Create Interactive Tour

Windows Analysis Report
http://h.parrable.com

Overview

General Information

Sample URL:http://h.parrable.com
Analysis ID:698230
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4896 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5564 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1936 --field-trial-handle=1784,i,2513098405004586722,15967348303203370874,131072 /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6012 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://h.parrable.com MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://h.parrable.comAvira URL Cloud: detection malicious, Label: malware
Source: https://h.parrable.com/favicon.icoAvira URL Cloud: Label: malware
Source: http://h.parrable.com/Avira URL Cloud: Label: malware
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: h.parrable.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: h.parrable.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://h.parrable.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _test_cookie=true
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: h.parrable.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 06 Sep 2022 14:02:34 GMTContent-Type: image/x-iconContent-Length: 2Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: mal56.win@32/0@4/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1936 --field-trial-handle=1784,i,2513098405004586722,15967348303203370874,131072 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://h.parrable.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1936 --field-trial-handle=1784,i,2513098405004586722,15967348303203370874,131072 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://h.parrable.comJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 698230 URL: http://h.parrable.com Startdate: 06/09/2022 Architecture: WINDOWS Score: 56 26 Antivirus detection for URL or domain 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 6 chrome.exe 13 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.1 unknown unknown 6->14 16 192.168.2.30 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 accounts.google.com 142.250.184.237, 443, 49722, 49725 GOOGLEUS United States 11->20 22 www.google.com 142.250.185.164, 443, 49728, 49815 GOOGLEUS United States 11->22 24 4 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://h.parrable.com5%VirustotalBrowse
http://h.parrable.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://h.parrable.com/favicon.ico100%Avira URL Cloudmalware
http://h.parrable.com/100%Avira URL Cloudmalware
http://h.parrable.com/5%VirustotalBrowse
https://h.parrable.com/5%VirustotalBrowse
https://h.parrable.com/favicon.ico5%VirustotalBrowse

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.184.237
truefalse
    high
    www.google.com
    142.250.185.164
    truefalse
      high
      clients.l.google.com
      142.250.186.142
      truefalse
        high
        h.parrable.com
        35.196.86.86
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://h.parrable.com/falseunknown
              https://h.parrable.com/trueunknown
              https://h.parrable.com/favicon.icofalse
              • 5%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://h.parrable.com/false
                • 5%, Virustotal, Browse
                • Avira URL Cloud: malware
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                35.196.86.86
                h.parrable.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.185.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                142.250.186.142
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                142.250.184.237
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.1
                192.168.2.30
                127.0.0.1
                Joe Sandbox Version:35.0.0 Citrine
                Analysis ID:698230
                Start date and time:2022-09-06 16:01:23 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 4m 45s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://h.parrable.com
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:19
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal56.win@32/0@4/8
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Adjust boot time
                • Enable AMSI
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.185.131, 142.250.186.78, 74.125.8.167, 142.250.185.74, 142.250.186.131
                • Excluded domains from analysis (whitelisted): r1---sn-5hne6nzk.gvt1.com, r2---sn-5hne6n6l.gvt1.com, client.wns.windows.com, fs.microsoft.com, redirector.gvt1.com, r2.sn-5hne6n6l.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com, optimizationguide-pa.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 104
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Sep 6, 2022 16:02:29.480367899 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.480433941 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.480578899 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.480735064 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.480778933 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.480846882 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.481908083 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.481942892 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.482033968 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.482215881 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.482249022 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.482336044 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.483124971 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.483136892 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.483163118 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.483191013 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.483448982 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.483469009 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.483597040 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.483613968 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.535468102 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.536098957 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.538979053 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.540298939 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.541184902 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.541219950 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.541604042 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.541706085 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.542124033 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.542150974 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.542428970 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.542468071 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.542957067 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.543032885 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.543159962 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.543179989 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.543186903 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.543279886 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.543813944 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.543914080 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:29.544291019 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:29.544369936 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:29.545893908 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:29.546017885 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.199094057 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.199290991 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.202505112 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.202693939 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.202807903 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.202836990 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.206717968 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.207284927 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.231738091 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.231862068 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.231940985 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.236664057 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.268326998 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.268368006 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.271482944 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.272021055 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.279608965 CEST49726443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.279645920 CEST44349726142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.318094969 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.318171978 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.318186045 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.318460941 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.318521023 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.363598108 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.363604069 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.363619089 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:31.363645077 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:02:31.535451889 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:02:31.536822081 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.825860977 CEST49725443192.168.2.3142.250.184.237
                Sep 6, 2022 16:02:31.825898886 CEST44349725142.250.184.237192.168.2.3
                Sep 6, 2022 16:02:32.017455101 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.017524958 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.017705917 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.018184900 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.018205881 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.069021940 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.145874977 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.213804960 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.213833094 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.215084076 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.215164900 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.215233088 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.219681978 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.219894886 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.345887899 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.345918894 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:32.538691044 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:32.885936022 CEST4973280192.168.2.335.196.86.86
                Sep 6, 2022 16:02:32.886826992 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.032620907 CEST804973235.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.033301115 CEST804973335.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.044562101 CEST4973280192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.044599056 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.048067093 CEST4973480192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.048981905 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.195262909 CEST804973435.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.195478916 CEST4973480192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.196352959 CEST804973335.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.196387053 CEST804973335.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.220413923 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.220455885 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.220539093 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.221183062 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.221199036 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.266777992 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.673808098 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.675307035 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.675339937 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.676815033 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.676933050 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.680464029 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.680679083 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.680694103 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.680722952 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.766813993 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.766839981 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.830563068 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:33.830647945 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.897034883 CEST49736443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:33.897075891 CEST4434973635.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.222038984 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.222103119 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.222213030 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.222917080 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.222938061 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.665116072 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.666961908 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.666997910 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.667499065 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.668910027 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.669054985 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.669143915 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:34.711385965 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.815814018 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.815907001 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.831379890 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:34.871296883 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:35.003467083 CEST49737443192.168.2.335.196.86.86
                Sep 6, 2022 16:02:35.003515959 CEST4434973735.196.86.86192.168.2.3
                Sep 6, 2022 16:02:42.068203926 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:42.068337917 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:02:42.068447113 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:42.584872007 CEST49728443192.168.2.3142.250.185.164
                Sep 6, 2022 16:02:42.584906101 CEST44349728142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:16.368302107 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:03:16.368316889 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:03:16.368321896 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:03:16.368343115 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:03:18.118552923 CEST4973280192.168.2.335.196.86.86
                Sep 6, 2022 16:03:18.228815079 CEST4973480192.168.2.335.196.86.86
                Sep 6, 2022 16:03:18.265505075 CEST804973235.196.86.86192.168.2.3
                Sep 6, 2022 16:03:18.274765015 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:03:18.375401974 CEST804973435.196.86.86192.168.2.3
                Sep 6, 2022 16:03:18.421444893 CEST804973335.196.86.86192.168.2.3
                Sep 6, 2022 16:03:30.936269999 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:30.936350107 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:30.936450958 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:30.937268972 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:30.937310934 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:30.985141039 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:30.985456944 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:30.985496998 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:30.986162901 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:30.986646891 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:30.986812115 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:31.028423071 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:32.436887980 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:03:32.437000036 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:03:32.437123060 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:03:32.437165022 CEST44349722142.250.184.237192.168.2.3
                Sep 6, 2022 16:03:32.437212944 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:03:32.437251091 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:03:32.437272072 CEST49722443192.168.2.3142.250.184.237
                Sep 6, 2022 16:03:32.437297106 CEST44349723142.250.186.142192.168.2.3
                Sep 6, 2022 16:03:32.437319994 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:03:32.437351942 CEST49723443192.168.2.3142.250.186.142
                Sep 6, 2022 16:03:33.191154003 CEST804973235.196.86.86192.168.2.3
                Sep 6, 2022 16:03:33.191342115 CEST4973280192.168.2.335.196.86.86
                Sep 6, 2022 16:03:33.345838070 CEST804973435.196.86.86192.168.2.3
                Sep 6, 2022 16:03:33.345988035 CEST4973480192.168.2.335.196.86.86
                Sep 6, 2022 16:03:34.474948883 CEST4973480192.168.2.335.196.86.86
                Sep 6, 2022 16:03:34.474961996 CEST4973280192.168.2.335.196.86.86
                Sep 6, 2022 16:03:34.621052980 CEST804973235.196.86.86192.168.2.3
                Sep 6, 2022 16:03:34.621079922 CEST804973435.196.86.86192.168.2.3
                Sep 6, 2022 16:03:40.976522923 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:40.976615906 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:40.976747036 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:42.486118078 CEST49815443192.168.2.3142.250.185.164
                Sep 6, 2022 16:03:42.486151934 CEST44349815142.250.185.164192.168.2.3
                Sep 6, 2022 16:03:48.197043896 CEST804973335.196.86.86192.168.2.3
                Sep 6, 2022 16:03:48.197698116 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:03:48.437536955 CEST4973380192.168.2.335.196.86.86
                Sep 6, 2022 16:03:48.584201097 CEST804973335.196.86.86192.168.2.3
                TimestampSource PortDest PortSource IPDest IP
                Sep 6, 2022 16:02:29.335585117 CEST6205053192.168.2.38.8.8.8
                Sep 6, 2022 16:02:29.339993000 CEST5963653192.168.2.38.8.8.8
                Sep 6, 2022 16:02:29.363327026 CEST53620508.8.8.8192.168.2.3
                Sep 6, 2022 16:02:29.378834963 CEST53596368.8.8.8192.168.2.3
                Sep 6, 2022 16:02:31.277884960 CEST5770453192.168.2.38.8.8.8
                Sep 6, 2022 16:02:31.297384977 CEST53577048.8.8.8192.168.2.3
                Sep 6, 2022 16:02:32.810033083 CEST5757153192.168.2.38.8.8.8
                Sep 6, 2022 16:02:32.829658985 CEST53575718.8.8.8192.168.2.3
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                Sep 6, 2022 16:02:29.335585117 CEST192.168.2.38.8.8.80x2785Standard query (0)accounts.google.comA (IP address)IN (0x0001)
                Sep 6, 2022 16:02:29.339993000 CEST192.168.2.38.8.8.80x583dStandard query (0)clients2.google.comA (IP address)IN (0x0001)
                Sep 6, 2022 16:02:31.277884960 CEST192.168.2.38.8.8.80xf25fStandard query (0)www.google.comA (IP address)IN (0x0001)
                Sep 6, 2022 16:02:32.810033083 CEST192.168.2.38.8.8.80x537fStandard query (0)h.parrable.comA (IP address)IN (0x0001)
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                Sep 6, 2022 16:02:29.363327026 CEST8.8.8.8192.168.2.30x2785No error (0)accounts.google.com142.250.184.237A (IP address)IN (0x0001)
                Sep 6, 2022 16:02:29.378834963 CEST8.8.8.8192.168.2.30x583dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                Sep 6, 2022 16:02:29.378834963 CEST8.8.8.8192.168.2.30x583dNo error (0)clients.l.google.com142.250.186.142A (IP address)IN (0x0001)
                Sep 6, 2022 16:02:31.297384977 CEST8.8.8.8192.168.2.30xf25fNo error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)
                Sep 6, 2022 16:02:32.829658985 CEST8.8.8.8192.168.2.30x537fNo error (0)h.parrable.com35.196.86.86A (IP address)IN (0x0001)
                • clients2.google.com
                • accounts.google.com
                • h.parrable.com
                • https:
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349726142.250.186.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349725142.250.184.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.34973635.196.86.86443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.34973735.196.86.86443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                4192.168.2.34973335.196.86.8680C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Sep 6, 2022 16:02:33.048981905 CEST787OUTGET / HTTP/1.1
                Host: h.parrable.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Sep 6, 2022 16:02:33.196387053 CEST789INHTTP/1.1 301 Moved Permanently
                Date: Tue, 06 Sep 2022 14:02:33 GMT
                Content-Type: text/html
                Content-Length: 166
                Connection: keep-alive
                Location: https://h.parrable.com/
                Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>openresty</center></body></html>
                Sep 6, 2022 16:03:18.274765015 CEST36184OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                5192.168.2.34973235.196.86.8680C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Sep 6, 2022 16:03:18.118552923 CEST36184OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                6192.168.2.34973435.196.86.8680C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Sep 6, 2022 16:03:18.228815079 CEST36184OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349726142.250.186.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-09-06 14:02:31 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-09-06 14:02:31 UTC0INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-pbUMSgJdbuhAnml7js-x3g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Tue, 06 Sep 2022 14:02:31 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5727
                X-Daystart: 25351
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-09-06 14:02:31 UTC1INData Raw: 32 63 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 37 32 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 35 33 35 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2ca<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5727" elapsed_seconds="25351"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2022-09-06 14:02:31 UTC1INData Raw: 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f
                Data Ascii: mmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></
                2022-09-06 14:02:31 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349725142.250.184.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-09-06 14:02:31 UTC2OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                2022-09-06 14:02:31 UTC3OUTData Raw: 20
                Data Ascii:
                2022-09-06 14:02:31 UTC3INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Tue, 06 Sep 2022 14:02:31 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-YMKCtIgd0nSEXT_ELC6KXg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-platform=*, ch-ua-platform-version=*
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-09-06 14:02:31 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2022-09-06 14:02:31 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.34973635.196.86.86443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-09-06 14:02:33 UTC4OUTGET / HTTP/1.1
                Host: h.parrable.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-09-06 14:02:33 UTC5INHTTP/1.1 200
                Date: Tue, 06 Sep 2022 14:02:33 GMT
                Content-Type: application/json
                Content-Length: 87
                Connection: close
                Set-Cookie: _test_cookie=true; Domain=h.parrable.com; Expires=Wed, 07 Sep 2022 14:02:33 GMT; Secure; SameSite=None
                Access-Control-Allow-Credentials: true
                2022-09-06 14:02:33 UTC5INData Raw: 7b 22 6f 70 74 6f 75 74 22 3a 66 61 6c 73 65 2c 22 69 62 61 4f 70 74 6f 75 74 22 3a 66 61 6c 73 65 2c 22 63 63 70 61 4f 70 74 6f 75 74 22 3a 66 61 6c 73 65 2c 22 65 69 64 22 3a 6e 75 6c 6c 2c 22 65 72 72 6f 72 22 3a 22 73 65 72 76 65 72 20 65 72 72 6f 72 22 7d
                Data Ascii: {"optout":false,"ibaOptout":false,"ccpaOptout":false,"eid":null,"error":"server error"}


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.34973735.196.86.86443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-09-06 14:02:34 UTC5OUTGET /favicon.ico HTTP/1.1
                Host: h.parrable.com
                Connection: keep-alive
                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://h.parrable.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: _test_cookie=true
                2022-09-06 14:02:34 UTC6INHTTP/1.1 404 Not Found
                Date: Tue, 06 Sep 2022 14:02:34 GMT
                Content-Type: image/x-icon
                Content-Length: 2
                Connection: close
                2022-09-06 14:02:34 UTC6INData Raw: 7b 7d
                Data Ascii: {}


                020406080100s020406080100

                Click to jump to process

                020406080100s0.0020406080100MB

                Click to jump to process

                • File
                • Registry

                Click to dive into process behavior distribution

                Target ID:0
                Start time:16:02:21
                Start date:06/09/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                Target ID:3
                Start time:16:02:24
                Start date:06/09/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1936 --field-trial-handle=1784,i,2513098405004586722,15967348303203370874,131072 /prefetch:8
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:4
                Start time:16:02:26
                Start date:06/09/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://h.parrable.com
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly