Edit tour

Windows Analysis Report
https://dl.edge-aicdn.net/assets/init-a.js

Overview

General Information

Sample URL:https://dl.edge-aicdn.net/assets/init-a.js
Analysis ID:1661430
Infos:

Detection

Score:1
Range:0 - 100
Confidence:80%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6760 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2124 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 2900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4972 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.edge-aicdn.net/assets/init-a.js" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 142.251.40.164:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.16.1:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.16.1:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49708 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /assets/init-a.js HTTP/1.1Host: dl.edge-aicdn.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dl.edge-aicdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dl.edge-aicdn.net/assets/init-a.jsAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: dl.edge-aicdn.net
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 438Content-Type: application/reports+jsonOrigin: https://dl.edge-aicdn.netUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Thu, 10 Apr 2025 03:21:58 GMTContent-Type: application/xml; charset=UTF-8Content-Length: 111Connection: closeX-GUploader-UploadID: AKDAyItfWPoOtM__Ca6BfowVmu3NSLNi_tGg-2R3nCXjfR82ZgI2AbHrx815NBS_bZafGnXy35HFU-gExpires: Thu, 10 Apr 2025 03:21:58 GMTCache-Control: private, max-age=0cf-cache-status: BYPASSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 92df1df99911c470-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=96969&min_rtt=96498&rtt_var=20694&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2833&recv_bytes=1185&delivery_rate=38492&cwnd=246&unsent_bytes=0&cid=2e6be109241fdb86&ts=493&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 142.251.40.164:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.16.1:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.16.1:443 -> 192.168.2.5:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49708 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6228_1862239408Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6228_1862239408Jump to behavior
Source: classification engineClassification label: clean1.win@23/2@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2124 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4972 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.edge-aicdn.net/assets/init-a.js"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2124 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4972 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1661430 URL: https://dl.edge-aicdn.net/a... Startdate: 10/04/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 192.168.2.5, 138, 443, 49675 unknown unknown 5->15 10 chrome.exe 5->10         started        13 chrome.exe 5->13         started        process4 dnsIp5 17 www.google.com 142.251.40.164, 443, 49701, 49713 GOOGLEUS United States 10->17 19 a.nel.cloudflare.com 35.190.80.1, 443, 49705, 49706 GOOGLEUS United States 10->19 21 dl.edge-aicdn.net 104.21.16.1, 443, 49702, 49703 CLOUDFLARENETUS United States 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://dl.edge-aicdn.net/assets/init-a.js0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://dl.edge-aicdn.net/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    dl.edge-aicdn.net
    104.21.16.1
    truefalse
      high
      www.google.com
      142.251.40.164
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://c.pki.goog/r/gsr1.crlfalse
          high
          http://c.pki.goog/r/r4.crlfalse
            high
            https://dl.edge-aicdn.net/assets/init-a.jsfalse
              unknown
              https://dl.edge-aicdn.net/favicon.icofalse
              • Avira URL Cloud: safe
              unknown
              https://a.nel.cloudflare.com/report/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3Dfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.251.40.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                104.21.16.1
                dl.edge-aicdn.netUnited States
                13335CLOUDFLARENETUSfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.5
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1661430
                Start date and time:2025-04-10 05:20:53 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 58s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://dl.edge-aicdn.net/assets/init-a.js
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:10
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean1.win@23/2@6/4
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 184.31.69.3, 199.232.214.172, 142.250.65.174, 142.251.41.3, 142.250.31.84, 142.250.65.238, 142.251.32.110, 142.250.65.206, 142.251.40.238, 142.250.176.206, 142.250.81.238, 142.250.65.227, 142.250.80.78, 142.251.40.195, 172.202.163.200
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, c.pki.goog
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • VT rate limit hit for: https://dl.edge-aicdn.net/assets/init-a.js
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):111
                Entropy (8bit):4.62062991365628
                Encrypted:false
                SSDEEP:3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n
                MD5:E7A9350210B4DBA641F6020447C96045
                SHA1:581ACCEF4A8B7FBED97291FE7DD4E113F794EC80
                SHA-256:08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80
                SHA-512:2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2
                Malicious:false
                Reputation:low
                URL:https://dl.edge-aicdn.net/favicon.ico
                Preview:<?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 74
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Apr 10, 2025 05:21:43.131386995 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:43.443434954 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:44.052861929 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:44.091269970 CEST49672443192.168.2.5204.79.197.203
                Apr 10, 2025 05:21:45.255925894 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:47.311867952 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:47.405554056 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:21:47.405639887 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:47.430227995 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:47.524321079 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:21:47.524511099 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:21:47.524560928 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:21:47.524629116 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:47.662164927 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:48.116282940 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:48.213232994 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:21:48.255891085 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:21:52.631459951 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:21:53.708731890 CEST49672443192.168.2.5204.79.197.203
                Apr 10, 2025 05:21:55.842133045 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:55.842179060 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:21:55.842402935 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:55.842528105 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:55.842544079 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:21:56.052948952 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:21:56.053175926 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:56.055139065 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:56.055150032 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:21:56.055635929 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:21:56.101116896 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:21:57.438692093 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.438729048 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.438812971 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.439282894 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.439333916 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.439430952 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.439486027 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.439497948 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.439636946 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.439644098 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.653336048 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.653413057 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.653940916 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.654184103 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.654489994 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.654495001 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.654978037 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.655385971 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.655391932 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.655775070 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.655859947 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.695769072 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.696299076 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.891721010 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.891912937 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.891974926 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.892956972 CEST49703443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:57.892975092 CEST44349703104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:57.973093033 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:58.016303062 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:58.128483057 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:58.128571987 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:58.128657103 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:58.130369902 CEST49702443192.168.2.5104.21.16.1
                Apr 10, 2025 05:21:58.130384922 CEST44349702104.21.16.1192.168.2.5
                Apr 10, 2025 05:21:58.227118969 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.227220058 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.227300882 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.227483988 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.227508068 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.432962894 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.433053970 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.434155941 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.434180975 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.434727907 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.435077906 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.476295948 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.640937090 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.641135931 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.641222000 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.641526937 CEST49705443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.641563892 CEST4434970535.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.642513037 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.642564058 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.642633915 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.642800093 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.642819881 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.842889071 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.844949961 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.844971895 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:58.845190048 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:58.845199108 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:59.063479900 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:59.063692093 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:21:59.063751936 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:59.064146996 CEST49706443192.168.2.535.190.80.1
                Apr 10, 2025 05:21:59.064162016 CEST4434970635.190.80.1192.168.2.5
                Apr 10, 2025 05:22:02.241308928 CEST49676443192.168.2.520.189.173.14
                Apr 10, 2025 05:22:05.449666977 CEST49675443192.168.2.52.23.227.208
                Apr 10, 2025 05:22:05.449706078 CEST443496752.23.227.208192.168.2.5
                Apr 10, 2025 05:22:05.680001020 CEST49708443192.168.2.5150.171.27.254
                Apr 10, 2025 05:22:05.680103064 CEST44349708150.171.27.254192.168.2.5
                Apr 10, 2025 05:22:05.680207014 CEST49708443192.168.2.5150.171.27.254
                Apr 10, 2025 05:22:05.680607080 CEST49708443192.168.2.5150.171.27.254
                Apr 10, 2025 05:22:05.680641890 CEST44349708150.171.27.254192.168.2.5
                Apr 10, 2025 05:22:05.993812084 CEST44349708150.171.27.254192.168.2.5
                Apr 10, 2025 05:22:05.993925095 CEST49708443192.168.2.5150.171.27.254
                Apr 10, 2025 05:22:06.046499968 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:06.046581030 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:06.046649933 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:07.555229902 CEST49701443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:07.555272102 CEST44349701142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:50.366056919 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:22:50.459285975 CEST8049691142.251.40.131192.168.2.5
                Apr 10, 2025 05:22:50.459389925 CEST4969180192.168.2.5142.251.40.131
                Apr 10, 2025 05:22:55.804691076 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:55.804737091 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:55.804905891 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:55.805130005 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:55.805139065 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:56.007580996 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:22:56.008057117 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:22:56.008090019 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:23:06.016172886 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:23:06.016330957 CEST44349713142.251.40.164192.168.2.5
                Apr 10, 2025 05:23:06.016603947 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:23:07.555160046 CEST49713443192.168.2.5142.251.40.164
                Apr 10, 2025 05:23:07.555233955 CEST44349713142.251.40.164192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Apr 10, 2025 05:21:51.298928976 CEST53625581.1.1.1192.168.2.5
                Apr 10, 2025 05:21:51.506489992 CEST53571821.1.1.1192.168.2.5
                Apr 10, 2025 05:21:52.321898937 CEST53594391.1.1.1192.168.2.5
                Apr 10, 2025 05:21:55.743633032 CEST5035353192.168.2.51.1.1.1
                Apr 10, 2025 05:21:55.743983984 CEST5262453192.168.2.51.1.1.1
                Apr 10, 2025 05:21:55.840692043 CEST53503531.1.1.1192.168.2.5
                Apr 10, 2025 05:21:55.840876102 CEST53526241.1.1.1192.168.2.5
                Apr 10, 2025 05:21:57.338711023 CEST6037653192.168.2.51.1.1.1
                Apr 10, 2025 05:21:57.338963985 CEST5706653192.168.2.51.1.1.1
                Apr 10, 2025 05:21:57.437741041 CEST53570661.1.1.1192.168.2.5
                Apr 10, 2025 05:21:57.438102961 CEST53603761.1.1.1192.168.2.5
                Apr 10, 2025 05:21:58.129702091 CEST6428753192.168.2.51.1.1.1
                Apr 10, 2025 05:21:58.129877090 CEST5317753192.168.2.51.1.1.1
                Apr 10, 2025 05:21:58.226104975 CEST53642871.1.1.1192.168.2.5
                Apr 10, 2025 05:21:58.226325989 CEST53531771.1.1.1192.168.2.5
                Apr 10, 2025 05:22:09.326023102 CEST53583161.1.1.1192.168.2.5
                Apr 10, 2025 05:22:28.405482054 CEST53550131.1.1.1192.168.2.5
                Apr 10, 2025 05:22:46.404113054 CEST138138192.168.2.5192.168.2.255
                Apr 10, 2025 05:22:51.108880997 CEST53625311.1.1.1192.168.2.5
                Apr 10, 2025 05:22:51.116099119 CEST53531281.1.1.1192.168.2.5
                Apr 10, 2025 05:22:54.168248892 CEST53550881.1.1.1192.168.2.5
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 10, 2025 05:21:55.743633032 CEST192.168.2.51.1.1.10xf9cbStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:55.743983984 CEST192.168.2.51.1.1.10xbfffStandard query (0)www.google.com65IN (0x0001)false
                Apr 10, 2025 05:21:57.338711023 CEST192.168.2.51.1.1.10x4153Standard query (0)dl.edge-aicdn.netA (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.338963985 CEST192.168.2.51.1.1.10xba37Standard query (0)dl.edge-aicdn.net65IN (0x0001)false
                Apr 10, 2025 05:21:58.129702091 CEST192.168.2.51.1.1.10xf292Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:58.129877090 CEST192.168.2.51.1.1.10x86e3Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 10, 2025 05:21:55.840692043 CEST1.1.1.1192.168.2.50xf9cbNo error (0)www.google.com142.251.40.164A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:55.840876102 CEST1.1.1.1192.168.2.50xbfffNo error (0)www.google.com65IN (0x0001)false
                Apr 10, 2025 05:21:57.437741041 CEST1.1.1.1192.168.2.50xba37No error (0)dl.edge-aicdn.net65IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.16.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.112.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.48.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.80.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.32.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.64.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:57.438102961 CEST1.1.1.1192.168.2.50x4153No error (0)dl.edge-aicdn.net104.21.96.1A (IP address)IN (0x0001)false
                Apr 10, 2025 05:21:58.226104975 CEST1.1.1.1192.168.2.50xf292No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                • dl.edge-aicdn.net
                • a.nel.cloudflare.com
                • c.pki.goog
                Session IDSource IPSource PortDestination IPDestination Port
                0192.168.2.549691142.251.40.13180
                TimestampBytes transferredDirectionData
                Apr 10, 2025 05:21:47.430227995 CEST202OUTGET /r/gsr1.crl HTTP/1.1
                Cache-Control: max-age = 3000
                Connection: Keep-Alive
                Accept: */*
                If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
                User-Agent: Microsoft-CryptoAPI/10.0
                Host: c.pki.goog
                Apr 10, 2025 05:21:47.524511099 CEST1254INHTTP/1.1 200 OK
                Accept-Ranges: bytes
                Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                Cross-Origin-Resource-Policy: cross-origin
                Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                Content-Length: 1739
                X-Content-Type-Options: nosniff
                Server: sffe
                X-XSS-Protection: 0
                Date: Thu, 10 Apr 2025 03:06:39 GMT
                Expires: Thu, 10 Apr 2025 03:56:39 GMT
                Cache-Control: public, max-age=3000
                Age: 908
                Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
                Content-Type: application/pkix-crl
                Vary: Accept-Encoding
                Data Raw: 30 82 06 c7 30 82 05 af 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69 67 6e 20 6e 76 2d 73 61 31 10 30 0e 06 03 55 04 0b 13 07 52 6f 6f 74 20 43 41 31 1b 30 19 06 03 55 04 03 13 12 47 6c 6f 62 61 6c 53 69 67 6e 20 52 6f 6f 74 20 43 41 17 0d 32 35 30 34 30 37 30 30 30 30 30 30 5a 17 0d 32 35 30 37 31 35 30 30 30 30 30 30 5a 30 82 04 f1 30 2a 02 0b 04 00 00 00 00 01 1e 44 a5 e4 04 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 29 45 c3 a8 0f 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 20 19 c1 8d 68 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2c 5e 7f 1a 88 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 15 4b 5a [TRUNCATED]
                Data Ascii: 000*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA250407000000Z250715000000Z00*D141125000000Z00U0*)E141125000000Z00U0* h141125000000Z00U0*,^141125000000Z00U0*KZ160107000000Z00U0*/NIR170419000000Z00U0*/NG170419000000Z00U0*/N9191120000000Z00U0*/N=k191204000000Z00U
                Apr 10, 2025 05:21:47.524560928 CEST1198INData Raw: 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2f 4e e1 3b 58 17 0d 31 39 31 32 30 34 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2d 02 0e 47 c3 0f ff 8a 61 9a 37 f5 a8 2e f0 b5 75 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30
                Data Ascii: 0*/N;X191204000000Z00U0-Ga7.u200630000000Z00U0-GA>ThA200630000000Z00U0-GK&TA+200630000000Z00U0*6::200711160000Z00U0/vSBS
                Apr 10, 2025 05:21:48.116282940 CEST200OUTGET /r/r4.crl HTTP/1.1
                Cache-Control: max-age = 3000
                Connection: Keep-Alive
                Accept: */*
                If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                User-Agent: Microsoft-CryptoAPI/10.0
                Host: c.pki.goog
                Apr 10, 2025 05:21:48.213232994 CEST1243INHTTP/1.1 200 OK
                Accept-Ranges: bytes
                Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                Cross-Origin-Resource-Policy: cross-origin
                Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                Content-Length: 530
                X-Content-Type-Options: nosniff
                Server: sffe
                X-XSS-Protection: 0
                Date: Thu, 10 Apr 2025 02:48:38 GMT
                Expires: Thu, 10 Apr 2025 03:38:38 GMT
                Cache-Control: public, max-age=3000
                Age: 1990
                Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                Content-Type: application/pkix-crl
                Vary: Accept-Encoding
                Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.549703104.21.16.14436760C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-10 03:21:57 UTC683OUTGET /assets/init-a.js HTTP/1.1
                Host: dl.edge-aicdn.net
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-10 03:21:57 UTC1354INHTTP/1.1 200 OK
                Date: Thu, 10 Apr 2025 03:21:57 GMT
                Content-Type: text/javascript
                Content-Length: 0
                Connection: close
                X-GUploader-UploadID: AKDAyIu4scdPO9ruMfQMOZ4M7s3TATtVtbDX7K37F1NjAgYQ-W8l3SbwjJemyz3zCuaB9ksS
                x-goog-generation: 1743183533533707
                x-goog-metageneration: 4
                x-goog-stored-content-encoding: identity
                x-goog-stored-content-length: 0
                x-goog-hash: crc32c=AAAAAA==
                x-goog-hash: md5=1B2M2Y8AsgTpgAmY7PhCfg==
                x-goog-storage-class: STANDARD
                Expires: Tue, 08 Apr 2025 11:41:16 GMT
                Cache-Control: public, max-age=1209600
                Age: 146439
                Last-Modified: Fri, 28 Mar 2025 17:38:53 GMT
                ETag: "d41d8cd98f00b204e9800998ecf8427e"
                CF-Cache-Status: HIT
                Accept-Ranges: bytes
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=LPSXeaaEMMe%2BQugUuSSUIDpltc8LMozHrkIHWtDGjvSlbfLJ8YfIljbP9m4zHeC%2Flc6mTgBgsgKTt1IfxPo75prhKAhY0E%2BX0%2B%2FWJD0sBTyrmI%2BEosvvRNjGUjuLAOoMLf5CxA%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Access-Control-Allow-Origin: *
                Server: cloudflare
                CF-RAY: 92df1df86f9958af-EWR
                alt-svc: h3=":443"; ma=86400
                server-timing: cfL4;desc="?proto=TCP&rtt=97731&min_rtt=97643&rtt_var=20681&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2834&recv_bytes=1255&delivery_rate=38151&cwnd=245&unsent_bytes=0&cid=8f4e40794fe6532f&ts=254&x=0"


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.549702104.21.16.14436760C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-10 03:21:57 UTC613OUTGET /favicon.ico HTTP/1.1
                Host: dl.edge-aicdn.net
                Connection: keep-alive
                sec-ch-ua-platform: "Windows"
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                sec-ch-ua-mobile: ?0
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://dl.edge-aicdn.net/assets/init-a.js
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-10 03:21:58 UTC975INHTTP/1.1 403 Forbidden
                Date: Thu, 10 Apr 2025 03:21:58 GMT
                Content-Type: application/xml; charset=UTF-8
                Content-Length: 111
                Connection: close
                X-GUploader-UploadID: AKDAyItfWPoOtM__Ca6BfowVmu3NSLNi_tGg-2R3nCXjfR82ZgI2AbHrx815NBS_bZafGnXy35HFU-g
                Expires: Thu, 10 Apr 2025 03:21:58 GMT
                Cache-Control: private, max-age=0
                cf-cache-status: BYPASS
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 92df1df99911c470-EWR
                alt-svc: h3=":443"; ma=86400
                server-timing: cfL4;desc="?proto=TCP&rtt=96969&min_rtt=96498&rtt_var=20694&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2833&recv_bytes=1185&delivery_rate=38492&cwnd=246&unsent_bytes=0&cid=2e6be109241fdb86&ts=493&x=0"
                2025-04-10 03:21:58 UTC111INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 27 31 2e 30 27 20 65 6e 63 6f 64 69 6e 67 3d 27 55 54 46 2d 38 27 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 64 65 6e 69 65 64 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
                Data Ascii: <?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.54970535.190.80.14436760C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-10 03:21:58 UTC546OUTOPTIONS /report/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://dl.edge-aicdn.net
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-10 03:21:58 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: OPTIONS, POST
                access-control-allow-origin: *
                access-control-allow-headers: content-length, content-type
                date: Thu, 10 Apr 2025 03:21:58 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.54970635.190.80.14436760C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2025-04-10 03:21:58 UTC521OUTPOST /report/v4?s=j5kWIFRJDsapUdjlaDjo7FPE32JsfyMfkZt9a6So4qY2hYbdsMfacW0VyhUDIcdWLvWTONDBimaDrZbafrRFqTNGI6YK8qexEr6lbli2mDtefFrcn1mbLoVszzIVG%2F3frpKxFw%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 438
                Content-Type: application/reports+json
                Origin: https://dl.edge-aicdn.net
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br, zstd
                Accept-Language: en-US,en;q=0.9
                2025-04-10 03:21:58 UTC438OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 35 35 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 64 6c 2e 65 64 67 65 2d 61 69 63 64 6e 2e 6e 65 74 2f 61 73 73 65 74 73 2f 69 6e 69 74 2d 61 2e 6a 73 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 31 36 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72
                Data Ascii: [{"age":0,"body":{"elapsed_time":155,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://dl.edge-aicdn.net/assets/init-a.js","sampling_fraction":1.0,"server_ip":"104.21.16.1","status_code":403,"type":"http.error"},"type":"networ
                2025-04-10 03:21:59 UTC214INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-allow-origin: *
                vary: Origin
                date: Thu, 10 Apr 2025 03:21:58 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                020406080s020406080100

                Click to jump to process

                020406080s0.0050100MB

                Click to jump to process

                Target ID:1
                Start time:23:21:45
                Start date:09/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff6fa0a0000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:23:21:49
                Start date:09/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2124 /prefetch:3
                Imagebase:0x7ff6fa0a0000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:23:21:51
                Start date:09/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1932,i,12294007067438847739,4108631176542216730,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4972 /prefetch:8
                Imagebase:0x7ff6fa0a0000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:6
                Start time:23:21:55
                Start date:09/04/2025
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl.edge-aicdn.net/assets/init-a.js"
                Imagebase:0x7ff65bd60000
                File size:3'388'000 bytes
                MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                No disassembly