Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank

Overview

General Information

Sample URL:https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank
Analysis ID:671859
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 3116 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: C139654B5C1438A95B321BB01AD63EF6)
    • chrome.exe (PID: 5828 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1604,18173075307747983275,7024365074969089678,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1928 /prefetch:8 MD5: C139654B5C1438A95B321BB01AD63EF6)
  • chrome.exe (PID: 6172 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank MD5: C139654B5C1438A95B321BB01AD63EF6)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9SlashNext: Label: Credential Stealing type: Phishing & Social Engineering

Phishing

barindex
Source: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9Matcher: Template: google matched with high similarity
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdicJump to behavior
Source: unknownHTTPS traffic detected: 142.251.209.4:443 -> 192.168.2.3:49774 version: TLS 1.2
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/mqdrxkc/2Factor.html HTTP/1.1Host: locksmithelpasotexas.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9 HTTP/1.1Host: voyage-croissant-31209.herokuapp.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /general/geo.js HTTP/1.1Host: voyage-croissant-31209.herokuapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /get_html.php HTTP/1.1Host: api.hostip.infoConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Origin: https://voyage-croissant-31209.herokuapp.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://voyage-croissant-31209.herokuapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /general/download.png HTTP/1.1Host: voyage-croissant-31209.herokuapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /%2084.17.52.2 HTTP/1.1Host: ipinfo.ioConnection: keep-aliveAccept: application/json, text/javascript, */*; q=0.01User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Origin: https://voyage-croissant-31209.herokuapp.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://voyage-croissant-31209.herokuapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /84.17.52.2 HTTP/1.1Host: ipinfo.ioConnection: keep-aliveAccept: application/json, text/javascript, */*; q=0.01User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Origin: https://voyage-croissant-31209.herokuapp.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://voyage-croissant-31209.herokuapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /dns/valid.php?callback=jQuery331028936727179644905_1658542512723&domain=brian.williams%40kraftmaid.com&loc=&_=1658542512724 HTTP/1.1Host: hancott.bizConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://voyage-croissant-31209.herokuapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /s2/favicons?domain=google.com HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://voyage-croissant-31209.herokuapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: voyage-croissant-31209.herokuapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /s2/favicons?domain=google.com HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closeDate: Fri, 22 Jul 2022 17:15:14 GMTServer: ApacheContent-Length: 196Content-Type: text/html; charset=iso-8859-1Via: 1.1 vegur
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://accounts.google.com
Source: craw_window.js.0.drString found in binary or memory: https://accounts.google.com/MergeSession
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://apis.google.com
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://clients2.google.com
Source: manifest.json.0.drString found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://clients2.googleusercontent.com
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.dr, e7c1a6bd-cdc3-44b9-96d7-3723aab2789c.tmp.1.drString found in binary or memory: https://dns.google
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://fonts.googleapis.com
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://fonts.gstatic.com
Source: craw_window.js.0.dr, craw_background.js.0.drString found in binary or memory: https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
Source: History Provider Cache.0.drString found in binary or memory: https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnR
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://ogs.google.com
Source: craw_window.js.0.dr, manifest.json.0.drString found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://play.google.com
Source: craw_window.js.0.dr, manifest.json.0.drString found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://ssl.gstatic.com
Source: History Provider Cache.0.drString found in binary or memory: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams
Source: craw_window.js.0.dr, craw_background.js.0.drString found in binary or memory: https://www-googleapis-staging.sandbox.google.com
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://www.google.com
Source: manifest.json.0.drString found in binary or memory: https://www.google.com/
Source: craw_window.js.0.drString found in binary or memory: https://www.google.com/accounts/OAuthLogin?issueuberauth=1
Source: craw_window.js.0.drString found in binary or memory: https://www.google.com/images/cleardot.gif
Source: craw_window.js.0.drString found in binary or memory: https://www.google.com/images/dot2.gif
Source: craw_window.js.0.drString found in binary or memory: https://www.google.com/images/x2.gif
Source: craw_background.js.0.drString found in binary or memory: https://www.google.com/intl/en-US/chrome/blank.html
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.dr, craw_window.js.0.dr, craw_background.js.0.drString found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: 1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drString found in binary or memory: https://www.gstatic.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownHTTPS traffic detected: 142.251.209.4:443 -> 192.168.2.3:49774 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Temp\35440360-4f2d-4d8e-b7f2-371523e91c34.tmpJump to behavior
Source: classification engineClassification label: mal56.phis.win@27/86@10/11
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1604,18173075307747983275,7024365074969089678,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1928 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1604,18173075307747983275,7024365074969089678,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1928 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62DB59AB-C2C.pmaJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdicJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9100%SlashNextCredential Stealing type: Phishing & Social Engineering
https://dns.google0%URL Reputationsafe
https://voyage-croissant-31209.herokuapp.com/favicon.ico0%Avira URL Cloudsafe
https://api.hostip.info/get_html.php2%VirustotalBrowse
https://api.hostip.info/get_html.php0%Avira URL Cloudsafe
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnR0%VirustotalBrowse
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnR0%Avira URL Cloudsafe
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html0%VirustotalBrowse
https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html0%Avira URL Cloudsafe
https://voyage-croissant-31209.herokuapp.com/general/download.png0%Avira URL Cloudsafe
https://voyage-croissant-31209.herokuapp.com/general/geo.js0%Avira URL Cloudsafe
https://hancott.biz/dns/valid.php?callback=jQuery331028936727179644905_1658542512723&domain=brian.williams%40kraftmaid.com&loc=&_=16585425127240%Avira URL Cloudsafe
https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
voyage-croissant-31209.herokuapp.com
23.22.144.165
truefalse
    unknown
    hancott.biz
    79.110.52.9
    truefalse
      unknown
      accounts.google.com
      142.250.180.141
      truefalse
        high
        ipinfo.io
        34.117.59.81
        truefalse
          high
          www.google.com
          142.251.209.4
          truefalse
            high
            clients.l.google.com
            216.58.209.46
            truefalse
              high
              api.hostip.info
              104.21.84.241
              truefalse
                unknown
                locksmithelpasotexas.com
                173.231.223.247
                truefalse
                  unknown
                  clients2.google.com
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://ipinfo.io/%2084.17.52.2false
                      high
                      https://voyage-croissant-31209.herokuapp.com/favicon.icofalse
                      • Avira URL Cloud: safe
                      unknown
                      https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                        high
                        https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                          high
                          https://api.hostip.info/get_html.phpfalse
                          • 2%, Virustotal, Browse
                          • Avira URL Cloud: safe
                          unknown
                          https://ipinfo.io/84.17.52.2false
                            high
                            https://www.google.com/s2/favicons?domain=google.comfalse
                              high
                              https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.htmlfalse
                              • 0%, Virustotal, Browse
                              • Avira URL Cloud: safe
                              unknown
                              https://voyage-croissant-31209.herokuapp.com/general/download.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://voyage-croissant-31209.herokuapp.com/general/geo.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://hancott.biz/dns/valid.php?callback=jQuery331028936727179644905_1658542512723&domain=brian.williams%40kraftmaid.com&loc=&_=1658542512724false
                              • Avira URL Cloud: safe
                              unknown
                              NameSourceMaliciousAntivirus DetectionReputation
                              https://dns.google1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.dr, e7c1a6bd-cdc3-44b9-96d7-3723aab2789c.tmp.1.drfalse
                              • URL Reputation: safe
                              unknown
                              https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.pcraw_window.js.0.dr, craw_background.js.0.drfalse
                                high
                                https://www.google.com/intl/en-US/chrome/blank.htmlcraw_background.js.0.drfalse
                                  high
                                  https://ogs.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                    high
                                    https://www.google.com/images/cleardot.gifcraw_window.js.0.drfalse
                                      high
                                      https://play.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                        high
                                        https://payments.google.com/payments/v4/js/integrator.jscraw_window.js.0.dr, manifest.json.0.drfalse
                                          high
                                          https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRHistory Provider Cache.0.drfalse
                                          • 0%, Virustotal, Browse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://sandbox.google.com/payments/v4/js/integrator.jscraw_window.js.0.dr, manifest.json.0.drfalse
                                            high
                                            https://www.google.com/images/x2.gifcraw_window.js.0.drfalse
                                              high
                                              https://accounts.google.com/MergeSessioncraw_window.js.0.drfalse
                                                high
                                                https://www.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                                  high
                                                  https://www.google.com/images/dot2.gifcraw_window.js.0.drfalse
                                                    high
                                                    https://accounts.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                                      high
                                                      https://clients2.googleusercontent.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                                        high
                                                        https://apis.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                                          high
                                                          https://www.google.com/accounts/OAuthLogin?issueuberauth=1craw_window.js.0.drfalse
                                                            high
                                                            https://www.google.com/manifest.json.0.drfalse
                                                              high
                                                              https://www-googleapis-staging.sandbox.google.comcraw_window.js.0.dr, craw_background.js.0.drfalse
                                                                high
                                                                https://clients2.google.com1c73881b-fe55-4220-be07-ac4722a7c3e1.tmp.1.drfalse
                                                                  high
                                                                  https://clients2.google.com/service/update2/crxmanifest.json.0.drfalse
                                                                    high
                                                                    https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williamsHistory Provider Cache.0.drfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    • No. of IPs < 25%
                                                                    • 25% < No. of IPs < 50%
                                                                    • 50% < No. of IPs < 75%
                                                                    • 75% < No. of IPs
                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                    34.117.59.81
                                                                    ipinfo.ioUnited States
                                                                    139070GOOGLE-AS-APGoogleAsiaPacificPteLtdSGfalse
                                                                    142.251.209.4
                                                                    www.google.comUnited States
                                                                    15169GOOGLEUSfalse
                                                                    23.22.144.165
                                                                    voyage-croissant-31209.herokuapp.comUnited States
                                                                    14618AMAZON-AESUSfalse
                                                                    216.58.209.46
                                                                    clients.l.google.comUnited States
                                                                    15169GOOGLEUSfalse
                                                                    173.231.223.247
                                                                    locksmithelpasotexas.comUnited States
                                                                    54641INMOTI-1USfalse
                                                                    79.110.52.9
                                                                    hancott.bizRomania
                                                                    60233V4ESCROW-ASROfalse
                                                                    104.21.84.241
                                                                    api.hostip.infoUnited States
                                                                    13335CLOUDFLARENETUSfalse
                                                                    239.255.255.250
                                                                    unknownReserved
                                                                    unknownunknownfalse
                                                                    142.250.180.141
                                                                    accounts.google.comUnited States
                                                                    15169GOOGLEUSfalse
                                                                    IP
                                                                    192.168.2.1
                                                                    127.0.0.1
                                                                    Joe Sandbox Version:35.0.0 Citrine
                                                                    Analysis ID:671859
                                                                    Start date and time: 22/07/202219:14:032022-07-22 19:14:03 +02:00
                                                                    Joe Sandbox Product:CloudBasic
                                                                    Overall analysis duration:0h 3m 24s
                                                                    Hypervisor based Inspection enabled:false
                                                                    Report type:full
                                                                    Cookbook file name:browseurl.jbs
                                                                    Sample URL:https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank
                                                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                    Number of analysed new started processes analysed:14
                                                                    Number of new started drivers analysed:0
                                                                    Number of existing processes analysed:0
                                                                    Number of existing drivers analysed:0
                                                                    Number of injected processes analysed:0
                                                                    Technologies:
                                                                    • HCA enabled
                                                                    • EGA enabled
                                                                    • HDC enabled
                                                                    • AMSI enabled
                                                                    Analysis Mode:default
                                                                    Analysis stop reason:Timeout
                                                                    Detection:MAL
                                                                    Classification:mal56.phis.win@27/86@10/11
                                                                    EGA Information:Failed
                                                                    HDC Information:Failed
                                                                    HCA Information:
                                                                    • Successful, ratio: 100%
                                                                    • Number of executed functions: 0
                                                                    • Number of non-executed functions: 0
                                                                    Cookbook Comments:
                                                                    • Adjust boot time
                                                                    • Enable AMSI
                                                                    • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, svchost.exe
                                                                    • Excluded IPs from analysis (whitelisted): 142.250.184.78, 173.194.188.199, 74.125.163.198, 142.251.209.3, 142.250.184.42, 142.250.184.36, 142.250.184.35, 216.58.209.35
                                                                    • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, r2---sn-4g5ednsd.gvt1.com, ajax.googleapis.com, r2.sn-4g5ednsd.gvt1.com, clientservices.googleapis.com, t1.gstatic.com, arc.msn.com, r1.sn-4g5lznle.gvt1.com, r1---sn-4g5lznle.gvt1.com, redirector.gvt1.com, store-images.s-microsoft.com, login.live.com, update.googleapis.com, www.gstatic.com
                                                                    • Not all processes where analyzed, report is missing behavior information
                                                                    • Report size getting too big, too many NtOpenFile calls found.
                                                                    • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                    No simulations
                                                                    No context
                                                                    No context
                                                                    No context
                                                                    No context
                                                                    No context
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):451603
                                                                    Entropy (8bit):5.009711072558331
                                                                    Encrypted:false
                                                                    SSDEEP:12288:ZHfRTyGZ6lup8Cfrvq4JBPKh+FBlESBw4p6:NfOCzvRKhGvwJ
                                                                    MD5:A78AD14E77147E7DE3647E61964C0335
                                                                    SHA1:CECC3DD41F4CEA0192B24300C71E1911BD4FCE45
                                                                    SHA-256:0D6803758FF8F87081FAFD62E90F0950DFB2DD7991E9607FE76A8F92D0E893FA
                                                                    SHA-512:DDE24D5AD50D68FC91E9E325D31E66EF8F624B6BB3A07D14FFED1104D3AB5F4EF1D7969A5CDE0DFBB19CB31C506F7DE97AF67C2F244F7E7E8E10648EA8321101
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:BDic.... ....6...."..Z..4g....6.2...{/...3...5....AF 1363.AF nm.AF pt.AF n1.AF p.AF tc.AF SM.AF M.AF S.AF MS.AF MNR.AF GDS.AF MNT.AF MH.AF MR.AF SZMR.AF MJ.AF MT.AF MY.AF MRZ.AF MN.AF MG.AF RM.AF N.AF MV.AF XM.AF DSM.AF SD.AF G.AF R.AF MNX.AF MRS.AF MD.AF MNRB.AF B.AF ZSMR.AF PM.AF SMNGJ.AF SMN.AF ZMR.AF SMGB.AF MZR.AF GM.AF SMR.AF SMDG.AF RMZ.AF ZM.AF MDG.AF MDT.AF SMNXT.AF SDY.AF LSDG.AF LGDS.AF GLDS.AF UY.AF U.AF DSGNX.AF GNDSX.AF DSG.AF Y.AF GS.AF IEMS.AF YP.AF ZGDRS.AF XGNVDS.AF UT.AF GNDS.AF GVDS.AF MYPS.AF XGNDS.AF TPRY.AF MDSG.AF ZGSDR.AF DYSG.AF PMYTNS.AF AGDS.AF DRZGS.AF PY.AF GSPMDY.AF EGVDS.AF SL.AF GNXDS.AF DSBG.AF IM.AF I.AF MDGS.AF SMY.AF DSGN.AF DSLG.AF GMDS.AF MDSBG.AF SGD.AF IY.AF P.AF DSMG.AF BLZGDRS.AF TR.AF AGSD.AF ZGBDRSL.AF PTRY.AF ASDGV.AF ASM.AF ICANGSD.AF ICAM.AF IKY.AF AMS.AF PMYTRS.AF BZGVDRS.AF SDRBZG.AF GVMDS.AF PSM.AF DGLS.AF GNVXDS.AF AGDSL.AF DGS.AF XDSGNV.AF BZGDRS.AF AM.AF AS.AF A.AF LDSG.AF AGVDS.AF SDG.AF LDSMG.AF EDSMG.AF EY.AF DRSMZG.AF PRYT.AF LZ
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):92724
                                                                    Entropy (8bit):3.7480622274639557
                                                                    Encrypted:false
                                                                    SSDEEP:384:TJpVOzvV2YZ1qfmN/rcvrx3crpsHFEGQvrqVLXxsJJxIrCTmqN2hfDX0Op5jNm1i:gCFdO9IwQe3vVl0fLKtKbd/dd
                                                                    MD5:9EE6CDA7B2DF9C73DB38EBC7658D4761
                                                                    SHA1:9EE4607EFF7106EA67BD2B39997038E0719B2C13
                                                                    SHA-256:808630BB3EC7158EFFE702D8AE625D3D59E859D6A747FD2BCED856FA2E7B2C9B
                                                                    SHA-512:8BC33E4FCC7D074A3E208EA7EFEB43EA126FB6A8D77A490A1EAFFC1CC3D260B0AB566A03E462D94F4188CD92B9D33C44D7E5408616AE69315ADBB8BFC7F925F0
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:0j..............*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L..P!...[)...%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .o.f.f.i.c.e.\.o.f.f.i.c.e.1.6.\.......g.r.o.o.v.e.e.x...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .2.0.1.6...*...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .f.o.r. .B.u.s.i.n.e.s.s. .E.x.t.e.n.s.i.o.n.s.....1.6...0...4.7.1.1...1.0.0.0.....*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n....b8.D...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.C.o.m.m.o.n. .F.i.l.e.s.\.M.i.c.r.o.s.o.f.t. .S.h.a.r.e.d.\.O.F.F.I.C.E.1.6.\.m.s.o.s.h.e.x.t...d.l.l..@.....U/...%.c.o.m.m.o.n.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .s.h.a.r.e.d.\.o.f.f.i.c.e.1.6.\.......m.s.o.s.h.e.x.t...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.)...M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n. .H.a.n.d.l.e.r.s.......1.6...0...4.2.6.6...1.0.0.1.....D...C.:.\.P.r.o.g.r.a.m.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):215348
                                                                    Entropy (8bit):6.07087747126387
                                                                    Encrypted:false
                                                                    SSDEEP:6144:Q/MqLHWLJ5QQlBDjRFrGU4OCUaqfIlUOoSiuRr:Q/zzgD9l1jAzow
                                                                    MD5:7D19236E7ADDB8BE6D5574FD0F0EEB51
                                                                    SHA1:E083DC39A70F5ACF0366BB5AE2051BE5082ABB53
                                                                    SHA-256:5D09D9395996519785325BF0658418A4839EC2B6DE8116039A4B7082948876CF
                                                                    SHA-512:A65E65D3A65404BEC79745665FF76DC1F1E497767BA56F02F17DFD0DA22E2DFAFB7155DF0545B956B7CBA94BDFDB0E83A9486613206A19F216C4373BFA9A0010
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.658542510416211e+12,"network":1.658510111e+12,"ticks":119391173.0,"uncertainty":3961078.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13291230639114408"},"plugins":{"metadata":{"adobe-flash-player":{"disp
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):215348
                                                                    Entropy (8bit):6.0708781200788495
                                                                    Encrypted:false
                                                                    SSDEEP:6144:fMqLHWLJ5QQlBDjRFrGU4OCUaqfIlUOoSiuRr:fzzgD9l1jAzow
                                                                    MD5:31D26DCA2E7EB06C66E37A00A2FD632A
                                                                    SHA1:892E2C3799D9433213CF07D86575EA1AE63E6FC6
                                                                    SHA-256:EE64291CFADBD9B7D8CA56ECCC6AD472562EB6155139B7EBB272789B2047B32D
                                                                    SHA-512:33B235B7BAA8C8C7CED5E1C50670796E38465F1BB93C217F9417B02D0D8DCDBE3BF0217AB6DE662C15F488B2C5923193FF7D7BF81ED9FCDB207A74C40317EF61
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.658542510416211e+12,"network":1.658510111e+12,"ticks":119391173.0,"uncertainty":3961078.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13245951016607996"},"plugins":{"metadata":{"adobe-flash-player":{"disp
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:modified
                                                                    Size (bytes):40
                                                                    Entropy (8bit):3.254162526001658
                                                                    Encrypted:false
                                                                    SSDEEP:3:FkXft0xE1n:+ftIE1n
                                                                    MD5:BD4642AD6C750A12D912B20BCB92E14D
                                                                    SHA1:C549F0F48FDD4FBC62E51AC26D7E185160CE2123
                                                                    SHA-256:4FD71FE78DFE203137C89C9FB0734358FF432F2BC83338112DC7B830F9B30F2C
                                                                    SHA-512:04410D12EF327614C3AF1251C9906BFEB2977211A7F53CBB08A8C01F9465A382CD001E51AB936A0D196D359F1DECDDAEAF5E7D1DBD49CE5F4FF91BF5C332B6CF
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:sdPC....................s}.....M..2.!..%
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4219
                                                                    Entropy (8bit):4.871684703914691
                                                                    Encrypted:false
                                                                    SSDEEP:48:YXsJjMH+5s7YMHBKsvxMHVzspxMHbsIHt/soBDysKqnsllzMHpDCLsWJMHLsNuMg:RG+ZGJG+GTTD7IGpD+G7Gp2GnG4GVhH
                                                                    MD5:EDC4A4E22003A711AEF67FAED28DB603
                                                                    SHA1:977E551B9ED5F60D018C030B0B4AA2E33B954556
                                                                    SHA-256:DD2C9F43F622F801FCC213CDE8E3E90EF1D0D26665AE675449A94CEC7EB1D453
                                                                    SHA-512:84D3930579FD73C7D86144D5CDC636436955BA79759273C740D2D72BC4847F2F7F165BBCA3EB2E4DFB01777D6A5F141623278C1BF74615C5A491092CE3FD1602
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[],"expiration":"13248543677350473","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543677350474","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31344},"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31656},"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501454993","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501454994","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":39369},"server":"https://www.googleapis.com","supports_spdy":true},
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:very short file (no magic)
                                                                    Category:dropped
                                                                    Size (bytes):1
                                                                    Entropy (8bit):0.0
                                                                    Encrypted:false
                                                                    SSDEEP:3:L:L
                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):17703
                                                                    Entropy (8bit):5.577099159293023
                                                                    Encrypted:false
                                                                    SSDEEP:384:+jotXLlzIX61kXqKf/pUZNCgVLH2HfDhrUeBRTQVEg4N:9Llm61kXqKf/pUZNCgVLH2HfNrUeBRse
                                                                    MD5:FF1965623C7930425740EED6888057A8
                                                                    SHA1:C211557743E2CCAAB5DD40556D8EF753F777AD15
                                                                    SHA-256:143B16E8AA7C0956ED8225B3B86575668B3058ACF777F5DD36C92BAB7580FFB7
                                                                    SHA-512:9E483660970D9AE31AB5A62092E1573AE14E26DCD981EE1C37FE74DF626CC7EC1F84E5AE163A10570794B903A99DB92F996F9DE346A688A55DC36BB7269D5862
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13303016108093578","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5293
                                                                    Entropy (8bit):4.983887917457666
                                                                    Encrypted:false
                                                                    SSDEEP:96:nslfV1pcKIWh6ok0JCXyRWL8vzkz18bOTQVuwn:ns/1pcEhV4iYEkzk
                                                                    MD5:4A78C018621C7FCE98F31AABE29B0205
                                                                    SHA1:477EF78979844EE598D29D21F99966F8D0A64D5B
                                                                    SHA-256:3696DAA6B07FFC6AEB9384CA40F77ADD2A737F9746743B41FAEBEEC6B2B4AC38
                                                                    SHA-512:8428519F835E43639EDFBAA327D5C37C552DD5D8F68FF70CA5E73E64DC5FEFB61C23B48EC921ED70160D9CD7279A182CB238E4B74A74D39B1240C83CEDE27852
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13303016108799586","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13245951485614034","autocomplete":{"retention_policy_last_version":85},"autofill":{"orphan_rows_removed":true},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","7355378"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:modified
                                                                    Size (bytes):11217
                                                                    Entropy (8bit):6.069602775336632
                                                                    Encrypted:false
                                                                    SSDEEP:192:GbylJnlTwGB7V9Hne4qasKxXItmLG48gcLg/PkI:Gb+nldByaFx4toj8VEPT
                                                                    MD5:90F880064A42B29CCFF51FE5425BF1A3
                                                                    SHA1:6A3CAE3996E9FFF653A1DDF731CED32B2BE2ACBF
                                                                    SHA-256:965203D541E442C107DBC6D5B395168123D0397559774BEAE4E5B9ABC44EF268
                                                                    SHA-512:D9CBFCD865356F19A57954F8FD952CAF3D31B354112766C41892D1EF40BD2533682D4EC3F4DA0E59A5397364F67A484B45091BA94E6C69ED18AB681403DFD3F3
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"file_hashes":[{"block_hashes":["A+1PYW3V6CJbBuQ7aqrgYhyH3bT8PKyBXp3hN2slpI0=","WSOpQRkYTHjPSlG9Zif2a7TNhy43NDcG1Zg5Nv0UbH0=","jDctR8ImG5KZrQKm4kDjUB7FokSJfjo/pmvFowRVlaY=","LPxhhJiuU0lprt0T6flpS7TkaDg7MocrbmzO65xH6RI=","nZ9zLb2By96AkKXALRM+C0Eu11XUjPiMXEKjiCPdtHE=","wifibc1QfMBN2jrtUtLgsCefvuceTpAatmLvul11RJA=","dHjWlSIIdjj7MWqg3T8MG58RuuqRXk32vqi/13JqEgA=","zd3DV7dbvfNvx1hdhU01fW5ily52DLN0CFL/ADaEeTI=","DpjXcO85FFFY9KJFPkGNfFUtdQIOsGwO5jUckiUwY14=","gqid6l1+mk/6yWgUECRofI9lMipXgXh2jEN2+CxmPE0=","prDB91X2Mmfg/M/txVMITWBmEGbOGjqBTP7CMjYqdHs=","yLPAqV4gqoyS/zFkEt3Cn2j0q2v9QOSthVFfWn8EzCM=","EPQ3jzdrLkAHyvf3920B5Y3aAkO1IJdn/UtbnAmq6T0=","+oOc6ca+ChKUpTu+oa2ZRxRE+wG3QJmuYWEvYCs40NI=","3mBGNAiRlTANEQkqzU3TEi+5wJ0ubR5uwtS4/9OOM7w=","1A9NNawxuhu95H5eThvf1rewJ4QQWhhPNxJXO1C/n68=","E3vWLQxzmj+e5QxYbUscllJ5n0ITpw5JBHV1Kph3/KM=","i3I8ghdTF9c1ZXNBZmvsID+DV4gxBVN27rj9wsMtRpg=","R8B8qYabnMSlLPhrtu0hGYrHn3llsMHqBbi70gkIjEE=","rhlzuEvv2KRAFMms896xFwkNgPrw6WvmgPn6xrBSa2Y=","LAMXv6sRb0VZrY34aVXF3Fftxs
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):38
                                                                    Entropy (8bit):1.8784775129881184
                                                                    Encrypted:false
                                                                    SSDEEP:3:FQxlXNQxlX:qTCT
                                                                    MD5:51A2CBB807F5085530DEC18E45CB8569
                                                                    SHA1:7AD88CD3DE5844C7FC269C4500228A630016AB5B
                                                                    SHA-256:1C43A1BDA1E458863C46DFAE7FB43BFB3E27802169F37320399B1DD799A819AC
                                                                    SHA-512:B643A8FA75EDA90C89AB98F79D4D022BB81F1F62F50ED4E5440F487F22D1163671EC3AE73C4742C11830214173FF2935C785018318F4A4CAD413AE4EEEF985DF
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.f.5................f.5...............
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):372
                                                                    Entropy (8bit):5.310143128992383
                                                                    Encrypted:false
                                                                    SSDEEP:6:6NSGO9+q2PWXp+N23iKKdK25+Xqx8chI+IFUtqV5NSEeLJZmwYV5NSEeL9VkwOWM:cSGO4va5KkTXfchI3FUtKS5J/kS5D5fk
                                                                    MD5:249160FA2CB069667D455BDC2FDB375B
                                                                    SHA1:19CDC9A0F6F528FB038172BECDE6DDE487FFA2F3
                                                                    SHA-256:7A3CC560CF94CF6FD7009F8BC9E07BA6BEDED1D7E1BB0D0540293450DDA6A6C5
                                                                    SHA-512:E85374F3F2D55A851257EBE7180B985698ECA2F10647750D2F651931D2E67CA24DBDB9020AC8E392DA69B666ECA81FB2553C2C061EF7E6BCCE1C81E5B23182D3
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:2022/07/22-19:15:17.876 1b68 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/MANIFEST-000001.2022/07/22-19:15:17.878 1b68 Recovering log #3.2022/07/22-19:15:17.878 1b68 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/000003.log .
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):372
                                                                    Entropy (8bit):5.310143128992383
                                                                    Encrypted:false
                                                                    SSDEEP:6:6NSGO9+q2PWXp+N23iKKdK25+Xqx8chI+IFUtqV5NSEeLJZmwYV5NSEeL9VkwOWM:cSGO4va5KkTXfchI3FUtKS5J/kS5D5fk
                                                                    MD5:249160FA2CB069667D455BDC2FDB375B
                                                                    SHA1:19CDC9A0F6F528FB038172BECDE6DDE487FFA2F3
                                                                    SHA-256:7A3CC560CF94CF6FD7009F8BC9E07BA6BEDED1D7E1BB0D0540293450DDA6A6C5
                                                                    SHA-512:E85374F3F2D55A851257EBE7180B985698ECA2F10647750D2F651931D2E67CA24DBDB9020AC8E392DA69B666ECA81FB2553C2C061EF7E6BCCE1C81E5B23182D3
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:2022/07/22-19:15:17.876 1b68 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/MANIFEST-000001.2022/07/22-19:15:17.878 1b68 Recovering log #3.2022/07/22-19:15:17.878 1b68 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/000003.log .
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):3036
                                                                    Entropy (8bit):6.109403228808135
                                                                    Encrypted:false
                                                                    SSDEEP:48:JeSwzAcyTEja7AlzicMbLHz0nA27O2lNKni0ErixoFKqUit1t7rHlP3iqB3nz788:oBzryTIRiLj0AYOMnrixvqUiLdHnB3nB
                                                                    MD5:3732B31F627C4B2F6DEDB2BE246F920C
                                                                    SHA1:77034A5E113A48A50631F968A8493D7855875127
                                                                    SHA-256:6A04BD75F63F35E7D8E81ECDB4D86960DF11FAAAE3953C4048639B657679245E
                                                                    SHA-512:8A1A0B81CB39A4E0623678218492595EBC57CA1BABEBE467CC8FD8861FC73983703A7A6A3FC42D1DD81612B6ED082EC1661BA817FC5F4DBD8201CEEE4924337A
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:............"...-..0d22..31209..4c86..862cfe04d2e9..8ab0..9f8d7962..account..brian..com..croissant..freemail..general..herokuapp..html..https..interceptiontype..kraftmaid.!l2ftndjcnpcihjxpzagcgoro1v2szbbxg..login."mq1vzdmmvcnacavpkskc0vdsomzkeznxxl..ndybhkivfvntkkz..norobot..requestsecuritytoken..rp6a5qp4z..sdada..service..settings..sharepoint..statistics..successurl..username..usr..verifylogin..voyage..williams..xrbxfc8vkmf6s..2factor..blank..content..locksmithelpasotexas..mqdrxkc..plugins..target..wp.&ynjpyw4ud2lsbglhbxnaa3jhznrtywlklmnvbq*...-....0d22......2factor.$....31209......4c86......862cfe04d2e9......8ab0......9f8d7962......account......blank.%....brian......com......content.&....croissant......freemail......general......herokuapp......html......https......interceptiontype......kraftmaid...%.!l2ftndjcnpcihjxpzagcgoro1v2szbbxg......locksmithelpasotexas.'....login...&."mq1vzdmmvcnacavpkskc0vdsomzkeznxxl......mqdrxkc.(....ndybhkivfvntkkz......norobot......plugins.)....requestse
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4219
                                                                    Entropy (8bit):4.871684703914691
                                                                    Encrypted:false
                                                                    SSDEEP:48:YXsJjMH+5s7YMHBKsvxMHVzspxMHbsIHt/soBDysKqnsllzMHpDCLsWJMHLsNuMg:RG+ZGJG+GTTD7IGpD+G7Gp2GnG4GVhH
                                                                    MD5:EDC4A4E22003A711AEF67FAED28DB603
                                                                    SHA1:977E551B9ED5F60D018C030B0B4AA2E33B954556
                                                                    SHA-256:DD2C9F43F622F801FCC213CDE8E3E90EF1D0D26665AE675449A94CEC7EB1D453
                                                                    SHA-512:84D3930579FD73C7D86144D5CDC636436955BA79759273C740D2D72BC4847F2F7F165BBCA3EB2E4DFB01777D6A5F141623278C1BF74615C5A491092CE3FD1602
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[],"expiration":"13248543677350473","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543677350474","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31344},"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31656},"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501454993","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501454994","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":39369},"server":"https://www.googleapis.com","supports_spdy":true},
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5293
                                                                    Entropy (8bit):4.983887917457666
                                                                    Encrypted:false
                                                                    SSDEEP:96:nslfV1pcKIWh6ok0JCXyRWL8vzkz18bOTQVuwn:ns/1pcEhV4iYEkzk
                                                                    MD5:4A78C018621C7FCE98F31AABE29B0205
                                                                    SHA1:477EF78979844EE598D29D21F99966F8D0A64D5B
                                                                    SHA-256:3696DAA6B07FFC6AEB9384CA40F77ADD2A737F9746743B41FAEBEEC6B2B4AC38
                                                                    SHA-512:8428519F835E43639EDFBAA327D5C37C552DD5D8F68FF70CA5E73E64DC5FEFB61C23B48EC921ED70160D9CD7279A182CB238E4B74A74D39B1240C83CEDE27852
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"account_id_migration_state":2,"account_tracker_service_last_update":"13303016108799586","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13245951485614034","autocomplete":{"retention_policy_last_version":85},"autofill":{"orphan_rows_removed":true},"browser":{"has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","7355378"],"daily_received_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):17703
                                                                    Entropy (8bit):5.577099159293023
                                                                    Encrypted:false
                                                                    SSDEEP:384:+jotXLlzIX61kXqKf/pUZNCgVLH2HfDhrUeBRTQVEg4N:9Llm61kXqKf/pUZNCgVLH2HfNrUeBRse
                                                                    MD5:FF1965623C7930425740EED6888057A8
                                                                    SHA1:C211557743E2CCAAB5DD40556D8EF753F777AD15
                                                                    SHA-256:143B16E8AA7C0956ED8225B3B86575668B3058ACF777F5DD36C92BAB7580FFB7
                                                                    SHA-512:9E483660970D9AE31AB5A62092E1573AE14E26DCD981EE1C37FE74DF626CC7EC1F84E5AE163A10570794B903A99DB92F996F9DE346A688A55DC36BB7269D5862
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13303016108093578","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):270336
                                                                    Entropy (8bit):0.0012471779557650352
                                                                    Encrypted:false
                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):420
                                                                    Entropy (8bit):4.985305467053914
                                                                    Encrypted:false
                                                                    SSDEEP:6:YHpoNXR8+eq7JdV5qQlsDHF4xj70PpqQEsDHF4R8HLJ2AVQBR70S7PMVKJw1K3Ky:YHO8sdBsB6MAsBdLJlyH7E4f3K33y
                                                                    MD5:C401B619D9D8E0ADABC25A47EE49CFBA
                                                                    SHA1:C9D3B816DD3FBCD98E9C0A32CEC7B501EFC0BBDA
                                                                    SHA-256:8F5D75F5EF9876E8D30CE477509F735B50C4D87DBEDB433BE8EDBE6D4B3CB82F
                                                                    SHA-512:BC12F16CB95CB0AD708C6BBD005EF863A8552613E612F1084086E0F8262752E1B5144D044F0D141CE8462CC33343C36B517A5CC778751680485D8F88FB51B862
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[50],"expiration":"13248543490879170","port":443,"protocol_str":"quic"},{"advertised_versions":[73],"expiration":"13248543490879171","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://dns.google","supports_spdy":true}],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):420
                                                                    Entropy (8bit):4.985305467053914
                                                                    Encrypted:false
                                                                    SSDEEP:6:YHpoNXR8+eq7JdV5qQlsDHF4xj70PpqQEsDHF4R8HLJ2AVQBR70S7PMVKJw1K3Ky:YHO8sdBsB6MAsBdLJlyH7E4f3K33y
                                                                    MD5:C401B619D9D8E0ADABC25A47EE49CFBA
                                                                    SHA1:C9D3B816DD3FBCD98E9C0A32CEC7B501EFC0BBDA
                                                                    SHA-256:8F5D75F5EF9876E8D30CE477509F735B50C4D87DBEDB433BE8EDBE6D4B3CB82F
                                                                    SHA-512:BC12F16CB95CB0AD708C6BBD005EF863A8552613E612F1084086E0F8262752E1B5144D044F0D141CE8462CC33343C36B517A5CC778751680485D8F88FB51B862
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[50],"expiration":"13248543490879170","port":443,"protocol_str":"quic"},{"advertised_versions":[73],"expiration":"13248543490879171","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://dns.google","supports_spdy":true}],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):16
                                                                    Entropy (8bit):3.2743974703476995
                                                                    Encrypted:false
                                                                    SSDEEP:3:1sjgWIV//Rv:1qIFJ
                                                                    MD5:6752A1D65B201C13B62EA44016EB221F
                                                                    SHA1:58ECF154D01A62233ED7FB494ACE3C3D4FFCE08B
                                                                    SHA-256:0861415CADA612EA5834D56E2CF1055D3E63979B69EB71D32AE9AE394D8306CD
                                                                    SHA-512:9CFD838D3FB570B44FC3461623AB2296123404C6C8F576B0DE0AABD9A6020840D4C9125EB679ED384170DBCAAC2FA30DC7FA9EE5B77D6DF7C344A0AA030E0389
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:MANIFEST-000004.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):16
                                                                    Entropy (8bit):3.2743974703476995
                                                                    Encrypted:false
                                                                    SSDEEP:3:1sjgWIV//Rv:1qIFJ
                                                                    MD5:6752A1D65B201C13B62EA44016EB221F
                                                                    SHA1:58ECF154D01A62233ED7FB494ACE3C3D4FFCE08B
                                                                    SHA-256:0861415CADA612EA5834D56E2CF1055D3E63979B69EB71D32AE9AE394D8306CD
                                                                    SHA-512:9CFD838D3FB570B44FC3461623AB2296123404C6C8F576B0DE0AABD9A6020840D4C9125EB679ED384170DBCAAC2FA30DC7FA9EE5B77D6DF7C344A0AA030E0389
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:MANIFEST-000004.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):17702
                                                                    Entropy (8bit):5.577115110295432
                                                                    Encrypted:false
                                                                    SSDEEP:384:+joteLlzIX61kXqKf/pUZNCgVLH2HfDhrUURTQVEg44:MLlm61kXqKf/pUZNCgVLH2HfNrUURsV1
                                                                    MD5:8EE14B94B12258B41CE612ECCBB14CD0
                                                                    SHA1:7D6DB722D4D05BA6051DCE2269354EF0DEB02FD5
                                                                    SHA-256:29F2220A2CD46FFFC73997B5EE941C6563DE689BF8F7E6E9C4A064A09C214B08
                                                                    SHA-512:AD606C1B56032E911CA93D3662BEC201CBB1EB8ECF3374C3CA007AD999D12F4A9B3BE075F744732175B8F16DD346745A945DECA4B7BB3F18FAA2258414CE9FB5
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"download":{"always_open_pdf_externally":true,"directory_upgrade":true,"extensions_to_open":"pdf:doc:docx:docxm:docm:xls:xlsx:xlsxm:xlsm:ppt:pptx:pptxm:pptm:mht:rtf:pub:vsd:mpp:mdb:dot:dotm:xlsb:xll:hwp:show:cell:hwpx:hwt:jtd:zip:iso:7z:rar:tar:vbs:js:jse:vbe:exe:html:htm:xhtml:tbz2:lz"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13303016108093578","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_i
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):106
                                                                    Entropy (8bit):3.138546519832722
                                                                    Encrypted:false
                                                                    SSDEEP:3:tbloIlrJ5ldQxl7aXVdJiG6R0RlAl:tbdlrnQxZaHIGi0R6l
                                                                    MD5:DE9EF0C5BCC012A3A1131988DEE272D8
                                                                    SHA1:FA9CCBDC969AC9E1474FCE773234B28D50951CD8
                                                                    SHA-256:3615498FBEF408A96BF30E01C318DAC2D5451B054998119080E7FAAC5995F590
                                                                    SHA-512:CEA946EBEADFE6BE65E33EDFF6C68953A84EC2E2410884E12F406CAC1E6C8A0793180433A7EF7CE097B24EA78A1FDBB4E3B3D9CDF1A827AB6FF5605DA3691724
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e...e.x.e.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):13
                                                                    Entropy (8bit):2.8150724101159437
                                                                    Encrypted:false
                                                                    SSDEEP:3:Yx7:4
                                                                    MD5:C422F72BA41F662A919ED0B70E5C3289
                                                                    SHA1:AAD27C14B27F56B6E7C744A8EC5B1A7D767D7632
                                                                    SHA-256:02E71EB4C587FEB7EE00CE8600F97411C2774C2FC34CB95B92D5538E7F30DA59
                                                                    SHA-512:86010ED2B2EEBDCC5A8A076B37703669C294C6D1BFAAEA963E26A9C94B81B4C53EC765D9425E5B616159C43923F800A891F9B903659575DF02F8845521F8DC46
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:85.0.4183.121
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):215348
                                                                    Entropy (8bit):6.07087747126387
                                                                    Encrypted:false
                                                                    SSDEEP:6144:Q/MqLHWLJ5QQlBDjRFrGU4OCUaqfIlUOoSiuRr:Q/zzgD9l1jAzow
                                                                    MD5:7D19236E7ADDB8BE6D5574FD0F0EEB51
                                                                    SHA1:E083DC39A70F5ACF0366BB5AE2051BE5082ABB53
                                                                    SHA-256:5D09D9395996519785325BF0658418A4839EC2B6DE8116039A4B7082948876CF
                                                                    SHA-512:A65E65D3A65404BEC79745665FF76DC1F1E497767BA56F02F17DFD0DA22E2DFAFB7155DF0545B956B7CBA94BDFDB0E83A9486613206A19F216C4373BFA9A0010
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.658542510416211e+12,"network":1.658510111e+12,"ticks":119391173.0,"uncertainty":3961078.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13291230639114408"},"plugins":{"metadata":{"adobe-flash-player":{"disp
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:SysEx File -
                                                                    Category:dropped
                                                                    Size (bytes):94708
                                                                    Entropy (8bit):3.7487272926378195
                                                                    Encrypted:false
                                                                    SSDEEP:384:9JpVOzvV2YdC15VC4fmN/rcvrx3crpsHFEGQvrqVLXxsJJxIrCTmqN2hfDX0Op5X:JOCFdO9IwQe3vVl0fLKtKbd/dV
                                                                    MD5:E9F728515EFAE8E220F0ED1322C08CFA
                                                                    SHA1:59D2ECF5CB0E2D3E9A464926BE5EAF50E3233ECE
                                                                    SHA-256:EE88BC171093EDFD8C1D919243483C0E958B2FBB66565317B16F78DE9E43331D
                                                                    SHA-512:CF86DA206650CBBAE84050F14285BA3C0343D98AEEFE777D8C5D013F6BAF27F8B6F2FC07FDD2062E6A4D2101DBB21602F8E2041F4008624F65D25695CA5F4C5B
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.q..............*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L..P!...[)...%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .o.f.f.i.c.e.\.o.f.f.i.c.e.1.6.\.......g.r.o.o.v.e.e.x...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .2.0.1.6...*...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .f.o.r. .B.u.s.i.n.e.s.s. .E.x.t.e.n.s.i.o.n.s.....1.6...0...4.7.1.1...1.0.0.0.....*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n....b8.D...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.C.o.m.m.o.n. .F.i.l.e.s.\.M.i.c.r.o.s.o.f.t. .S.h.a.r.e.d.\.O.F.F.I.C.E.1.6.\.m.s.o.s.h.e.x.t...d.l.l..@.....U/...%.c.o.m.m.o.n.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .s.h.a.r.e.d.\.o.f.f.i.c.e.1.6.\.......m.s.o.s.h.e.x.t...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.)...M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n. .H.a.n.d.l.e.r.s.......1.6...0...4.2.6.6...1.0.0.1.....D...C.:.\.P.r.o.g.r.a.m.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:SysEx File -
                                                                    Category:dropped
                                                                    Size (bytes):94708
                                                                    Entropy (8bit):3.7487272926378195
                                                                    Encrypted:false
                                                                    SSDEEP:384:9JpVOzvV2YdC15VC4fmN/rcvrx3crpsHFEGQvrqVLXxsJJxIrCTmqN2hfDX0Op5X:JOCFdO9IwQe3vVl0fLKtKbd/dV
                                                                    MD5:E9F728515EFAE8E220F0ED1322C08CFA
                                                                    SHA1:59D2ECF5CB0E2D3E9A464926BE5EAF50E3233ECE
                                                                    SHA-256:EE88BC171093EDFD8C1D919243483C0E958B2FBB66565317B16F78DE9E43331D
                                                                    SHA-512:CF86DA206650CBBAE84050F14285BA3C0343D98AEEFE777D8C5D013F6BAF27F8B6F2FC07FDD2062E6A4D2101DBB21602F8E2041F4008624F65D25695CA5F4C5B
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.q..............*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L..P!...[)...%.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .o.f.f.i.c.e.\.o.f.f.i.c.e.1.6.\.......g.r.o.o.v.e.e.x...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .2.0.1.6...*...M.i.c.r.o.s.o.f.t. .O.n.e.D.r.i.v.e. .f.o.r. .B.u.s.i.n.e.s.s. .E.x.t.e.n.s.i.o.n.s.....1.6...0...4.7.1.1...1.0.0.0.....*...C.:.\.P.R.O.G.R.A.~.1.\.M.I.C.R.O.S.~.1.\.O.f.f.i.c.e.1.6.\.G.R.O.O.V.E.E.X...D.L.L.....M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n....b8.D...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.C.o.m.m.o.n. .F.i.l.e.s.\.M.i.c.r.o.s.o.f.t. .S.h.a.r.e.d.\.O.F.F.I.C.E.1.6.\.m.s.o.s.h.e.x.t...d.l.l..@.....U/...%.c.o.m.m.o.n.p.r.o.g.r.a.m.f.i.l.e.s.%.\.m.i.c.r.o.s.o.f.t. .s.h.a.r.e.d.\.o.f.f.i.c.e.1.6.\.......m.s.o.s.h.e.x.t...d.l.l.....M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.)...M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e. .S.h.e.l.l. .E.x.t.e.n.s.i.o.n. .H.a.n.d.l.e.r.s.......1.6...0...4.2.6.6...1.0.0.1.....D...C.:.\.P.r.o.g.r.a.m.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):215348
                                                                    Entropy (8bit):6.0708781200788495
                                                                    Encrypted:false
                                                                    SSDEEP:6144:fMqLHWLJ5QQlBDjRFrGU4OCUaqfIlUOoSiuRr:fzzgD9l1jAzow
                                                                    MD5:31D26DCA2E7EB06C66E37A00A2FD632A
                                                                    SHA1:892E2C3799D9433213CF07D86575EA1AE63E6FC6
                                                                    SHA-256:EE64291CFADBD9B7D8CA56ECCC6AD472562EB6155139B7EBB272789B2047B32D
                                                                    SHA-512:33B235B7BAA8C8C7CED5E1C50670796E38465F1BB93C217F9417B02D0D8DCDBE3BF0217AB6DE662C15F488B2C5923193FF7D7BF81ED9FCDB207A74C40317EF61
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.658542510416211e+12,"network":1.658510111e+12,"ticks":119391173.0,"uncertainty":3961078.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13245951016607996"},"plugins":{"metadata":{"adobe-flash-player":{"disp
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:Google Chrome extension, version 3
                                                                    Category:dropped
                                                                    Size (bytes):248531
                                                                    Entropy (8bit):7.963657412635355
                                                                    Encrypted:false
                                                                    SSDEEP:3072:r+nmRykNgoldZ8GjJCiUXZSk+QSVh85PxEalRVHmcld9R6yYfEp4ABUGDcaKklrv:k3oF4Z4h45P99Fld9RBQYBVcaxlnfL
                                                                    MD5:541F52E24FE1EF9F8E12377A6CCAE0C0
                                                                    SHA1:189898BB2DCAE7D5A6057BC2D98B8B450AFAEBB6
                                                                    SHA-256:81E3A4D43A73699E1B7781723F56B8717175C536685C5450122B30789464AD82
                                                                    SHA-512:D779D78A15C5EFCA51EBD6B96A7CCB6D718741BDF7D9A37F53B2EB4B98AA1A78BC4CFA57D6E763AAB97276C8F9088940AC0476690D4D46023FF4BF52F3326C88
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:Cr24..............0.."0...*.H.............0...........\7c.<........Fto.8.2'5..qk...%....2...C.F.9.#..e.xQ.......[...L|....3>/....u.:T.7...(.yM...?V.<?........1.a...O?d.....A.H..'.MpB..T.m..Vn Ip..>k.|1..n.<Fb..f..*Q1.....s..2..{*.6....Pp....obM..1.......b1.......(.u^.'z......v.F.W.X4."-*eu...b.........\..F!...b...l5....zJ.q.......L].....w[T0.6....E.....r..%Z.vFm.9..5!,.~g5...;.t...']....+A.....u....k...e..&..l.6r[yU...%..f.......N..V.....<+.....l..}.{...z...)y.n..'..).....,.b....5.08K%..O.g..D.S.F5o..<(....>....\f..X..I..2."l...w....7f|.~.c.4.E.......0..0...*.H............0.......).'..b.*$w\$.q&.]zF_2..;...?.U,...W..L1.2...R..#....W.....c1k.$W..$.J....+M!.Hz.n`U.I)N.|b.l....{.K@]6.LlP/....](.A..................I...).H....IQ.y.;MG.d..ix..#f.Z$|..|.?...0K...t"i..s...Y..%.Ky....0...{.!+.~v.;....J.....Z....).(6..@?v.;~..2..c....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. .0...|!..A..L.+.=...kP.!.1..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:very short file (no magic)
                                                                    Category:dropped
                                                                    Size (bytes):1
                                                                    Entropy (8bit):0.0
                                                                    Encrypted:false
                                                                    SSDEEP:3:L:L
                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:Google Chrome extension, version 3
                                                                    Category:dropped
                                                                    Size (bytes):248531
                                                                    Entropy (8bit):7.963657412635355
                                                                    Encrypted:false
                                                                    SSDEEP:3072:r+nmRykNgoldZ8GjJCiUXZSk+QSVh85PxEalRVHmcld9R6yYfEp4ABUGDcaKklrv:k3oF4Z4h45P99Fld9RBQYBVcaxlnfL
                                                                    MD5:541F52E24FE1EF9F8E12377A6CCAE0C0
                                                                    SHA1:189898BB2DCAE7D5A6057BC2D98B8B450AFAEBB6
                                                                    SHA-256:81E3A4D43A73699E1B7781723F56B8717175C536685C5450122B30789464AD82
                                                                    SHA-512:D779D78A15C5EFCA51EBD6B96A7CCB6D718741BDF7D9A37F53B2EB4B98AA1A78BC4CFA57D6E763AAB97276C8F9088940AC0476690D4D46023FF4BF52F3326C88
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:Cr24..............0.."0...*.H.............0...........\7c.<........Fto.8.2'5..qk...%....2...C.F.9.#..e.xQ.......[...L|....3>/....u.:T.7...(.yM...?V.<?........1.a...O?d.....A.H..'.MpB..T.m..Vn Ip..>k.|1..n.<Fb..f..*Q1.....s..2..{*.6....Pp....obM..1.......b1.......(.u^.'z......v.F.W.X4."-*eu...b.........\..F!...b...l5....zJ.q.......L].....w[T0.6....E.....r..%Z.vFm.9..5!,.~g5...;.t...']....+A.....u....k...e..&..l.6r[yU...%..f.......N..V.....<+.....l..}.{...z...)y.n..'..).....,.b....5.08K%..O.g..D.S.F5o..<(....>....\f..X..I..2."l...w....7f|.~.c.4.E.......0..0...*.H............0.......).'..b.*$w\$.q&.]zF_2..;...?.U,...W..L1.2...R..#....W.....c1k.$W..$.J....+M!.Hz.n`U.I)N.|b.l....{.K@]6.LlP/....](.A..................I...).H....IQ.y.;MG.d..ix..#f.Z$|..|.?...0K...t"i..s...Y..%.Ky....0...{.!+.~v.;....J.....Z....).(6..@?v.;~..2..c....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. .0...|!..A..L.+.=...kP.!.1..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):796
                                                                    Entropy (8bit):4.864931792423268
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJMLkSlwZGGMLkSlwZ+WYpU34f145Gb+dgoxTyO8ZpU34f1L0frhmJ03OyZnLt:1HE7n4gn8WYpYrbhz8ZpotHOGAOf6aD
                                                                    MD5:6F8E288A9AD5B1ED8633B430E2B4D4CA
                                                                    SHA1:F671D3D4BEFA431D1946D706F4192D44E29B6F08
                                                                    SHA-256:A114E2783D0E9B12155017323BA70838F0F82A71C7EE8DC1F115AE36991241F8
                                                                    SHA-512:0F87F3F0D115B872288949E59ACD3CD41B1FBC64A622D8FDA6D71FAFC5A900D92ADFBB0E7EB926F2A8759BBAA0896D48728FB719BBF5EF54AC21027328F7700C
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "........ . ... ........ .. Chrome".. },.. "app_name": {.. "message": "........ . ... ........ .. Chrome".. },.. "craw_app_unavailable": {.. "message": "........... .... ...... .. .............".. },.. "craw_connect_to_network": {.. "message": "...., ........ .. . ......".. },.. "iap_unavailable": {.. "message": "........... .... ...... .. .......... ....... .. .........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "...., ...... . Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):675
                                                                    Entropy (8bit):4.536753193530313
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ0gbbGG0gbb+WYpU34g3YbiLO+dgyGFoO8ZpU34+puiPmb03OyZnLAOfTYABk:1HE5baib6WYpm31Lt0Z8Zp8pxOGAOfKD
                                                                    MD5:1FDAFC926391BD580B655FBAF46ED260
                                                                    SHA1:C95743C3F43B2B099FEBEBC5BD850F0C20E820AC
                                                                    SHA-256:C67898B67F9C9209EAFDA6532B62D5789863CFB855998DD6A70E7775316CEC20
                                                                    SHA-512:39D95D45C5746DA3BAA7AE6A3344EA17D7A7C3569C2A56959FF119261DA08C747A320FCF701AC72B8DBDBF8BF06FD8B239017A282CDDA444F3826D4EC672CBB4
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Ara mateix aquesta aplicaci. no est. disponible.".. },.. "craw_connect_to_network": {.. "message": "Connecteu-vos a una xarxa.".. },.. "iap_unavailable": {.. "message": "La funci. Pagaments a l'aplicaci. no est. disponible actualment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicieu la sessi. a Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):641
                                                                    Entropy (8bit):4.698608127109193
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJfZGGfZ+WYpU34OBh+dgN/O8ZpU34j05U03OyZnLAOfTYWc:1HEl4G8WYpdt8Zpq5TOGAOfW
                                                                    MD5:76DEC64ED1556180B452A13C83171883
                                                                    SHA1:CFB1E56FD587BCDC459C1D9A683B71F9849058F9
                                                                    SHA-256:32290D69A90E6BAAC428B10382C99221B12773BB9A184F3B93DFB48A4F6D7A40
                                                                    SHA-512:5230A217968D5DC463E2E92D704544311A721E5CEF65C3125CBD8DEB9C0293D3BFB5C820A6011ABF77095FDEE7DAF67D541DC202B0C9CDB0908CBB85D84885CB
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "app_name": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikace v sou.asn. dob. nen. dostupn..".. },.. "craw_connect_to_network": {.. "message": "P.ipojte se pros.m k s.ti.".. },.. "iap_unavailable": {.. "message": "Platby v aplikaci aktu.ln. nejsou k dispozici.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "P.ihlaste se do Chromu.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):624
                                                                    Entropy (8bit):4.5289746475384565
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJJMKKFZGGJMKKFZ+WYpU34OHu+dgxlCZO8ZpU34J4Wu03OyZnLAOfTYzD:1HErMKfqMKVWYpM6lL8ZpDNOGAOfiD
                                                                    MD5:238B97A36E411E42FF37CEFAF2927ED1
                                                                    SHA1:4E47AC90BA24C8F4724D9293FA40CFD4ADA66FE0
                                                                    SHA-256:4977D4A053542FF66967FAED6B06585DD70E68E20BFEB533B66FE3287F9655D9
                                                                    SHA-512:FD0742D47B5F5AB9AAD9B4C3D57F63CB693E060EECE123A72036C6E92156D099495C7E9E9CC6DC83EEBCDDCC4B4C81FB47E4C9559DA3EBA024780FFF10C53E0A
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Betalinger i Chrome Webshop".. },.. "app_name": {.. "message": "Betalinger i Chrome Webshop".. },.. "craw_app_unavailable": {.. "message": "Appen er ikke tilg.ngelig i .jeblikket.".. },.. "craw_connect_to_network": {.. "message": "Opret forbindelse til et netv.rk.".. },.. "iap_unavailable": {.. "message": "Betaling i appen er ikke tilg.ngelig i .jeblikket.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Log ind p. Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):651
                                                                    Entropy (8bit):4.583694000020627
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJQ1ZGGQ1Z+WYpU34pCEMT+dgJMlCTO8ZpU34p6FK603OyZnLAOfTYJ6K:1HEzWWYp3Bewv8Zp7k4OGAOfQj
                                                                    MD5:6B3E916E8C1991AA0453CBA00FEDCAAA
                                                                    SHA1:D6366D15912E40CA107FD42BFE9579C3336A51F9
                                                                    SHA-256:A62FFAB910E31531758EEE48B2CC71A8857BEC3021DEAD50B668CBA3C8667053
                                                                    SHA-512:87EA4311B61F29543B13F3E17DFA919D0C320B4FE370CC152E0B1514BCA79B0ABB526DDCF08621D6EBFA48923EE8FB4C667EFB120A72BD9583EEBEE7BFB80552
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Web Store-Zahlungen".. },.. "app_name": {.. "message": "Chrome Web Store-Zahlungen".. },.. "craw_app_unavailable": {.. "message": "Die App ist momentan nicht verf.gbar.".. },.. "craw_connect_to_network": {.. "message": "Bitte stellen Sie eine Verbindung zu einem Netzwerk her.".. },.. "iap_unavailable": {.. "message": "In-App-Zahlungen sind momentan nicht m.glich.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Bitte melden Sie sich in Chrome an.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):787
                                                                    Entropy (8bit):4.973349962793468
                                                                    Encrypted:false
                                                                    SSDEEP:24:1HEw+aZ+6WYpbWZe80A08ZpCGyDVWlOGAOf+XD:WguYpCZnpEZbGoD
                                                                    MD5:05C437A322C1148B5F78B2F341339147
                                                                    SHA1:AB53003A678E44A170E73711FBD9949833BBF3AA
                                                                    SHA-256:A052C32B4FCAC61152EB0ADB2C260FB6A8256AD104AA0013DB93E9798D41A070
                                                                    SHA-512:C36CB9202A34356DD06D377E2A088F428D0B8EBE7D2E54F8380485E9D94A0598D7F651C1E7A2FD55BE481D49C02B0812F2BA335E08611EC85EE0BD60784A6B40
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "........ ... Chrome Web Store".. },.. "app_name": {.. "message": "........ ... Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": ". ........ .... .. ..... ... ..... ..........".. },.. "craw_connect_to_network": {.. "message": ".......... .. ... .......".. },.. "iap_unavailable": {.. "message": ".. ........ ..... ......... ... ..... ..... .. ...... ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": ".......... ... Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):593
                                                                    Entropy (8bit):4.483686991119526
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                                                    MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                                                    SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                                                    SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                                                    SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):593
                                                                    Entropy (8bit):4.483686991119526
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                                                    MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                                                    SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                                                    SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                                                    SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):661
                                                                    Entropy (8bit):4.450938335136508
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34lPbdlVo03OyZnLAOfTY6xjD:1HEvaC6WYpcDeEFxq8ZpNl5OGAOffD
                                                                    MD5:82719BD3999AD66193A9B0BB525F97CD
                                                                    SHA1:41194D511F1ACC16C1CA828AC81C18C8C6B47287
                                                                    SHA-256:4DB9B2721E625C18B9E05C04B31AF5D9694712F1CAAF6219ABE34BB08E5DB1C7
                                                                    SHA-512:D4C49B43427799B6292CEED11CACB1D76F7CE43EBF402B43B638A6EB2B414ED0981E386CB8CDF0B51D1BD9552934FE25B2F6392266BB73D8C9A691F65BCE0128
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "Los pagos en la aplicaci.n no est.n disponibles en este momento.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicia sesi.n en Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):637
                                                                    Entropy (8bit):4.47253983486615
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34GLO03OyZnLAOfTYiJD:1HEvaC6WYpcDeEFxq8Zp4LlOGAOfvD
                                                                    MD5:6B2583D8D1C147E36A69A88009CBEBC7
                                                                    SHA1:4D4DEEB4BE6AA0181825F3371A761ABC5B4D5937
                                                                    SHA-256:6659BC3705311D7641A73995DCFEA80C7734F2F4EBBC3787B3892A240348324F
                                                                    SHA-512:37F0DBFCC1B5A2B8E4C92C49D2D9DEEF25616421350324F57E0149A45A6CCB437F5E3CBE97412C4B5DBBF2593783C7DF71E9C25A851AEAE6E4764C545723FA53
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "En este momento, Pagos En-Apps no est. disponible.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Accede a Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):595
                                                                    Entropy (8bit):4.467205425399467
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJfPGGGfPG+WYpU34Ze7z+dgrW9O8ZpU34ZwZz03OyZnLAOfTYgoLIR:1HEdvqlWYpTeObk8ZpT/OGAOfuLIR
                                                                    MD5:CFF6CB76EC724B17C1BC920726CB35A7
                                                                    SHA1:14ED068251D65A840F00C05409D705259D329FFC
                                                                    SHA-256:C85800BF45942FCC7FD6B1DF929C25F9CC2A977A6678966BD03D4B6B69889AFD
                                                                    SHA-512:53D7D01BB30C0306DE65A79FD9551D2E8C1F71F4F45F71906B009071CB3E0F231E6A50FDD78773E9B4DE94085BC7B97F829842FA21A89A2080D33458B745C46F
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome'i veebipoe maksed".. },.. "app_name": {.. "message": "Chrome'i veebipoe maksed".. },.. "craw_app_unavailable": {.. "message": "Rakendus pole praegu saadaval.".. },.. "craw_connect_to_network": {.. "message": "Looge .hendus v.rguga.".. },.. "iap_unavailable": {.. "message": "Rakendusesisesed maksed ei ole praegu saadaval.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Logige Chrome'i sisse.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):647
                                                                    Entropy (8bit):4.595421267152647
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJRuzGGRuz+WYpU34ujSBu+dgYO8ZpU34J+Bu03OyZnLAOfTY5HN:1HEFcWYpPNa8ZpD+FOGAOfEHN
                                                                    MD5:3A01FEE829445C482D1721FF63153D16
                                                                    SHA1:F3EAAADDC03F943FC88B30B67F534AA13E3336DD
                                                                    SHA-256:0BDE54B20845124113383B6EB81E43A0F05E4EB0C44BEE3C1DFAC4CC5FEC2836
                                                                    SHA-512:3B92B6C86D30FD36AA3CEFF8773BA60C3FC5CC19C693540137044C5838A5503895C770C0336A4D0A3DB5E42F3FB36274D8D3F85B9DCA2F3EC0E974FDDB0BEAD8
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Web Storen maksut".. },.. "app_name": {.. "message": "Chrome Web Storen maksut".. },.. "craw_app_unavailable": {.. "message": "Sovellus ei ole t.ll. hetkell. k.ytett.viss..".. },.. "craw_connect_to_network": {.. "message": "Muodosta verkkoyhteys.".. },.. "iap_unavailable": {.. "message": "Sovelluksen sis.iset maksut eiv.t ole t.ll. hetkell. k.ytett.viss..".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Kirjaudu sis..n Chromeen.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):658
                                                                    Entropy (8bit):4.5231229502550745
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJADlbGGADlb+WYpU34hTUT+dgHfZAFFZO8ZpU34hTjzeT03OyZnLAOfTYHfvF:1HEYah6WYp7TUSoxOS8Zp7TOsOGAOfqV
                                                                    MD5:57AF5B654270A945BDA8053A83353A06
                                                                    SHA1:EEEF7A4F869F97CF471A05D345E74F982D15E167
                                                                    SHA-256:EC002ED92359F67818B49455DFC579E140368E6A004080AF022FD4F57F6B03F2
                                                                    SHA-512:5F0AE839FCF3F4EA48FF41A76655AE0F3821564AFD5D42FBB9FBB9A38E8D8F7BB5E9B6F71064588CD441261F644095A44A755C134CE546D506D9A21E488BAF52
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "app_name": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Kasalukuyang hindi available ang app.".. },.. "craw_connect_to_network": {.. "message": "Mangyaring kumonekta sa isang network.".. },.. "iap_unavailable": {.. "message": "Kasalukuyang hindi available ang Mga Pagbabayad na In-App.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Mangyaring mag-sign in sa Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):677
                                                                    Entropy (8bit):4.552569602149629
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJALf/nbGGALf/nb+WYpU34Owdgbyb+dgdQjO8ZpU34ITQpGnbyb03OyZnLAO8:1HE4Hna1Hn6WYpNdgpY8ZpSTQwnBOGAh
                                                                    MD5:8D11C90F44A6585B57B933AB38D1FFF8
                                                                    SHA1:3F9D44EA8807069A32AACA2AAAD02FD892E6CC90
                                                                    SHA-256:599491F8C52B945C16C441ADF45BFD45AFAE046DA07757D97C56AF4DE75ED3B5
                                                                    SHA-512:D7EF7F5AD7EF1A1595825D79B69E2B1E988AD3CF1F3881496FCCD30F241E4E9C6E457F9F5D0F855DE3536DB7A40C3E1C55946B50D3F556F4A35285066A0CD6F7
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "app_name": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "craw_app_unavailable": {.. "message": "Application indisponible pour le moment.".. },.. "craw_connect_to_network": {.. "message": "Veuillez vous connecter . un r.seau.".. },.. "iap_unavailable": {.. "message": "Les paiements via l'application ne sont pas disponibles pour le moment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Veuillez vous connecter . Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):835
                                                                    Entropy (8bit):4.791154467711985
                                                                    Encrypted:false
                                                                    SSDEEP:24:1HEs07J0JWYp9vnCSVLP8Zp6CsOGAOf8SLm:Wh7qgYp1CMLUph1GiSLm
                                                                    MD5:E376D757C8FD66AC70A7D2D49760B94E
                                                                    SHA1:1525C5B1312D409604F097768503298EC440CC4D
                                                                    SHA-256:8106D98C4F8DA16DB698444409558E29CC96735E188BFA303C333A5D99231C1D
                                                                    SHA-512:673F3F259AF2946E4F49BBED14A2A70D44BF9FDA9D7A71DC9172BA9B7B3C7F7062B16D29682B638D485B0520ED6F99E7A735F28C7C719B539559005B69FA7555
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome ... ..... ......".. },.. "app_name": {.. "message": "Chrome ... ..... ......".. },.. "craw_app_unavailable": {.. "message": "......... .. ... ...... .... ...".. },.. "craw_connect_to_network": {.. "message": "..... ....... .. ...... .....".. },.. "iap_unavailable": {.. "message": "..-.. ...... ... ...... .... ...".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "..... Chrome ... .... .. .....".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):618
                                                                    Entropy (8bit):4.56999230891419
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJGiimxmbZGGGiimxmbZ+WYpU34OBOEuhopIO+dgcapZO8ZpU34GiiZrMrQphK:1HE4H4TH8WYpNjTta28ZpQVLP0SOGAOK
                                                                    MD5:8185D0490C86363602A137F9A261CC50
                                                                    SHA1:5BD933B874441CEACB9201CCC941FF67BAED6DC0
                                                                    SHA-256:A2B2EC359A9DD9DCCCE02859CE1E738BD30FAA4A05F1DC522893FFDF722BBC15
                                                                    SHA-512:D7629978FC031EA5F716F9C1065FB2FEAB48C15F10CD68830DC966FA1002C03DDC7ACDE314C7D075F9F3A0A68552A6ACBCCDEE24CF20B6C3DD1BCE6562D0396E
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "app_name": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikacija trenuta.no nije dostupna.".. },.. "craw_connect_to_network": {.. "message": "Pove.ite se s mre.om.".. },.. "iap_unavailable": {.. "message": "Pla.anje u aplikaciji trenuta.no nije dostupno.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prijavite se na Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):683
                                                                    Entropy (8bit):4.675370843321512
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJVJiGGVJi+WYpU34Hpo9O+dgMmfgijO8ZpU34Huo9O03OyZnLAOfTYBIAYm:1HEVrk5WYpQzTUg/8ZpwoXOGAOfYIAd
                                                                    MD5:85609CF8623582A8376C206556ED2131
                                                                    SHA1:1E16EB70DB5E59BB684866FF3E3925C2DEF25A12
                                                                    SHA-256:32A249749F12ADB6A220BF9ADC272C7E5D9AD5497A38B0086D961E3ABA17FBC6
                                                                    SHA-512:27883430865D3CFA6EDFE8C6CE1442BD96150B5CE520CCF7D556A330CAA6392C712B47BD86F7350E174876BC681F6DEC94D1312402655B0AF90883A2899EC78B
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "app_name": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "craw_app_unavailable": {.. "message": "Az alkalmaz.s jelenleg nem .rhet. el.".. },.. "craw_connect_to_network": {.. "message": "K.rj.k, csatlakozzon egy h.l.zathoz.".. },.. "iap_unavailable": {.. "message": "Az alkalmaz.son bel.li fizet.s jelenleg nem .rhet. el.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Jelentkezzen be a Chrome-ba.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):604
                                                                    Entropy (8bit):4.465685261172395
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJs25bGGs25b+WYpU34ORBHAeSJ+dgkmO8ZpU34s22C/SzFAs03OyZnLAOfTYR:1HEBaA6WYpaHFH8ZptOYOGAOf2D
                                                                    MD5:EAB2B946D1232AB98137E760954003AA
                                                                    SHA1:60BDC2937905B311D2C9844DF2D639D7AC9F7F67
                                                                    SHA-256:C6E8800450602DE0F39FE9F6854472383813FB454B08ABAE7E25A9167CE004C3
                                                                    SHA-512:970FEC9A9EF0BAF7F693C4C5977F3B47914579C5B5414FCE9DBB5E4574659A5BB9AD2DE0CC886B368F49C019785AF7D2D7FE82F71341F039EADC399ED776CA12
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pembayaran Chrome Webstore".. },.. "app_name": {.. "message": "Pembayaran Chrome Webstore".. },.. "craw_app_unavailable": {.. "message": "Aplikasi tidak tersedia saat ini.".. },.. "craw_connect_to_network": {.. "message": "Sambungkan ke jaringan.".. },.. "iap_unavailable": {.. "message": "Pembayaran Dalam Aplikasi saat ini tidak tersedia.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Harap masuk ke Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):603
                                                                    Entropy (8bit):4.479418964635223
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJsqd/bGGsqd/b+WYpU34OcX4+dgUvIO8ZpU34vq703OyZnLAOfTYsD:1HEXd/aKd/6WYpZrv58ZpskOGAOfzD
                                                                    MD5:A328EEF5E841E0C72D3CD7366899C5C8
                                                                    SHA1:2851ED658385804E87911643F5A4200B1FB26E13
                                                                    SHA-256:CD891C45F7586FB4A2514205A11F260E4A6D4482FA03D901909DD9F57BE0536D
                                                                    SHA-512:E47297896E981774EC3B59D41B89D6BA9333F6B4435EB9727D8645A46B10C7D408ADE06844871FA757382FBE7E645276449DB7B1B23BC59C9A71A5CB5A5ECC57
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pagamenti Chrome Web Store".. },.. "app_name": {.. "message": "Pagamenti Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "App al momento non disponibile.".. },.. "craw_connect_to_network": {.. "message": "Collegati a una rete.".. },.. "iap_unavailable": {.. "message": "La funzione Pagamenti In-App non . al momento disponibile.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Accedi a Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):697
                                                                    Entropy (8bit):5.20469020877498
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ07uGG07u+WYpU34DB+dgnsVztO8ZpU34MwiB03OyZnLAOfTYmSH:1HEcnDNWYp1kxU8Zp2wiqOGAOfpSH
                                                                    MD5:9B3A5D473C3F2BBFAEECE94A07A940B8
                                                                    SHA1:61BACA342CF766BBA15C7B4D892A0E7DAC9405AA
                                                                    SHA-256:706312A4A2AEF3317223F141EB2B82685345B7EED444F16BB4DF3A272716DA1F
                                                                    SHA-512:94F6FEE9A11BD890AB8211C98D1CC142348961EBCF756F66477A3E3A76519804B70BE0AE4E551739F8AFE32D7ADE6EDE04EF6B9B9EED03E3A857E6058EEDD4C6
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome ........".. },.. "app_name": {.. "message": "Chrome ........".. },.. "craw_app_unavailable": {.. "message": ".................".. },.. "craw_connect_to_network": {.. "message": "................".. },.. "iap_unavailable": {.. "message": ".......................".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Chrome ............".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):631
                                                                    Entropy (8bit):5.160315577642469
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ1GG1+WYpU34K3aT+dgh8d0HTO8ZpU34KaNkaT03OyZnLAOfTY/YeHx:1HEajWYpc3aSl0Hq8Zpc6kasOGAOfyYA
                                                                    MD5:9F6B4D82A70C74CA751E2EAE70FAB5CF
                                                                    SHA1:0534F125FFCE8222277CF2BE3401C59DAF9217F8
                                                                    SHA-256:D1467B8D037114403E8F4EFC52E88C4A7FEB96126BE4CFF883FEFF1084EF7E68
                                                                    SHA-512:ED9319830314385D09C06F62EE34186E8CA576C857981205E4468A28B3ACD2AB03384E77B866032C324ABDD97A56EFD08E2D6E0C79D563578B3EC52517819BD8
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome . ... ..".. },.. "app_name": {.. "message": "Chrome . ... ..".. },.. "craw_app_unavailable": {.. "message": ".. .. ... . .....".. },.. "craw_connect_to_network": {.. "message": "..... ......".. },.. "iap_unavailable": {.. "message": ".. .. ... ... . .....".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Chrome. .......".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):665
                                                                    Entropy (8bit):4.66839186029557
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJpqHnkGGpqHnk+WYpU346M+dgV6O8ZpU34WzSWz03OyZnLAOfTYx:1HELqHtKqHPWYpM3A8ZpwGzOGAOfg
                                                                    MD5:4CA644F875606986A9898D04BDAE3EA5
                                                                    SHA1:722A10569E93975129D67FBDB75B537D9D622AD1
                                                                    SHA-256:7C311AB751D840D750C11553C083785813E079C1D464FE568A98C9E3EF3DB96C
                                                                    SHA-512:E575E3D0622F5BD4B6C0EE79128A1B1F1882195670139D1983F4377D847141B8FB8EBB8BCED82AF3A220ED07D3577AFBE085BADC0E9C7678292B80E3EC5D3444
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": ".Chrome. internetin.s parduotuv.s mok.jimo sistema".. },.. "app_name": {.. "message": ".Chrome. internetin.s parduotuv.s mok.jimo sistema".. },.. "craw_app_unavailable": {.. "message": "Programa .iuo metu negalima.".. },.. "craw_connect_to_network": {.. "message": "Prisijunkite prie tinklo.".. },.. "iap_unavailable": {.. "message": "Mok.jimai programoje .iuo metu negalimi.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prisijunkite prie .Chrome..".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):671
                                                                    Entropy (8bit):4.631774066483956
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJFhVbGGFhVb+WYpU34wDoz+dgGedBO8ZpU34wF03OyZnLAOfTYGYID:1HENQKkWYp2Doy/em8Zp2WOGAOfRYID
                                                                    MD5:C5CE2C51391EAFD3DA9E4C71549A3C28
                                                                    SHA1:1F67FF6EF6E90C0CE3AAF56ED543A3EFD381574D
                                                                    SHA-256:1FA1DF2CA8516DEF490FB8484E9AA498ACFF80EEF5C9258FFE42D3678E6C7DED
                                                                    SHA-512:C85F6281E682F52BC2147DEA7E2F3BB4DC48D98BADA8687B05C6C7271C78EA7F5431CD51671A4184C9AE004FC53C016E3C594697F483195CCBA08A93821EEF70
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome interneta veikala maks.jumu sist.ma".. },.. "app_name": {.. "message": "Chrome interneta veikala maks.jumu sist.ma".. },.. "craw_app_unavailable": {.. "message": "Lietotne pagaid.m nav pieejama.".. },.. "craw_connect_to_network": {.. "message": "L.dzu, izveidojiet savienojumu ar t.klu.".. },.. "iap_unavailable": {.. "message": "Maks.jumi lietotn.s pa.laik nav pieejami.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "L.dzu, pierakstieties p.rl.k. Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):624
                                                                    Entropy (8bit):4.555032032637389
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJhiOGGhiO+WYpU34OHSN+dgFjdGFZO8ZpU34JgdN03OyZnLAOfTYiD:1HEDiHIitWYpCYJ8ZpD1OGAOfRD
                                                                    MD5:93C459A23BC6953FF744C35920CD2AF9
                                                                    SHA1:162F884972103A08ADB616A7EB3598431A2924C5
                                                                    SHA-256:2CD700AEB57D89C2E73333D0702556EE3FF3863516170F85669BC680FCBDC4E0
                                                                    SHA-512:F76E6E8D8499306883C3EC1E774F7E8BB6B601096DA5A14D17D3E7D5732829542041E42B7350466589291ADCC83FB065FD591B4E20CFCF8EDC586E128ECBFCB5
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Nettmarked-betalinger".. },.. "app_name": {.. "message": "Chrome Nettmarked-betalinger".. },.. "craw_app_unavailable": {.. "message": "Appen er utilgjengelig for .yeblikket.".. },.. "craw_connect_to_network": {.. "message": "Du m. koble til et nettverk.".. },.. "iap_unavailable": {.. "message": "Betaling i app er ikke tilgjengelig for .yeblikket.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Du m. logge p. Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):615
                                                                    Entropy (8bit):4.4715318546237315
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJJQGkbGGJQGkb+WYpU34OQKJT+dgiXUmvFZO8ZpU34g7JT03OyZnLAOfTYMD:1HErxkaqxk6WYptndXI8ZpTOGAOfbD
                                                                    MD5:7A8F9D0249C680F64DEC7650A432BD57
                                                                    SHA1:53477198AEE389F6580921B4876719B400A23CA1
                                                                    SHA-256:92BE7C2DC9CFBE5A65E9CE6488D364C8D7EC19E7B67A31E4D43C1CB2B169671C
                                                                    SHA-512:969AB979546A741C0F3EDBEEB21BABA375FA8870D4FB9248CDD4C305736E332E10CAB7B64C5C078E60EC0CD73848101B390BE8F44B89C310058AF4C1CA3C8AA7
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Betalingen via Chrome Web Store".. },.. "app_name": {.. "message": "Betalingen via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "App momenteel niet beschikbaar.".. },.. "craw_connect_to_network": {.. "message": "Maak verbinding met een netwerk.".. },.. "iap_unavailable": {.. "message": "In-app-betalingen is momenteel niet beschikbaar.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Log in bij Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):636
                                                                    Entropy (8bit):4.646901997539488
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJbiVbGGbiVb+WYpU34OBHlBi9+dgQUg6O8ZpU34bdbfiIu03OyZnLAOfTYR5k:1HE5iVauiV6WYpIAYr8ZpxFiaOGAOfIC
                                                                    MD5:0E6194126AFCCD1E3098D276A7400175
                                                                    SHA1:E8127B905A640B1C46362FA6E1127BE172F4A40F
                                                                    SHA-256:E2699F98C511B18A2AFB82EAE9A4804B646C4FF1077D80E77C17A3943A6373C2
                                                                    SHA-512:A71F7C7BFBBF1E37E699601AF2E095C56CBA91F90CB7556477DF31D01B83ADFB1271E1775C9BA299FF6875BBFC2B6AB47488CC88E33DEF2F6F2E0E5AC687B777
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "P.atno.ci w sklepie Chrome Web Store".. },.. "app_name": {.. "message": "P.atno.ci w sklepie Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplikacja jest obecnie niedost.pna.".. },.. "craw_connect_to_network": {.. "message": "Po..cz si. z sieci..".. },.. "iap_unavailable": {.. "message": "P.atno.ci w ramach aplikacji s. teraz niedost.pne.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Zaloguj si. w Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):636
                                                                    Entropy (8bit):4.515158874306633
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJsc/bGGsc/b+WYpU34OLw+dgn/KzO8ZpU34FjIBMwGRO03OyZnLAOfTYN+KcY:1HEb/a8/6WYp4mZ8Zp7cKlOGAOf2tD
                                                                    MD5:86A2B91FA18B867209024C522ED665D5
                                                                    SHA1:63DEC245637818C76655E01FCB6D59784BC7184E
                                                                    SHA-256:6374880FDD1F8AF1EE8AEA6A06B73BE0AB265AFCEB4FE6F08BDE3B3989264B21
                                                                    SHA-512:DA6DBDE5028756421C2904F605632EE98831A25A1247E6238A931629B94CE8A00FD76F4235F118D2167304BD60F2C06B2AD78E54FF6CE53F8C38DF8C7B5AFCE4
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pagamentos da Chrome Web Store".. },.. "app_name": {.. "message": "Pagamentos da Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplicativo indispon.vel no momento.".. },.. "craw_connect_to_network": {.. "message": "Conecte-se a uma rede.".. },.. "iap_unavailable": {.. "message": "No momento, os Pagamentos no aplicativo n.o est.o dispon.veis.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Fa.a login no Google Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):622
                                                                    Entropy (8bit):4.526171498622949
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJsZUkbGGsZUkb+WYpU34OAE+dgqxKzO8ZpU34rEpBfvPO03OyZnLAOfTYLD:1HEmUka5Uk6WYpFvdxZ8ZpSTnPlOGAOS
                                                                    MD5:750A4800EDB93FBE56495963F9FB3B94
                                                                    SHA1:8BFB915488A4EB3CB33D68E2E59F1F8447DB7D61
                                                                    SHA-256:C1C94F65FABAF17DEF98A8587711A56D61B1E5607500E9B01F2824DB109F9E83
                                                                    SHA-512:2AEDEF5793406221BE76AF22031CE8C30AB5FAEAED09BB394C153E2EBE990C89C1A2A73B40D8A92842641AFCA8C77FFD808A2058602D3646FD8DAE2844406F24
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pagamentos via Chrome Web Store".. },.. "app_name": {.. "message": "Pagamentos via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Aplica..o atualmente indispon.vel.".. },.. "craw_connect_to_network": {.. "message": "Ligue-se a uma rede.".. },.. "iap_unavailable": {.. "message": "Os Pagamentos na app est.o atualmente indispon.veis.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicie sess.o no Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):641
                                                                    Entropy (8bit):4.61125938671415
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJqJrJZGGqJrJZ+WYpU344HIx2Z+dgrVPlZO8ZpU34qT7hI3O03OyZnLAOfTYU:1HEC4D8WYpKow8WV68ZpKhoOGAOfoVGD
                                                                    MD5:98D43E4B1054A65DF3FA3CC40AB6FB6D
                                                                    SHA1:46E0A21C4DA2BB5D4D8F837AE211C1B6FA26E7E2
                                                                    SHA-256:113A13900CBA62FE8AED06751971C23A80A99B47F9BE219CF884D57DB19611D9
                                                                    SHA-512:A76DC53912A4F46714926B9EA2B22E909540E447F61F6DD72607AB7B3BB5D4A9B39E525B04C33AEC53BA813D14AC1FB5827275B2524E52B693E83171E1CD1466
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pl..i prin Magazinul web Chrome".. },.. "app_name": {.. "message": "Pl..i prin Magazinul web Chrome".. },.. "craw_app_unavailable": {.. "message": ".n prezent, aplica.ia nu este disponibil..".. },.. "craw_connect_to_network": {.. "message": "Conecteaz.-te la o re.ea.".. },.. "iap_unavailable": {.. "message": "Pl..ile .n aplica.ie nu sunt disponibile momentan.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Conecteaz.-te la Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):744
                                                                    Entropy (8bit):4.918620852166656
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ7OJHZMSl3ZGG7OJHZMSl3Z+WYpU34zWJ2F+dgVtLSv/TO8ZpU347NWjT03On:1HElOJHZMq4uOJHZMq8WYpdWJ/YGHq8m
                                                                    MD5:DB2EDF1465946C06BD95C71A1E13AE64
                                                                    SHA1:FB4F3ECE9ECECEBBC6CA2A592A15FB9C1FDFB811
                                                                    SHA-256:FBAF22CE6E16DE174CED8CB5EA3098CCA1C3426A2111FF33BD3E64DA64ED67AB
                                                                    SHA-512:4E0CF00BAEF1757548DEB17BBE1AF55770A0A0F7351779EF55C7DEFA6D112D0227B8865C2C22E0EC62E6E2F1C8E1632A2D0CE6828D25C5ABBF143C990116F632
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "......... ....... ........-........ Chrome".. },.. "app_name": {.. "message": "......... ....... ........-........ Chrome".. },.. "craw_app_unavailable": {.. "message": ".......... ...........".. },.. "craw_connect_to_network": {.. "message": "............ . .....".. },.. "iap_unavailable": {.. "message": "....... ..... .......... ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "....... . Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):647
                                                                    Entropy (8bit):4.640777810668463
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJfZGGfZ+WYpU34ORO+dgmmCO8ZpU34yH7u2Z03OyZnLAOfTYCUAi0D:1HEl4G8WYpetPmD8ZpcH7aOGAOfzUeD
                                                                    MD5:8DF215D1EFBDABB175CCDD68ED8DCB0A
                                                                    SHA1:2B374462137A38589A73FDD00A84CBDC7E50F9F4
                                                                    SHA-256:7FA16AF97E6CFC52EC6008EB679D3F30E7E0C24F9EF2D18A9228EAF4DED9D63B
                                                                    SHA-512:C0E623343BDAEB4731800D183B59F2FCFE285F0C7153EC99641FD84F2F2DCFE47D21E73F3D28B1240340453C5668EB0AFFBE087AAB62F1C88CD2A40CC44E599D
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "app_name": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplik.cia moment.lne nie je dostupn..".. },.. "craw_connect_to_network": {.. "message": "Pripojte sa k sieti.".. },.. "iap_unavailable": {.. "message": "Platby v aplik.cii moment.lne nie s. k dispoz.cii.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prihl.ste sa do prehliada.a Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):617
                                                                    Entropy (8bit):4.5101656584816885
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJGcyvmbZGGGcyvmbZ+WYpU34OBOEtf+dgca1ZO8ZpU34GcQArERff03OyZnLh:1HE4cyY4TcyY8WYpNoWa1w8ZpQcQ6AfK
                                                                    MD5:3943FA2A647AECEDFD685408B27139EE
                                                                    SHA1:0129DD19D28373359530B3B477FE8A9279DABB7D
                                                                    SHA-256:18AFF072EE0DF7C3495045435C752A805606E6D5D462EF2321C443F1773F4B3A
                                                                    SHA-512:42E62B3855611FF2E1D39C11404CB1A09825EE4CA6A8ACB3FF538B4574388F549E3BD79137DD4DC128A8DC44DD270D7D878E4AAD20DA8250A5C25297B0DEC09D
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Pla.ila v spletni trgovini Chrome".. },.. "app_name": {.. "message": "Pla.ila v spletni trgovini Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikacija trenutno ni na voljo.".. },.. "craw_connect_to_network": {.. "message": "Pove.ite se z omre.jem.".. },.. "iap_unavailable": {.. "message": "Pla.ila v aplikacijah trenutno niso na voljo.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prijavite se v Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):743
                                                                    Entropy (8bit):4.913927107235852
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJssbdOGGssbdO+WYpU347xBP+dgcucO8ZpU34s1muP03OyZnLAOfTYzDYD:1HEKsb59sbTWYplx4Xud8Zpy1mNOGAOv
                                                                    MD5:D485DF17F085B6A37125694F85646FD0
                                                                    SHA1:24D51D8642CDC6EFD5D8D7A4430232D8CDE25108
                                                                    SHA-256:7FFDE34C58E7C376C042DE64DEF6481DAE32BE8B70F0B18EDF536290CBE0C818
                                                                    SHA-512:0DDECFD860E99290B6C3AAA04F510272AE081CF2D93ED5832D9D6378EC9D36177FFBE213471247FB94721EA34A83E7665669200047091D0FDE134E3D763217E7
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "....... . Chrome ...-..........".. },.. "app_name": {.. "message": "....... . Chrome ...-..........".. },.. "craw_app_unavailable": {.. "message": ".......... .. ........ ...........".. },.. "craw_connect_to_network": {.. "message": "........ .. .......".. },.. "iap_unavailable": {.. "message": "....... . .......... .. ........ ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "......... .. . Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):630
                                                                    Entropy (8bit):4.52964089437422
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJJMkbGGJMkb+WYpU34OACwz+dgNPGFZO8ZpU34JgpXLSb03OyZnLAOfTYLdID:1HErMkaqMk6WYpTOcb8ZpDgdZOGAOf8Y
                                                                    MD5:D372B8204EB743E16F45C7CBD3CAAF37
                                                                    SHA1:C96C57219D292B01016B37DCF82E7C79AD0DD1E8
                                                                    SHA-256:B8BA77E0089B0676545EC16D32468B727812B444F90B33A7A5B748E6C36C4388
                                                                    SHA-512:33640529E0D5DCC5CA4BDB0615A2818E8D26C6FCB7B3474C08AC3EB67B9DB40E1F0A79954ED20728CD47A686D2533DCBC76ABCBDB917F8530C8DE8BBA687352E
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Betalning via Chrome Web Store".. },.. "app_name": {.. "message": "Betalning via Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Appen .r inte tillg.nglig f.r tillf.llet.".. },.. "craw_connect_to_network": {.. "message": "Anslut till ett n.tverk.".. },.. "iap_unavailable": {.. "message": "Betalning i appen .r inte tillg.ngligt f.r n.rvarande.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Logga in i Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):945
                                                                    Entropy (8bit):4.801079428724355
                                                                    Encrypted:false
                                                                    SSDEEP:24:1HEKa1dDa1/WYp6UFi72SmlG8ZpyactrW2SAOGAOfvSLD:WK2DNYp6U4y3bpyLxwGFW
                                                                    MD5:83E2D1E97791A4B2C5C69926EFB629C9
                                                                    SHA1:429600425CB0F196DDD717F940E94DBD8BFF2837
                                                                    SHA-256:2FECA577F43D97BAEEA464741D585892103585208FD0A935B810A03BDCE83C88
                                                                    SHA-512:60A5928DAA8CB4341487F477C56B5A98B83EDE50E5F4F55A802E01FDDAB86F3E795D391953D3D9214552D14D3F58C5A183693C613720FC12FC387D7B8F9B9AB6
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "............... Chrome .........".. },.. "app_name": {.. "message": "............... Chrome .........".. },.. "craw_app_unavailable": {.. "message": ".............................".. },.. "craw_connect_to_network": {.. "message": ".........................".. },.. "iap_unavailable": {.. "message": "...............................................".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "................. Chrome".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):631
                                                                    Entropy (8bit):4.710869622361971
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ9Y8GG9Y8+WYpU34wWT+dgGb0GO8ZpU34wryd7T03OyZnLAOfTYGbPKG:1HE0jWYpyRnG8Zpyr/OGAOfFPn
                                                                    MD5:2CEAE0567B6BB1D240BBAD690A98CA3B
                                                                    SHA1:5944346FBD4A0797B13223895995CAB58E9ECD23
                                                                    SHA-256:A7CB86F30C9C31FE5540282C308BA96ADB4EC16EF98C87129EB88105E5BEF5FC
                                                                    SHA-512:108A07C6D03D7178E8D0FFEF5349E0249A898D864964FED8757BD8A08BC1C6D9613F2A6C01AA34A6606127D1C6CE14C229FA02586677DBB060B85E3E845950E1
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome Web Ma.azas. .demeleri".. },.. "app_name": {.. "message": "Chrome Web Ma.azas. .demeleri".. },.. "craw_app_unavailable": {.. "message": "Uygulama .u anda kullan.lam.yor.".. },.. "craw_connect_to_network": {.. "message": "L.tfen bir a.a ba.lan.n.".. },.. "iap_unavailable": {.. "message": "Uygulama ..i .demeler .u anda kullan.lamaz.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "L.tfen Chrome'da oturum a..n.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):720
                                                                    Entropy (8bit):4.977397623063544
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ7wILkSlXZGG7wILkSlXZ+WYpU34zb1Oy2P+dgSV1EjiTO8ZpU347qtfP2CTW:1HElwEkK4uwEkK8WYpd/dTV1e8Zptq5S
                                                                    MD5:AB0B56120E6B38C42CC3612BE948EF50
                                                                    SHA1:8B3F520E5713D9F116D68E71DAEED1F6E8D74629
                                                                    SHA-256:68ABA284751EB9C856032062EF9B1651E2A1E5CE5FDA0977FFC97D63BA7BED9E
                                                                    SHA-512:CD852A58217F739C1CD58567FF432D31A7AD3F68C884ABBA1DA95799BCD1545C6A5D3B06F319681C12B78AD0A709828DE4B22736316F148D21F5DB76A5BCCBEF
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "....... ...-........ Chrome".. },.. "app_name": {.. "message": "....... ...-........ Chrome".. },.. "craw_app_unavailable": {.. "message": "........ ......... ...........".. },.. "craw_connect_to_network": {.. "message": "............. .. .......".. },.. "iap_unavailable": {.. "message": "....... ..... ........ ..... .. .........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "........ . Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):695
                                                                    Entropy (8bit):4.855375139026009
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJMAZrSFZGGMAZrSFZ+WYpU34WFHoz+dgdklzoO8ZpU34NFHoz03OyZnLAOfTU:1HEI4B8WYpAKytFZ8ZpXKMOGAOfd6D
                                                                    MD5:7EBB677FEAD8557D3676505225A7249A
                                                                    SHA1:F161B4B6001AEAEAB246FF8987F4D992B48D47BE
                                                                    SHA-256:051F96ED874C11C4A13589B5F68964E4F5B03B52DDA223D56524F2CA23760C04
                                                                    SHA-512:74FD267CF7E299FB8E7054605C3F651F057F676FF865082FA24F4916755456768DB0DA62DBC515D829B48AB1F9CFC8AD3E841DCBF1F194D5CB14C5335A192A0D
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Thanh to.n tr.n c.a h.ng Chrome tr.c tuy.n".. },.. "app_name": {.. "message": "Thanh to.n tr.n c.a h.ng Chrome tr.c tuy.n".. },.. "craw_app_unavailable": {.. "message": ".ng d.ng hi.n kh.ng kh. d.ng.".. },.. "craw_connect_to_network": {.. "message": "Vui l.ng k.t n.i v.i m.ng.".. },.. "iap_unavailable": {.. "message": "Thanh to.n trong .ng d.ng hi.n kh.ng kh. d.ng.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Vui l.ng ..ng nh.p v.o Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):595
                                                                    Entropy (8bit):5.210259193489374
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ01GG01+WYpU34zeHz+dgfO8ZpU34YKiO03OyZnLAOfTYB6U:1HEpIWYpISv8Zp+JOGAOfa6U
                                                                    MD5:BB73BF561BB79F89D9BF7C67C5AE5C65
                                                                    SHA1:2FADD3A1959B29C44830033A35C637D0311A8C9C
                                                                    SHA-256:D804F2A040D21D7511EFD5213D8E1721D64964A1A0DBB48E21622CEEDC9D967E
                                                                    SHA-512:627D44CEF1FE5C5ABD598BD47FF5E22B9EFC1CF98DDE3868FA9E5896C134A0C9C055AC34EDDADAE56B6690E51AEA89965D38F770552A85C732CC796795DC68D2
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome .........".. },.. "app_name": {.. "message": "Chrome .........".. },.. "craw_app_unavailable": {.. "message": ".........".. },.. "craw_connect_to_network": {.. "message": ".......".. },.. "iap_unavailable": {.. "message": "............".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "... Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:UTF-8 Unicode text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):634
                                                                    Entropy (8bit):5.386215984611281
                                                                    Encrypted:false
                                                                    SSDEEP:12:1HEJ2j62GG2j62+WYpU34m7T+dgc8nOO8ZpU34mvIO03OyZnLAOfTYAuH:1HEuSZCWYpsStwP8ZpROGAOfCH
                                                                    MD5:5FF50C673CC0C661D615F0CFD0E6DCA0
                                                                    SHA1:60DFF98DEAB9C4746B288BDD9C94B3BCAE5EAA85
                                                                    SHA-256:C6F8C640F3353A7B9B1432A0C139C1AEEC40133800E6C9B467B63991AD660308
                                                                    SHA-512:361D62D91F4931C5F34092C9F2C6A5323D5EEB82A24E7ABE11F7817D8D66341C0ECAD4DCB4B10873920C8D6A3CC9F5704889E178EB2549001A9F62BEDF6C8019
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app_description": {.. "message": "Chrome ............".. },.. "app_name": {.. "message": "Chrome ............".. },.. "craw_app_unavailable": {.. "message": ".............".. },.. "craw_connect_to_network": {.. "message": "......".. },.. "iap_unavailable": {.. "message": "................".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "... Chrome.".. }..}..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):7780
                                                                    Entropy (8bit):5.791315351651491
                                                                    Encrypted:false
                                                                    SSDEEP:192:RktDNJ2UzsL5KcASyoH+CouKP/iNGRo/oRHMIT:AZQflcsU
                                                                    MD5:0834821960CB5C6E9D477AEF649CB2E4
                                                                    SHA1:7D25F027D7CEE9E94E9CBDEE1F9220C8D20A1588
                                                                    SHA-256:52A24FA2FB3BCB18D9D8571AE385C4A830FF98CE4C18384D40A84EA7F6BA7F69
                                                                    SHA-512:9AEAFC3ECE295678242D81D71804E370900A6D4C6A618C5A81CACD869B84346FEAC92189E01718A7BB5C8226E9BE88B063D2ECE7CB0C84F17BB1AF3C5B1A3FC4
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiJfbG9jYWxlcy9iZy9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiZHUtdGRPdUNWcmxDY254Q0poRkg2NXpLU05vb1RiUE56bDNHbzdRMGJ3SSJ9LHsicGF0aCI6Il9sb2NhbGVzL2NhL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJ6ZGtWaF9XdkxJWlhkck5xWHBvSHNRMGh1ZGtSM2d1QlMzb2VsTEZLNklVIn0seyJwYXRoIjoiX2xvY2FsZXMvY3MvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6Ik9nUkNIZlVoam9xOU93NHFfaEhvTTQxNzNMelJyYkVpUVdsRXNRSzhscFkifSx7InBhdGgiOiJfbG9jYWxlcy9kYS9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiN2JVWW1LYkhQUUNRMXBGcmUzTHJySEhwWk9xN1c2Zk5hT0laWmdKUERTTSJ9LHsicGF0aCI6Il9sb2NhbGVzL2RlL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJOV3FkU3Rfc1NFMm9KT2VuSUZtM0pMRm9iOGtBZ3ZTa3RtZGpCRGJWazdBIn0seyJwYXRoIjoiX2xvY2FsZXMvZWwvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6ImgyaEZ0YUJoLXJQUEtoUm00QkFWM0VEZmhFbnh5MElGOVhYT3Z0aHhlNjAifSx7InBhdGgiOiJfbG9jYWxlcy9lbi9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoid0pSZDFmM3NxMERFVTJHLXd
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines
                                                                    Category:dropped
                                                                    Size (bytes):544643
                                                                    Entropy (8bit):5.385396177420207
                                                                    Encrypted:false
                                                                    SSDEEP:6144:abyfBNC2FRdjiRXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0NjyTOEzZQ+h72W3GB0n:Ft/g
                                                                    MD5:6EEBED29E6A6301E92A9B8B347807F5F
                                                                    SHA1:65DFB69B650560551110B33DCBA50B25E5B876DE
                                                                    SHA-256:04CD9494B0ED83924DAD12202630B20D053D9E2819C8E826A386C814CC0A1697
                                                                    SHA-512:FEDE6DB31F2AD242E7BC7B52A8859BA7F466A0B920A8DADCB32DCFB5B2A2742E98B767FF22E0C5BC5C11FEC021240AA9E458486C9039EB4EBE5CF6AF7BE97BF2
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var d,e=e||{};e.scope={};e.arrayIteratorImpl=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};e.arrayIterator=function(a){return{next:e.arrayIteratorImpl(a)}};e.ASSUME_ES5=!1;e.ASSUME_NO_NATIVE_MAP=!1;e.ASSUME_NO_NATIVE_SET=!1;e.SIMPLE_FROUND_POLYFILL=!1;e.ISOLATE_POLYFILLS=!1;e.FORCE_POLYFILL_PROMISE=!1;e.FORCE_POLYFILL_PROMISE_WHEN_NO_UNHANDLED_REJECTION=!1;.e.defineProperty=e.ASSUME_ES5||"function"==typeof Object.defineProperties?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};e.getGlobal=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");};e.global=e.getGlobal(this);.e.IS_SYMBOL_NATIVE="func
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with very long lines
                                                                    Category:dropped
                                                                    Size (bytes):261316
                                                                    Entropy (8bit):5.444466092380538
                                                                    Encrypted:false
                                                                    SSDEEP:3072:I5vU7I6s2M9duIWFCbmYJ4tnFWdqpMad2vywhIp81QFv9F9nNsZgiDdOFlV/mZmc:I5vqFCb2p8Gx9FNNsZ9Dd/ceR
                                                                    MD5:1709B6F00A136241185161AA3DF46A06
                                                                    SHA1:33DA7D262FFED1A5C2D85B7390E9DBC830CBE494
                                                                    SHA-256:5721A4B3F8E09C869A629EFFD350B51C9D46F0AC136717D4DB6265C0EE6F9AC8
                                                                    SHA-512:26835B4C050F53AD2DDB84469DF9A84BBB2786A655AB52DFC20B54BEDCB81D1ECD789198D5B7D8B940242E5CEAC818A177444D402397AE82C203438C4B1D19CB
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var b,k=k||{};k.scope={};k.createTemplateTagFirstArg=function(a){return a.raw=a};k.createTemplateTagFirstArgWithRaw=function(a,c){a.raw=c;return a};k.arrayIteratorImpl=function(a){var c=0;return function(){return c<a.length?{done:!1,value:a[c++]}:{done:!0}}};k.arrayIterator=function(a){return{next:k.arrayIteratorImpl(a)}};k.makeIterator=function(a){var c="undefined"!=typeof Symbol&&Symbol.iterator&&a[Symbol.iterator];return c?c.call(a):k.arrayIterator(a)};.k.arrayFromIterator=function(a){for(var c,d=[];!(c=a.next()).done;)d.push(c.value);return d};k.arrayFromIterable=function(a){return a instanceof Array?a:k.arrayFromIterator(k.makeIterator(a))};k.ASSUME_ES5=!1;k.ASSUME_NO_NATIVE_MAP=!1;k.ASSUME_NO_NATIVE_SET=!1;k.SIMPLE_FROUND_POLYFILL=!1;k.ISOLATE_POLYFILLS=!1;k.FORCE_POLYFILL_PROMISE=!1;k.FORCE_POLYFILL_PROMISE_WHEN_NO_UNHANDLED_REJECTION=!1;.k.objectCreate=k.ASSUME_ES5||"function"==typeof Object.cre
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):1741
                                                                    Entropy (8bit):4.912380256743454
                                                                    Encrypted:false
                                                                    SSDEEP:24:LalZ74H+rMwJHwIodHRmxt3jiu1iu1RDpfeWlMl548wJHwDwCapt/VMYXj8Eq27K:Z+rMm71le88S1tWYXmrVZFH
                                                                    MD5:67BF9AABE17541852F9DDFF8245096CD
                                                                    SHA1:A4AC74DD258E8E0689034FAA1B15A5C7C56DC3BB
                                                                    SHA-256:10DFBD2D98950B79EE12F6B8E3885AABE31543048DE56AD4FC0A5E34D0D9D4EC
                                                                    SHA-512:298FA132C6F122798FDB9BC6DE8024915147ADC20355B56A92F0ED9ACCE4549BE6E7F42212E07DCA166E31624D4E66E299565845D4BA1C51CA935050641B61FE
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:html, body {. margin: 0;. overflow: hidden;.}..webview {. width: 100%;. height: 100%;. min-height: 100%;. position: absolute;.}...craw_overlay {. position: absolute;.. left: 0;. top: 0;. right: 0;. bottom: 0;.. background-color: white;.. -webkit-transition: opacity 250ms linear;.. display: -webkit-flex;. -webkit-flex-direction: column;. -webkit-flex: 1 0%;. -webkit-align-items: center;. -webkit-justify-content: center;.. -webkit-app-region: drag;.}...craw_overlay img {. margin: 16px;.}..#loading_overlay {. opacity: 1;.}..#offline_overlay {. opacity: 0;. display: none;.}..#offline_overlay > img {. -webkit-filter: saturate(0%);.}..#offline_overlay > span {. font-family: 'Open Sans', 'Deja Vu Sans', Arial, sans-serif;. font-size: 15px;. line-height: 21px;. color: #8d8d8d;. display: block;.}..#loading_splash {. width: 128px;. height: 128px;.}..#drag_overlay {. position: absolute;. left: 0;. top: 0;. right: 0;. bottom: 0;. pointer-events: none;. -webkit
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:HTML document, ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):810
                                                                    Entropy (8bit):4.723481385335562
                                                                    Encrypted:false
                                                                    SSDEEP:12:hYenuEJIig5fRpvV4AEdN2sAAuzg/7RwQuLYpUH9KfRnQBGgZKy3QGgjPSWZDQL:hYeLJKTVNEuLAuzg/twQucpS9bj3
                                                                    MD5:34A839BC40DEBC746BBD181D9EF9310C
                                                                    SHA1:8B4EAA74D31EED5B0BABA3CA5460201F6B10DA46
                                                                    SHA-256:BB8742615E4CD996AE5D0200E443AE6A6F0B473255F03AFFDB8FB4660DE4554D
                                                                    SHA-512:EE81E5509CBC2CB2B6C834224688C1E1B1AA9AA3866C52F8EAED040D5C390653C52D8D681E2E2CF62906643962ABAC823D5B622385B983B21E0DCCAFDF281EFF
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:<!DOCTYPE html>.<html>. <head>. <link href="/css/craw_window.css" rel="stylesheet">. <script src="/craw_window.js"></script>. </head>. <body>. <webview></webview>. <div class="craw_overlay" id="loading_overlay">. <img src="/images/icon_128.png" />. <img src="/images/flapper.gif" />. </div>. <div class="craw_overlay" id="offline_overlay">. <img src="/images/icon_128.png" />. <span id="app_unavailable"></span>. <span id="connect_to_network"></span>. </div>. <div id="drag_overlay"></div>. <div id="top_bar">. <div id='close_button'>. <img src='/images/topbar_floating_button_close.png'/>. </div>. <div id='maximize_button'>. <img src='/images/topbar_floating_button_maximize.png'/>. </div>. </div>. </body>.</html>.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:GIF image data, version 89a, 30 x 30
                                                                    Category:dropped
                                                                    Size (bytes):70364
                                                                    Entropy (8bit):7.119902236613185
                                                                    Encrypted:false
                                                                    SSDEEP:768:g5TXOSBAqNIPmA8NcjCWdM0VFMJEwavTeElfWupav5TXg7wV+irIPny9MTVQHydi:g5KSmiIPmAhZWiMsDfWug7DmqM6HybkF
                                                                    MD5:398ABB308EEBC355DA70BCE907B22E29
                                                                    SHA1:CFFB77B8A1724B8F81D98C6D6AD0071D10162252
                                                                    SHA-256:2B73533F47A99FFEA9CC405FFAFA9C4C53623F62487AEBFBA415945120B22040
                                                                    SHA-512:FC7A56FC8A61A582161874B54ADBAD30A84840190008EDB0B6FBF84F91393CA58E988E3FE446F11A0C3C691C18249B93AEC2904B3D0C4F0857D79034F662385A
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:GIF89a.......................................................!.......!..NETSCAPE2.0.....,.............9.:.h0.bT(6.!l.&..("g*k..JL1.[....o. .(:..B(.6."...Z.CUyh0.....j.C.z8..S....2.T'...Q..4 g|]$ueW.NyQ.IoL!AoF#9h>7.0t..%..,.@.m4..7..!.......,.............9.:.h0.bT(6.!l.&..("g*k..JL1.[....o. .(:..B(.6."...Z.CUyh0.....j.C.z8..S....2.T'...Q..4 g|]$ueW.NyQ.IoL!AoF#9h>7.0t..%..,.@.m4..7..!.......,............................................................................................................'..w=.....\.)._6.k..OF...n.#\~"....2b3..I.)..eu.Q.`.e......gr.?>.s.I0.....@.~.Tr.[8.+.,.;..EE....S.*f.....,.....B8/D..;.9.q......ukC...r.I.....j......BGY...o2J....+O4....X4.....cH%7....I.....0H!.!.....!.,.............................................................................................................................................................................................................p8.a$....hh@.4....X,A.0L..(....JX.j...,..........z.X.Q....jB.d....B..
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):4364
                                                                    Entropy (8bit):7.915848007375225
                                                                    Encrypted:false
                                                                    SSDEEP:96:YjlLDJjTvXUtNvX8dgb9HT6y8nviyHG5iCRYtIP:YtNTfUzvX8KM+MGRsIP
                                                                    MD5:4DBC9F9E6F5A08D299BAC9E54DF07694
                                                                    SHA1:BB38F5DE34B1E0BE1109220BA55271087A4D9EA5
                                                                    SHA-256:91C2718DD23B4356D71F88F6146868369033291086DF327534546DFA459BEB0E
                                                                    SHA-512:A5F2B1F47502836130D8083F757B7773C1E1CB36B76AD298CC29AB2B428C8002D2F15BD839838FC326DAC3681C2F48AB25A3E7631D33726C4B25E8EC14170912
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR..............>a.....IDATx..yp.....gF#.:,[H.l.l..8...`/.k....,!a7Km...E...Te..T.....J...p....%.(....+...3....eY.e...L.o...5....h4...\....{?....~.u.`0.....`0.....`0.....`.Y......[(.......).4....ai..w38.+....Bf././..]...{......8...3.....3W~OJ.. /...u6V.C..U.0.+._=.c..9.X.?....L....S@.L...m.0..>.C...L|TF.p5..f4M.,.V....8..a.<...RP..@)E,..E"...h.....!...-....,I..T..........m..._[[{w{{....{*.^......M.x..h4.h.....\.R.E....j).7.....h4.A.E....,. ...iii.Vj?2...=/.B.FK9P..@)=Rj..D".Y...2.B..x.}0...&J...2.......f.O..e.H.....!.J)'I..R....B............QJ;K..L...L.l".L~mhh.R.@).FFF~.L&...~.B.......u.........}.....~.....f..yUU...........^M...6......].,w.e..~.!$.C.R.....E(%e9.,....k..@...W8.........@...........O..@%.~..@.S..P.....`Tp...."...?ME..c......s...`..S1...7.b..aNE..k...3.yP.}.Ch.}......B..........IPE..C.<....T....k......Z..o_......g........P..A=y.J.)h..@.q.-.*].AU.4...F.M.....y%B]+ .\.~..9......:..=...r.....E].o...F..P........i...|....
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):558
                                                                    Entropy (8bit):7.505638146035601
                                                                    Encrypted:false
                                                                    SSDEEP:12:6v/7vyVgSKYsfFzXxXsrPfA+b0YX+5IOUWCQKznuow7:6yVnKYsfFzhXsrIq0YXmgQGn6
                                                                    MD5:FB9C46EA81AD3E456D90D58697C12C06
                                                                    SHA1:5FC450F7D73CCFAC8F0D818CB3392BA4D91B69DE
                                                                    SHA-256:016CA659BA080E194FBFC0929602B16506ED60AA6019FAA51410C4FD93B583E8
                                                                    SHA-512:ADD810EE9EB7CAEC505B5FD90A1F184CE39D8F8C689DCC240F188FE353B9575489492E07D572A3B1C11A1555CE66AFCA5134903E4C1AA3D54BC7C5ED3E65B50C
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR................a....IDAT8...Mk.Q...;... .....F..QW.....F....J.?.w..7~......'.Q..B]... .QS...M&_w..b&.|`......p...f.?.D$.y^..........y*...\..Z..t6..oRj.@&.u..G.qN).t.-V*.>(.N.Ep]wFk.60o.]0.`Y..cT..Y.Tb.`DF.d..s.Z..E..9.4._C.._...%..*.^....4.l...Y..X..R..../...Wj+w0[.].._B.k.${.\.>.%...........lz .w.ALxo.2;..a...".p..S..&..uXS...<..6..[..zD.._.N+w.WbM7ye6X<...'(,=.r}........$f..5..P....k..."..8.s.<zgSm@.....).Y.....:e..|.....F...I..A$.....T?.....m....8.........N...z.....V..vd.h'....C.?.....H.;]..C.M.....9.b......IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):160
                                                                    Entropy (8bit):5.475799237015411
                                                                    Encrypted:false
                                                                    SSDEEP:3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/RPJDmV7bScsP4a9zln94FptVp:6v/lhPKM4nDspnAkZJNmgPdln2TTp
                                                                    MD5:8803665A6328D23CC1014A7B0E9BE295
                                                                    SHA1:9DA6EE729D5A6E9F30658B8EC954710F107A641F
                                                                    SHA-256:D5F9234DC36E7FFA85F35B2359A4F82276F8395EFA76E4553507EA990B27FC6C
                                                                    SHA-512:ECD9E71B8BA1ED8BD4CA5A0936CB66A83611C4ABCBDA76C250F4CDF4AD80320212E8F5EEB79A38910718F8346ECC1AD580A3FA835EC2B22BE497F36899FB5930
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<...BIDATx...Q..0......2...(p...~Z.}'.>I%O...V!s..................../...`.<..`.....IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):252
                                                                    Entropy (8bit):6.512071394066515
                                                                    Encrypted:false
                                                                    SSDEEP:6:6v/lhPKM4nDsp7q1hKVlomsj9rxKNgtmN0VZ+GFYep:6v/7iMXVq1ylxemNgtmKVnYM
                                                                    MD5:0599DFD9107C7647F27E69331B0A7D75
                                                                    SHA1:3198C0A5F34DB67F91A0035DBC297354CBC95525
                                                                    SHA-256:131817CD9311C03DF22D769DD2AD7FA2E6E9558863A89F7E5E1657424031A937
                                                                    SHA-512:0076ACB9D6A886BD987876E49495038F9388B292A9EFE5C9093CCA64CA3692E3A5D24E35172C7697F6AAE34B86CA217EE59C003423E46D9499BD27EC7D77A649
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<....IDATx...... ..Pp.X....H...b@...|.^LC_.E.BP+......X.P..........q..~..p/. ..s.....%D^...$......@.!...<...).?.4{.k.G3...4..[cH..0..l.8.!r..m.R..{..........`.f...#.x.....IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):160
                                                                    Entropy (8bit):5.423186859407619
                                                                    Encrypted:false
                                                                    SSDEEP:3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/9lVtEHxrPLyN+ltNPhv/l2up:6v/lhPKM4nDspnAkZHVtERrPLygltNPn
                                                                    MD5:7CB6B9DC1A30F63B8BD976924B75AD96
                                                                    SHA1:0C40B0C496D2F2B5F2021C117EC8610AC03AB469
                                                                    SHA-256:721B7AAA9A42A54A349881615A12E3A26983ACA48E173FD2F66E66AA0D725735
                                                                    SHA-512:4764937364E355956B242B84010AC56102536D2AACBE4227F0E88E4DE7AB468571957EA6C33012539156E5349AE4F777115615AE3361F60ADDF9CD227424F76A
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<...BIDATx...A..0...+B.z.s...*.....$.<u..[...................h.......C.CA).....IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):166
                                                                    Entropy (8bit):5.8155898293424775
                                                                    Encrypted:false
                                                                    SSDEEP:3:yionv//thPl3xWrA4RthwkBDsTBZttd//HmnFz1P/ZjXlUTqyCIc30ItK1p:6v/lhPKM4nDsptF/HOP/ZjXlUeyCo/p
                                                                    MD5:232CE72808B60CBE0F4FA788A76523DF
                                                                    SHA1:721A9C98C835D2CD734153BBE07833C6637ECD68
                                                                    SHA-256:AFA4EA944CBDEC8543242E627EF46D5BFD3766DCAC664E7E50CDEEF2B352740C
                                                                    SHA-512:4048EEA5A78DD569521C488C4CE4F7B77AC0454C92EE9107A81A1B3AF91A4EE036039AC1A0A6B8DD26B12E7F1595DB80B7FAA7B6A25D9032BF385528A81A8654
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<...HIDATx......0.CQS.......~..."..........m.v+Sq....<!...M8m...'...@$..0....E........IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):160
                                                                    Entropy (8bit):5.46068685940762
                                                                    Encrypted:false
                                                                    SSDEEP:3:yionv//thPl3xWrA4RthwkBDsTBZtnAkx/9lVtEXIyN+ltN1/lsg1p:6v/lhPKM4nDspnAkZHVtEZgltN1eup
                                                                    MD5:E0862317407F2D54C85E12945799413B
                                                                    SHA1:FA557F8F761A04C41C9A4BA81994E43C6C275DBB
                                                                    SHA-256:5C10CE0589EB115600F77381130B70AE0B7B3752614D86D4C89E857658AA222B
                                                                    SHA-512:07CB69327961FD0019BEF8EF7590B5524905AC373A815F73F6D9E0B26840929F919A96CAA977D4B5656704DACD0F352D568FB3997F80EE6BB94C95B58839DBFE
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<...BIDATx...A..0...+B..@wu...*.....$.<u..[...................h.........M..x(....IEND.B`.
                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1322
                                                                    Entropy (8bit):5.449026004350873
                                                                    Encrypted:false
                                                                    SSDEEP:24:1HEis7ViC/yox/fiqeUoLFlmF1s80FKrGfd0d3NZNZx1Fq7eY7nfj1B:WL7V2opiV1mvs8rxTZRczhB
                                                                    MD5:01334FB9D092AF2AA46C4185E405C627
                                                                    SHA1:47AD3C0E82362FFE5B881DF8D71D6F79AB7F5796
                                                                    SHA-256:F52714812D68C577A445169D11E84DF6751C2D6886BC429643072BB5D61C6C27
                                                                    SHA-512:888D96ADB7A847ABE472145258C8C46950EB2FA3BA7D596C2E90A17C8FB06FD0155C56CC8ABA5D076D89368417464BCB2D236F9E40E53241950A01F9F8ED548F
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:{.. "app": {.. "background": {.. "scripts": [ "craw_background.js" ].. }.. },.. "default_locale": "en",.. "description": "__MSG_APP_DESCRIPTION__",.. "display_in_launcher": false,.. "display_in_new_tab_page": false,.. "icons": {.. "128": "images/icon_128.png",.. "16": "images/icon_16.png".. },.. "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB",.. "manifest_version": 2,.. "minimum_chrome_version": "29",.. "name": "__MSG_APP_NAME__",.. "oauth2": {.. "auto_approve": true,.. "client_id": "203784468217.apps.googleusercontent.com",.. "scopes": [ "https://www.googleapis.com/auth/sierra", "https://www.googleapis.com/auth/sierrasandbox", "https://www.googleapis.com/auth/chromewebstore", "https://www.googleapis.com/auth/chromewebstore.readonly" ].. },.
                                                                    No static file info
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jul 22, 2022 19:15:10.323167086 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.323224068 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.323316097 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.323555946 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.323607922 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.323702097 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.324784040 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.324810028 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.325004101 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.325032949 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.389892101 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.392267942 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.392309904 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.393347025 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.393445015 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.398000956 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.431354046 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.431399107 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.432133913 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.432159901 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.432245970 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.433711052 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.433796883 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.433815956 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.495594978 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.678960085 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.679274082 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.679421902 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.679728031 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.679946899 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.679981947 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.680335045 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.680375099 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.735470057 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.735593081 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.735634089 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.735760927 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.735826969 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.737046957 CEST49731443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:10.737070084 CEST44349731216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:10.743949890 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.747585058 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.747715950 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.747735023 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.747862101 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.747939110 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.752928972 CEST49730443192.168.2.3142.250.180.141
                                                                    Jul 22, 2022 19:15:10.752954006 CEST44349730142.250.180.141192.168.2.3
                                                                    Jul 22, 2022 19:15:10.786098957 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.786144972 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:10.786242008 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.786612988 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.786632061 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:10.786698103 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.786943913 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.786972046 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:10.787106991 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:10.787123919 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.229439020 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.230448008 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.237874985 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.237906933 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.238374949 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.238411903 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.239259958 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.239351988 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.239561081 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.239624977 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.244595051 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.244774103 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.244993925 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.245120049 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.245547056 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.245565891 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.343997955 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.344012976 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.344131947 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.427714109 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.427792072 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.427916050 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.434765100 CEST49735443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.434803963 CEST44349735173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:11.443979979 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:11.581275940 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.581326008 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:11.581413031 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.581841946 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.581906080 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:11.581995010 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.582123041 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.582149982 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:11.582360983 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:11.582401991 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.024629116 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.025738001 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.095756054 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.141549110 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.141596079 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.141649008 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.141731977 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.143870115 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.143924952 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.143959999 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.144715071 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.144782066 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.144819021 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.148220062 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.148518085 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.148566008 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.148762941 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.149133921 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.149157047 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.244066000 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.293072939 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.293097973 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.484935999 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.484992981 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.485013008 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.485101938 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.485131025 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.485153913 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.485188007 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.485229015 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.493244886 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.540620089 CEST49744443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.540656090 CEST4434974423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.598480940 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.640574932 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.746720076 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.746761084 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.746829987 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.746855021 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.746880054 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.746936083 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.751808882 CEST49745443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.751840115 CEST4434974523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.756251097 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.756320000 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:12.756407976 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.756689072 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:12.756721020 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.071769953 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.071841955 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.071960926 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.072186947 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.072206974 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.157752037 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.158098936 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.158173084 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.159640074 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.159766912 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.161542892 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.161676884 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.161701918 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.191230059 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.191653967 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.191680908 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.191987991 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.192462921 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.192584038 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.192620039 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.204659939 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.236504078 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.244143963 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.294226885 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.294275045 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.297732115 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.298105001 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.298161983 CEST44349756104.21.84.241192.168.2.3
                                                                    Jul 22, 2022 19:15:13.298198938 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.298228025 CEST49756443192.168.2.3104.21.84.241
                                                                    Jul 22, 2022 19:15:13.337316990 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.337348938 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.337418079 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.337440968 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.337456942 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.337496996 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.339271069 CEST49754443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.339297056 CEST4434975423.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.353710890 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.353754997 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.353840113 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.354068041 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.354080915 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.401128054 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.401465893 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.401501894 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.402615070 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.402725935 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.412019968 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.412239075 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.412252903 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.452505112 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.540718079 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.540786028 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.540884972 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.541449070 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.541471958 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.549834013 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.549941063 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.555105925 CEST49757443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.555138111 CEST4434975734.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.558389902 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.558455944 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.558552980 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.558851004 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.558876038 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.597131968 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.597481012 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.597503901 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.597775936 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.598263979 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.598345041 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.598459959 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.601443052 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.601834059 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.601849079 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.602931976 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.603003979 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.604546070 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.604629993 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.604696035 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.640602112 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.644229889 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.644264936 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.744210958 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.753302097 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.753436089 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.753520966 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.756928921 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.757215977 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.757301092 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.764117956 CEST49763443192.168.2.379.110.52.9
                                                                    Jul 22, 2022 19:15:13.764163971 CEST4434976379.110.52.9192.168.2.3
                                                                    Jul 22, 2022 19:15:13.767416000 CEST49764443192.168.2.334.117.59.81
                                                                    Jul 22, 2022 19:15:13.767436981 CEST4434976434.117.59.81192.168.2.3
                                                                    Jul 22, 2022 19:15:13.786878109 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.786923885 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.787065983 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.787354946 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:13.787367105 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:13.811142921 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.811191082 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.811273098 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.811507940 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.811517954 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.888905048 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.889694929 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.889734030 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.890829086 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.890928030 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.892539978 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.892637014 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.892827988 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.892851114 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.924946070 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:13.925046921 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.925714970 CEST49766443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:13.925746918 CEST44349766142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.218946934 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.236761093 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:14.236795902 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.237390041 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.239245892 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:14.239384890 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.239404917 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:14.284492970 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.388087034 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.388298035 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:14.392608881 CEST49765443192.168.2.323.22.144.165
                                                                    Jul 22, 2022 19:15:14.392633915 CEST4434976523.22.144.165192.168.2.3
                                                                    Jul 22, 2022 19:15:14.796051025 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.796139002 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.796272993 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.798778057 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.798810005 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.862819910 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.862935066 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.882344961 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.882380009 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.882652044 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.882729053 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.883722067 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.908970118 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.909071922 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:14.909102917 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.909142017 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.914194107 CEST49774443192.168.2.3142.251.209.4
                                                                    Jul 22, 2022 19:15:14.914232016 CEST44349774142.251.209.4192.168.2.3
                                                                    Jul 22, 2022 19:15:23.392322063 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:23.393002987 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:23.393076897 CEST49736443192.168.2.3173.231.223.247
                                                                    Jul 22, 2022 19:15:23.393088102 CEST44349736173.231.223.247192.168.2.3
                                                                    Jul 22, 2022 19:15:23.393150091 CEST49736443192.168.2.3173.231.223.247
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jul 22, 2022 19:15:10.284987926 CEST5811653192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:10.290060043 CEST6535853192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:10.310385942 CEST53581168.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:10.317090034 CEST53653588.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:10.678411007 CEST4987353192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:10.784298897 CEST53498738.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:11.559259892 CEST6354853192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:11.580205917 CEST53635488.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:13.047897100 CEST5898153192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:13.070641041 CEST53589818.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:13.333774090 CEST6445253192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:13.333894014 CEST6138053192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:13.352658033 CEST53644528.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:13.535550117 CEST53613808.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:13.789751053 CEST6314653192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:13.809271097 CEST53631468.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:14.765137911 CEST5862553192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:14.786591053 CEST53586258.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:14.832828999 CEST5281053192.168.2.38.8.8.8
                                                                    Jul 22, 2022 19:15:14.854995012 CEST53528108.8.8.8192.168.2.3
                                                                    Jul 22, 2022 19:15:15.905507088 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:15.944314957 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:15.952771902 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:15.991852999 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:15.991899014 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:15.991936922 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:15.991976976 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:15.992551088 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:15.995465994 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:16.055239916 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:16.055649996 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:16.101030111 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.107254982 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.107336998 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.128000975 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.128062010 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.128092051 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.142760038 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:16.142988920 CEST59391443192.168.2.3216.58.209.46
                                                                    Jul 22, 2022 19:15:16.150090933 CEST44359391216.58.209.46192.168.2.3
                                                                    Jul 22, 2022 19:15:16.153178930 CEST59391443192.168.2.3216.58.209.46
                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                    Jul 22, 2022 19:15:10.284987926 CEST192.168.2.38.8.8.80x6303Standard query (0)accounts.google.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:10.290060043 CEST192.168.2.38.8.8.80x19f5Standard query (0)clients2.google.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:10.678411007 CEST192.168.2.38.8.8.80xc5b8Standard query (0)locksmithelpasotexas.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:11.559259892 CEST192.168.2.38.8.8.80x711aStandard query (0)voyage-croissant-31209.herokuapp.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.047897100 CEST192.168.2.38.8.8.80xad34Standard query (0)api.hostip.infoA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.333774090 CEST192.168.2.38.8.8.80xa778Standard query (0)ipinfo.ioA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.333894014 CEST192.168.2.38.8.8.80x73feStandard query (0)hancott.bizA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.789751053 CEST192.168.2.38.8.8.80xf99cStandard query (0)www.google.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.765137911 CEST192.168.2.38.8.8.80x13f2Standard query (0)www.google.comA (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.832828999 CEST192.168.2.38.8.8.80x3ba4Standard query (0)voyage-croissant-31209.herokuapp.comA (IP address)IN (0x0001)
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                    Jul 22, 2022 19:15:10.310385942 CEST8.8.8.8192.168.2.30x6303No error (0)accounts.google.com142.250.180.141A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:10.317090034 CEST8.8.8.8192.168.2.30x19f5No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                                                                    Jul 22, 2022 19:15:10.317090034 CEST8.8.8.8192.168.2.30x19f5No error (0)clients.l.google.com216.58.209.46A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:10.784298897 CEST8.8.8.8192.168.2.30xc5b8No error (0)locksmithelpasotexas.com173.231.223.247A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:11.580205917 CEST8.8.8.8192.168.2.30x711aNo error (0)voyage-croissant-31209.herokuapp.com23.22.144.165A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:11.580205917 CEST8.8.8.8192.168.2.30x711aNo error (0)voyage-croissant-31209.herokuapp.com23.22.52.7A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:11.580205917 CEST8.8.8.8192.168.2.30x711aNo error (0)voyage-croissant-31209.herokuapp.com3.219.96.23A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:11.580205917 CEST8.8.8.8192.168.2.30x711aNo error (0)voyage-croissant-31209.herokuapp.com3.216.88.24A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.070641041 CEST8.8.8.8192.168.2.30xad34No error (0)api.hostip.info104.21.84.241A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.070641041 CEST8.8.8.8192.168.2.30xad34No error (0)api.hostip.info172.67.199.103A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.352658033 CEST8.8.8.8192.168.2.30xa778No error (0)ipinfo.io34.117.59.81A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.535550117 CEST8.8.8.8192.168.2.30x73feNo error (0)hancott.biz79.110.52.9A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:13.809271097 CEST8.8.8.8192.168.2.30xf99cNo error (0)www.google.com142.251.209.4A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.786591053 CEST8.8.8.8192.168.2.30x13f2No error (0)www.google.com142.251.209.4A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.854995012 CEST8.8.8.8192.168.2.30x3ba4No error (0)voyage-croissant-31209.herokuapp.com23.22.52.7A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.854995012 CEST8.8.8.8192.168.2.30x3ba4No error (0)voyage-croissant-31209.herokuapp.com3.219.96.23A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.854995012 CEST8.8.8.8192.168.2.30x3ba4No error (0)voyage-croissant-31209.herokuapp.com3.216.88.24A (IP address)IN (0x0001)
                                                                    Jul 22, 2022 19:15:14.854995012 CEST8.8.8.8192.168.2.30x3ba4No error (0)voyage-croissant-31209.herokuapp.com23.22.144.165A (IP address)IN (0x0001)
                                                                    • accounts.google.com
                                                                    • clients2.google.com
                                                                    • locksmithelpasotexas.com
                                                                    • https:
                                                                      • voyage-croissant-31209.herokuapp.com
                                                                      • api.hostip.info
                                                                      • ipinfo.io
                                                                      • hancott.biz
                                                                      • www.google.com
                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    0192.168.2.349730142.250.180.141443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:10 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                                                    Host: accounts.google.com
                                                                    Connection: keep-alive
                                                                    Content-Length: 1
                                                                    Origin: https://www.google.com
                                                                    Content-Type: application/x-www-form-urlencoded
                                                                    Sec-Fetch-Site: none
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: empty
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:10 UTC0OUTData Raw: 20
                                                                    Data Ascii:
                                                                    2022-07-22 17:15:10 UTC2INHTTP/1.1 200 OK
                                                                    Content-Type: application/json; charset=utf-8
                                                                    Access-Control-Allow-Origin: https://www.google.com
                                                                    Access-Control-Allow-Credentials: true
                                                                    X-Content-Type-Options: nosniff
                                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                    Pragma: no-cache
                                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                    Date: Fri, 22 Jul 2022 17:15:10 GMT
                                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                                                    Content-Security-Policy: script-src 'report-sample' 'nonce-oZsb9We78Q2zJU26wbrRXg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                                                    Content-Security-Policy: script-src 'nonce-oZsb9We78Q2zJU26wbrRXg' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport
                                                                    Cross-Origin-Opener-Policy: same-origin
                                                                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                    Server: ESF
                                                                    X-XSS-Protection: 0
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                    Accept-Ranges: none
                                                                    Vary: Accept-Encoding
                                                                    Connection: close
                                                                    Transfer-Encoding: chunked
                                                                    2022-07-22 17:15:10 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                                                    Data Ascii: 11["gaia.l.a.r",[]]
                                                                    2022-07-22 17:15:10 UTC4INData Raw: 30 0d 0a 0d 0a
                                                                    Data Ascii: 0


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    1192.168.2.349731216.58.209.46443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:10 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                                                    Host: clients2.google.com
                                                                    Connection: keep-alive
                                                                    X-Goog-Update-Interactivity: fg
                                                                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfm
                                                                    X-Goog-Update-Updater: chromecrx-85.0.4183.121
                                                                    Sec-Fetch-Site: none
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: empty
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:10 UTC1INHTTP/1.1 200 OK
                                                                    Content-Security-Policy: script-src 'report-sample' 'nonce-I-QDzm7CwXcWgqS8pSJpOA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                                                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                    Pragma: no-cache
                                                                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                    Date: Fri, 22 Jul 2022 17:15:10 GMT
                                                                    Content-Type: text/xml; charset=UTF-8
                                                                    X-Daynum: 5681
                                                                    X-Daystart: 36910
                                                                    X-Content-Type-Options: nosniff
                                                                    X-Frame-Options: SAMEORIGIN
                                                                    X-XSS-Protection: 1; mode=block
                                                                    Server: GSE
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                    Accept-Ranges: none
                                                                    Vary: Accept-Encoding
                                                                    Connection: close
                                                                    Transfer-Encoding: chunked
                                                                    2022-07-22 17:15:10 UTC2INData Raw: 33 31 62 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 36 38 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 36 39 31 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                                                    Data Ascii: 31b<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5681" elapsed_seconds="36910"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                                                    2022-07-22 17:15:10 UTC2INData Raw: 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 61
                                                                    Data Ascii: mmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app><a
                                                                    2022-07-22 17:15:10 UTC2INData Raw: 30 0d 0a 0d 0a
                                                                    Data Ascii: 0


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    10192.168.2.349766142.251.209.4443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC25OUTGET /s2/favicons?domain=google.com HTTP/1.1
                                                                    Host: www.google.com
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: image
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC25INHTTP/1.1 301 Moved Permanently
                                                                    Location: https://t1.gstatic.com/faviconV2?client=SOCIAL&type=FAVICON&fallback_opts=TYPE,SIZE,URL&url=http://google.com&size=16
                                                                    X-Content-Type-Options: nosniff
                                                                    Server: sffe
                                                                    Content-Length: 330
                                                                    X-XSS-Protection: 0
                                                                    Date: Fri, 22 Jul 2022 16:49:07 GMT
                                                                    Expires: Fri, 22 Jul 2022 17:19:07 GMT
                                                                    Cache-Control: public, max-age=1800
                                                                    Content-Type: text/html; charset=UTF-8
                                                                    Age: 1566
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                    Connection: close
                                                                    2022-07-22 17:15:13 UTC26INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 74 31 2e 67 73 74 61 74 69 63 2e 63 6f 6d 2f 66 61 76 69 63 6f 6e 56 32 3f 63 6c 69 65 6e 74 3d 53 4f 43 49 41 4c 26 61 6d 70 3b 74 79 70 65 3d 46 41 56 49 43 4f 4e 26 61 6d 70 3b 66 61 6c 6c 62 61 63 6b 5f 6f 70 74 73 3d 54 59 50 45 2c
                                                                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>301 Moved</TITLE></HEAD><BODY><H1>301 Moved</H1>The document has moved<A HREF="https://t1.gstatic.com/faviconV2?client=SOCIAL&amp;type=FAVICON&amp;fallback_opts=TYPE,


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    11192.168.2.34976523.22.144.165443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:14 UTC26OUTGET /favicon.ico HTTP/1.1
                                                                    Host: voyage-croissant-31209.herokuapp.com
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8
                                                                    Sec-Fetch-Site: same-origin
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: image
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:14 UTC27INHTTP/1.1 404 Not Found
                                                                    Connection: close
                                                                    Date: Fri, 22 Jul 2022 17:15:14 GMT
                                                                    Server: Apache
                                                                    Content-Length: 196
                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                    Via: 1.1 vegur
                                                                    2022-07-22 17:15:14 UTC27INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    12192.168.2.349774142.251.209.4443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:14 UTC27OUTGET /s2/favicons?domain=google.com HTTP/1.1
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
                                                                    Host: www.google.com
                                                                    2022-07-22 17:15:14 UTC28INHTTP/1.1 301 Moved Permanently
                                                                    Location: https://t1.gstatic.com/faviconV2?client=SOCIAL&type=FAVICON&fallback_opts=TYPE,SIZE,URL&url=http://google.com&size=16
                                                                    X-Content-Type-Options: nosniff
                                                                    Server: sffe
                                                                    Content-Length: 330
                                                                    X-XSS-Protection: 0
                                                                    Date: Fri, 22 Jul 2022 16:49:07 GMT
                                                                    Expires: Fri, 22 Jul 2022 17:19:07 GMT
                                                                    Cache-Control: public, max-age=1800
                                                                    Content-Type: text/html; charset=UTF-8
                                                                    Age: 1567
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                                                                    Connection: close
                                                                    2022-07-22 17:15:14 UTC28INData Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 31 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 73 3a 2f 2f 74 31 2e 67 73 74 61 74 69 63 2e 63 6f 6d 2f 66 61 76 69 63 6f 6e 56 32 3f 63 6c 69 65 6e 74 3d 53 4f 43 49 41 4c 26 61 6d 70 3b 74 79 70 65 3d 46 41 56 49 43 4f 4e 26 61 6d 70 3b 66 61 6c 6c 62 61 63 6b 5f 6f 70 74 73 3d 54 59 50 45 2c
                                                                    Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>301 Moved</TITLE></HEAD><BODY><H1>301 Moved</H1>The document has moved<A HREF="https://t1.gstatic.com/faviconV2?client=SOCIAL&amp;type=FAVICON&amp;fallback_opts=TYPE,


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    2192.168.2.349735173.231.223.247443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:11 UTC4OUTGET /wp-content/plugins/mqdrxkc/2Factor.html HTTP/1.1
                                                                    Host: locksmithelpasotexas.com
                                                                    Connection: keep-alive
                                                                    Upgrade-Insecure-Requests: 1
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                                                    Sec-Fetch-Site: none
                                                                    Sec-Fetch-Mode: navigate
                                                                    Sec-Fetch-User: ?1
                                                                    Sec-Fetch-Dest: document
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:11 UTC5INHTTP/1.1 200 OK
                                                                    Server: nginx/1.21.6
                                                                    Date: Fri, 22 Jul 2022 17:15:11 GMT
                                                                    Content-Type: text/html
                                                                    Content-Length: 974
                                                                    Connection: close
                                                                    Vary: Accept-Encoding
                                                                    Strict-Transport-Security: max-age=31536000
                                                                    X-Content-Type-Options: nosniff
                                                                    X-XSS-Protection: 1; mode=block
                                                                    Expect-CT: max-age=7776000, enforce
                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                    Content-Security-Policy: upgrade-insecure-requests;
                                                                    Last-Modified: Fri, 22 Jul 2022 13:02:11 GMT
                                                                    X-Proxy-Cache: HIT
                                                                    Accept-Ranges: bytes
                                                                    2022-07-22 17:15:11 UTC5INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0d 0a 20 20 20 0d 0a 20 20 20 2f 2f 76 61 72 20 76 73 72 20 3d 20 67 65 74 55 72 6c 56 61 72 73 28 29 5b 22 76 73 72 22 5d 3b 0d 0a 20 20 20 76 61 72 20 76 73 72 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 2e 73 6c 69 63 65 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 2e 69 6e 64 65 78 4f 66 28 27 23 27 29 20 2b 20 31 29 3b 0d 0a 09 76 73 72 3d 20 64 65 63 6f 64 65 55 52 49 43 6f 6d 70 6f 6e 65 6e 74 28 76 73 72 29 3b 0d 0a 09 63 6f 6e 73 74 20 6d 79 41 72 72 61 79 20 3d 20 76 73 72 2e 73 70 6c 69 74 28 22 26 22 29 0d 0a 09 76 73 72 20 3d 20 77 69 6e 64 6f 77 2e 61 74 6f 62 28 6d 79 41 72 72 61 79
                                                                    Data Ascii: <html><script type="text/javascript"> //var vsr = getUrlVars()["vsr"]; var vsr = window.location.href.slice(window.location.href.indexOf('#') + 1);vsr= decodeURIComponent(vsr);const myArray = vsr.split("&")vsr = window.atob(myArray


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    3192.168.2.34974423.22.144.165443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:12 UTC6OUTGET /general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9 HTTP/1.1
                                                                    Host: voyage-croissant-31209.herokuapp.com
                                                                    Connection: keep-alive
                                                                    Upgrade-Insecure-Requests: 1
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: navigate
                                                                    Sec-Fetch-Dest: document
                                                                    Referer: https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:12 UTC7INHTTP/1.1 200 OK
                                                                    Connection: close
                                                                    Date: Fri, 22 Jul 2022 17:15:12 GMT
                                                                    Server: Apache
                                                                    Last-Modified: Thu, 14 Jul 2022 14:01:27 GMT
                                                                    Etag: "191b-5e3c456729bc0"
                                                                    Accept-Ranges: bytes
                                                                    Content-Length: 6427
                                                                    Content-Type: text/html
                                                                    Via: 1.1 vegur
                                                                    2022-07-22 17:15:12 UTC7INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 69 64 3d 22 53 74 65 6e 63 69 6c 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 30 22 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 66 6f 72 6d 61 74 2d 64 65 74 65 63 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 6c 65 70 68 6f 6e 65 3d 6e 6f 22 3e 0a 20 20 20 20 20 20 20 20 3c
                                                                    Data Ascii: <!DOCTYPE html><html id="Stencil" class="no-js"> <head> <meta charset="utf-8"> <meta name="viewport" content="initial-scale=1, maximum-scale=1, user-scalable=0"/> <meta name="format-detection" content="telephone=no"> <


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    4192.168.2.34974523.22.144.165443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:12 UTC14OUTGET /general/geo.js HTTP/1.1
                                                                    Host: voyage-croissant-31209.herokuapp.com
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: */*
                                                                    Sec-Fetch-Site: same-origin
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: script
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:12 UTC14INHTTP/1.1 200 OK
                                                                    Connection: close
                                                                    Date: Fri, 22 Jul 2022 17:15:12 GMT
                                                                    Server: Apache
                                                                    Last-Modified: Thu, 14 Jul 2022 14:01:27 GMT
                                                                    Etag: "6e6-5e3c456729bc0"
                                                                    Accept-Ranges: bytes
                                                                    Content-Length: 1766
                                                                    Content-Type: application/javascript
                                                                    Via: 1.1 vegur
                                                                    2022-07-22 17:15:12 UTC15INData Raw: 2f 2f 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 61 6a 61 78 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 61 6a 61 78 2f 6c 69 62 73 2f 6a 71 75 65 72 79 2f 33 2e 33 2e 31 2f 6a 71 75 65 72 79 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 0a 0a 0a 0a 0a 66 75 6e 63 74 69 6f 6e 20 67 65 74 43 6f 75 6e 74 72 79 28 29 7b 0a 09 76 61 72 20 49 50 61 64 64 72 65 73 73 20 3d 20 6d 79 49 50 28 29 3b 0a 24 2e 67 65 74 4a 53 4f 4e 28 22 68 74 74 70 73 3a 2f 2f 69 70 69 6e 66 6f 2e 69 6f 2f 22 2b 49 50 61 64 64 72 65 73 73 2c 20 66 75 6e 63 74 69 6f 6e 28 64 61 74 61 29 20 7b 0a 20 20 20 20 76 61 72 20 6c 6f 63 20 3d 20 64 61 74 61 2e 63 6f 75 6e 74 72 79 3b 0a 09 24 28 22 23 6c 6f 63 22 29 2e 76 61 6c 28 6c 6f 63 29 3b 0a 09 67 65
                                                                    Data Ascii: //<script src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>function getCountry(){var IPaddress = myIP();$.getJSON("https://ipinfo.io/"+IPaddress, function(data) { var loc = data.country;$("#loc").val(loc);ge


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    5192.168.2.349756104.21.84.241443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC16OUTGET /get_html.php HTTP/1.1
                                                                    Host: api.hostip.info
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: */*
                                                                    Origin: https://voyage-croissant-31209.herokuapp.com
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: cors
                                                                    Sec-Fetch-Dest: empty
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC18INHTTP/1.1 200 OK
                                                                    Date: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    Content-Type: text/plain; charset=iso-8859-1
                                                                    Transfer-Encoding: chunked
                                                                    Connection: close
                                                                    Expires: Sat, 23 Jul 2022 17:15:13 GMT
                                                                    Last-Modified: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    Cache-Control: public, max-age=86400
                                                                    Pragma: !invalid
                                                                    Access-Control-Allow-Origin: *
                                                                    Strict-Transport-Security: max-age=31536000
                                                                    CF-Cache-Status: DYNAMIC
                                                                    Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
                                                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=gxN7T%2FrDfOKZtljEyzfogoBYpvxtlymaAKy8Ft17fCSX3o1M5GcRKKhdKtu70zKxNjozn3QVNAUAZyLOBvJglLEk3TgXjuD7d7tHAzon6bVmZhNApLHmwa0ErsPK96gOqxY%3D"}],"group":"cf-nel","max_age":604800}
                                                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                    Server: cloudflare
                                                                    CF-RAY: 72edd12f6a2574a5-LHR
                                                                    alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
                                                                    2022-07-22 17:15:13 UTC19INData Raw: 33 38 0d 0a 43 6f 75 6e 74 72 79 3a 20 49 54 41 4c 59 20 28 49 54 29 0a 43 69 74 79 3a 20 28 55 6e 6b 6e 6f 77 6e 20 63 69 74 79 29 0a 49 50 3a 20 38 34 2e 31 37 2e 35 32 2e 32 0a 0d 0a
                                                                    Data Ascii: 38Country: ITALY (IT)City: (Unknown city)IP: 84.17.52.2
                                                                    2022-07-22 17:15:13 UTC19INData Raw: 30 0d 0a 0d 0a
                                                                    Data Ascii: 0


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    6192.168.2.34975423.22.144.165443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC17OUTGET /general/download.png HTTP/1.1
                                                                    Host: voyage-croissant-31209.herokuapp.com
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8
                                                                    Sec-Fetch-Site: same-origin
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: image
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/general/noRobot.html?usr=brian.williams@kraftmaid.com&interceptiontype=VerifyLogin&interceptiontype=VerifyLogin&service=freemail&successURL=https%3A%2F%sharepoint%2Flogin&statistics=xRbXFc8VKmF6s%2Frp6a5qP4z%2FNdyBHKIvfVNtKKZ%2FMq1vzDMmvcNacavpkSKc0VdsoMzKeZnxxL%2Fl2FTNDJCnPcIHjxpzAgCgOro1V2sZbBxg%3D%3D&username=sdada&requestSecurityToken=9f8d7962-0d22-4c86-8ab0-862cfe04d2e9
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC19INHTTP/1.1 200 OK
                                                                    Connection: close
                                                                    Date: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    Server: Apache
                                                                    Last-Modified: Thu, 14 Jul 2022 14:01:27 GMT
                                                                    Etag: "ad2-5e3c456729bc0"
                                                                    Accept-Ranges: bytes
                                                                    Content-Length: 2770
                                                                    Content-Type: image/png
                                                                    Via: 1.1 vegur
                                                                    2022-07-22 17:15:13 UTC19INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 c8 00 00 00 c8 08 03 00 00 00 9a 86 5e ac 00 00 00 b1 50 4c 54 45 ff ff ff ab ab ab 42 85 f4 1c 3a a9 a6 a6 a6 10 2f a4 3a 80 f4 a9 b4 de cf cf cf ae ae ae b5 b5 b5 d4 d4 d4 ca ca ca e9 e9 e9 f2 f2 f2 c5 c5 c5 61 99 f6 bd bd bd e0 e0 e0 dd e2 f2 b1 ad a7 7a a9 f7 85 9d c7 1e 42 b3 f9 f9 f9 33 4e b2 e0 eb fd de de de ba ba ba 0e 2e a4 ec ec ec 15 34 a7 50 67 bd 43 5b b8 c4 cc e9 6c 7f c7 85 96 d1 f5 f8 fe 95 bb f9 36 7a ef 6d a1 f7 5f 74 c2 9d c0 f9 76 88 cb cb dd fc d9 e7 fd 26 43 ad 9c a9 d9 aa c8 fa bf d6 fb 04 25 a0 8a b3 f8 d2 d8 ee 91 9f d5 e9 ec f6 50 8e f5 b7 c1 e4 c3 d9 fb 8c a1 c4 e8 5f 95 b7 00 00 09 dc 49 44 41 54 78 9c ed 9c 7b 7b a3 28 14 87 63 43 ac 57 1c ed ce 0e ad d6 f4 36 f7 4e 67
                                                                    Data Ascii: PNGIHDR^PLTEB:/:azB3N.4PgC[l6zm_tv&C%P_IDATx{{(cCW6Ng


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    7192.168.2.34975734.117.59.81443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC22OUTGET /%2084.17.52.2 HTTP/1.1
                                                                    Host: ipinfo.io
                                                                    Connection: keep-alive
                                                                    Accept: application/json, text/javascript, */*; q=0.01
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Origin: https://voyage-croissant-31209.herokuapp.com
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: cors
                                                                    Sec-Fetch-Dest: empty
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC22INHTTP/1.1 302 Found
                                                                    access-control-allow-origin: *
                                                                    x-frame-options: SAMEORIGIN
                                                                    x-xss-protection: 1; mode=block
                                                                    x-content-type-options: nosniff
                                                                    referrer-policy: strict-origin-when-cross-origin
                                                                    location: /84.17.52.2
                                                                    vary: Accept, Accept-Encoding
                                                                    content-type: text/plain; charset=utf-8
                                                                    content-length: 33
                                                                    date: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    x-envoy-upstream-service-time: 2
                                                                    strict-transport-security: max-age=2592000; includeSubDomains
                                                                    Via: 1.1 google
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                    Connection: close
                                                                    2022-07-22 17:15:13 UTC23INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 2f 38 34 2e 31 37 2e 35 32 2e 32
                                                                    Data Ascii: Found. Redirecting to /84.17.52.2


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    8192.168.2.34976434.117.59.81443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC23OUTGET /84.17.52.2 HTTP/1.1
                                                                    Host: ipinfo.io
                                                                    Connection: keep-alive
                                                                    Accept: application/json, text/javascript, */*; q=0.01
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Origin: https://voyage-croissant-31209.herokuapp.com
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: cors
                                                                    Sec-Fetch-Dest: empty
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC24INHTTP/1.1 200 OK
                                                                    access-control-allow-origin: *
                                                                    x-frame-options: SAMEORIGIN
                                                                    x-xss-protection: 1; mode=block
                                                                    x-content-type-options: nosniff
                                                                    referrer-policy: strict-origin-when-cross-origin
                                                                    content-type: application/json; charset=utf-8
                                                                    content-length: 289
                                                                    date: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    x-envoy-upstream-service-time: 3
                                                                    strict-transport-security: max-age=2592000; includeSubDomains
                                                                    vary: Accept-Encoding
                                                                    Via: 1.1 google
                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                    Connection: close
                                                                    2022-07-22 17:15:13 UTC24INData Raw: 7b 0a 20 20 22 69 70 22 3a 20 22 38 34 2e 31 37 2e 35 32 2e 32 22 2c 0a 20 20 22 68 6f 73 74 6e 61 6d 65 22 3a 20 22 75 6e 6e 2d 38 34 2d 31 37 2d 35 32 2d 32 2e 63 64 6e 37 37 2e 63 6f 6d 22 2c 0a 20 20 22 63 69 74 79 22 3a 20 22 5a c3 bc 72 69 63 68 22 2c 0a 20 20 22 72 65 67 69 6f 6e 22 3a 20 22 5a 75 72 69 63 68 22 2c 0a 20 20 22 63 6f 75 6e 74 72 79 22 3a 20 22 43 48 22 2c 0a 20 20 22 6c 6f 63 22 3a 20 22 34 37 2e 33 38 37 36 2c 38 2e 35 32 30 37 22 2c 0a 20 20 22 6f 72 67 22 3a 20 22 41 53 32 31 32 32 33 38 20 44 61 74 61 63 61 6d 70 20 4c 69 6d 69 74 65 64 22 2c 0a 20 20 22 70 6f 73 74 61 6c 22 3a 20 22 38 30 30 35 22 2c 0a 20 20 22 74 69 6d 65 7a 6f 6e 65 22 3a 20 22 45 75 72 6f 70 65 2f 5a 75 72 69 63 68 22 2c 0a 20 20 22 72 65 61 64 6d 65 22 3a
                                                                    Data Ascii: { "ip": "84.17.52.2", "hostname": "unn-84-17-52-2.cdn77.com", "city": "Zrich", "region": "Zurich", "country": "CH", "loc": "47.3876,8.5207", "org": "AS212238 Datacamp Limited", "postal": "8005", "timezone": "Europe/Zurich", "readme":


                                                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                    9192.168.2.34976379.110.52.9443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    TimestampkBytes transferredDirectionData
                                                                    2022-07-22 17:15:13 UTC23OUTGET /dns/valid.php?callback=jQuery331028936727179644905_1658542512723&domain=brian.williams%40kraftmaid.com&loc=&_=1658542512724 HTTP/1.1
                                                                    Host: hancott.biz
                                                                    Connection: keep-alive
                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
                                                                    Accept: */*
                                                                    Sec-Fetch-Site: cross-site
                                                                    Sec-Fetch-Mode: no-cors
                                                                    Sec-Fetch-Dest: script
                                                                    Referer: https://voyage-croissant-31209.herokuapp.com/
                                                                    Accept-Encoding: gzip, deflate, br
                                                                    Accept-Language: en-US,en;q=0.9
                                                                    2022-07-22 17:15:13 UTC24INHTTP/1.1 200 OK
                                                                    Date: Fri, 22 Jul 2022 17:15:13 GMT
                                                                    Server: Apache
                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                    Pragma: no-cache
                                                                    Set-Cookie: PHPSESSID=5acd4bd1386e307f96a842459a96412a; path=/
                                                                    Content-Length: 69
                                                                    Connection: close
                                                                    Content-Type: text/html; charset=UTF-8
                                                                    2022-07-22 17:15:13 UTC25INData Raw: 6a 51 75 65 72 79 33 33 31 30 32 38 39 33 36 37 32 37 31 37 39 36 34 34 39 30 35 5f 31 36 35 38 35 34 32 35 31 32 37 32 33 28 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 69 6d 65 63 61 73 74 2e 63 6f 6d 22 7d 29
                                                                    Data Ascii: jQuery331028936727179644905_1658542512723({"message":"mimecast.com"})


                                                                    Click to jump to process

                                                                    Click to jump to process

                                                                    Click to dive into process behavior distribution

                                                                    Click to jump to process

                                                                    Target ID:0
                                                                    Start time:19:15:06
                                                                    Start date:22/07/2022
                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                                                    Imagebase:0x7ff7f6290000
                                                                    File size:2150896 bytes
                                                                    MD5 hash:C139654B5C1438A95B321BB01AD63EF6
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:low

                                                                    Target ID:1
                                                                    Start time:19:15:07
                                                                    Start date:22/07/2022
                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1604,18173075307747983275,7024365074969089678,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1928 /prefetch:8
                                                                    Imagebase:0x7ff7f6290000
                                                                    File size:2150896 bytes
                                                                    MD5 hash:C139654B5C1438A95B321BB01AD63EF6
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:low

                                                                    Target ID:2
                                                                    Start time:19:15:08
                                                                    Start date:22/07/2022
                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://locksmithelpasotexas.com/wp-content/plugins/mqdrxkc/2Factor.html#YnJpYW4ud2lsbGlhbXNAa3JhZnRtYWlkLmNvbQ==&target=_blank
                                                                    Imagebase:0x7ff7f6290000
                                                                    File size:2150896 bytes
                                                                    MD5 hash:C139654B5C1438A95B321BB01AD63EF6
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:low

                                                                    No disassembly