:56.758223057 CEST1.1.1.1192.168.2.40x368eNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
            May 27, 2024 02:46:56.803436995 CEST1.1.1.1192.168.2.40x2113No error (0)www.google.com65IN (0x0001)false
            May 27, 2024 02:47:09.376362085 CEST1.1.1.1192.168.2.40x4c0bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:47:09.376362085 CEST1.1.1.1192.168.2.40x4c0bNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 02:47:22.614289999 CEST1.1.1.1192.168.2.40xdce6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:47:22.614289999 CEST1.1.1.1192.168.2.40xdce6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 02:47:45.451879025 CEST1.1.1.1192.168.2.40xb92fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:47:45.451879025 CEST1.1.1.1192.168.2.40xb92fNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            May 27, 2024 02:48:06.291909933 CEST1.1.1.1192.168.2.40xc79eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            May 27, 2024 02:48:06.291909933 CEST1.1.1.1192.168.2.40xc79eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • clients2.googleusercontent.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735142.250.185.129804248C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            May 27, 2024 02:46:54.729300022 CEST666OUTGET /crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx HTTP/1.1
            Host: clients2.googleusercontent.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            May 27, 2024 02:46:55.357543945 CEST188INHTTP/1.1 403 Forbidden
            Content-Type: text/plain; charset=utf-8
            Content-Length: 42
            Date: Mon, 27 May 2024 00:46:55 GMT
            Server: UploadServer
            Data Raw: 53 53 4c 20 69 73 20 72 65 71 75 69 72 65 64 20 74 6f 20 70 65 72 66 6f 72 6d 20 74 68 69 73 20 6f 70 65 72 61 74 69 6f 6e 2e
            Data Ascii: SSL is required to perform this operation.
            May 27, 2024 02:46:55.442466021 CEST625OUTGET /favicon.ico HTTP/1.1
            Host: clients2.googleusercontent.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Referer: http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            May 27, 2024 02:46:55.636373043 CEST1236INHTTP/1.1 404 Not Found
            Cross-Origin-Resource-Policy: cross-origin
            Content-Type: text/html; charset=UTF-8
            X-Content-Type-Options: nosniff
            Date: Mon, 27 May 2024 00:46:55 GMT
            Server: sffe
            Content-Length: 1572
            X-XSS-Protection: 0
            Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 34 20 28 4e 6f 74 20 46 6f 75 6e 64 29 21 21 31 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 2a 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 7d 68 74 6d 6c 2c 63 6f 64 65 7b 66 6f 6e 74 3a 31 35 70 78 2f 32 32 70 78 20 61 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 7d 68 74 6d 6c 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 63 6f 6c 6f 72 3a 23 32 32 32 3b 70 61 64 64 69 6e 67 3a 31 35 70 78 7d 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 37 25 20 61 75 74 6f 20 30 3b 6d 61 78 2d 77 69 64 74 68 3a 33 39 [TRUNCATED]
            Data Ascii: <!DOCTYPE html><html lang=en> <meta charset=utf-8> <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width"> <title>Error 404 (Not Found)!!1</title> <style> *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www
            May 27, 2024 02:46:55.641083002 CEST573INData Raw: 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 30 7d 7d 40 6d 65 64 69 61
            Data Ascii: .google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat;
            May 27, 2024 02:47:40.654102087 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736142.250.185.129804248C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            May 27, 2024 02:47:39.745002031 CEST6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449740184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-05-27 00:46:58 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-27 00:46:58 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=228136
            Date: Mon, 27 May 2024 00:46:58 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449741184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-05-27 00:46:59 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-05-27 00:46:59 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=228218
            Date: Mon, 27 May 2024 00:46:59 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-05-27 00:46:59 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:20:46:47
            Start date:26/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:20:46:50
            Start date:26/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2056,i,8146993895664307503,12275233904855355838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:20:46:53
            Start date:26/05/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://clients2.googleusercontent.com/crx/blobs/AcO95oj7juz8l5ipKQ8J4HvJ5IaiLLyTXWqVcoi75bXCQuXNFG0by3_p5G34A7LBm-R7WO-UExKj38S32gDSTGpf2das0Rh3pvd1BomNhfUIRD7ttBsI3w0_KmQ2RCTPzJrTAMZSmuXvFlc9xBmQZj1rEkHpKaNAkKASCA/EFLHGAMMLCOFELHAGIOEGONGHDMHABMK_1_5_7_0.crx"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:6
            Start time:20:47:15
            Start date:26/05/2024
            Path:C:\Windows\System32\conhost.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Imagebase:0x7ff7699e0000
            File size:862'208 bytes
            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
            Has elevated privileges:true
            Has administrator privileges:false
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly