Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://cdn.ayc0zsm69431gfebd.xyz

Overview

General Information

Sample URL:http://cdn.ayc0zsm69431gfebd.xyz
Analysis ID:698366
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Performs DNS queries to domains with low reputation

Classification

  • System is w10x64
  • chrome.exe (PID: 4600 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 6188 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1568 --field-trial-handle=1776,i,1772263521914058094,11622399945766028648,131072 /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6356 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.ayc0zsm69431gfebd.xyz MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://cdn.ayc0zsm69431gfebd.xyzAvira URL Cloud: detection malicious, Label: phishing
Source: http://cdn.ayc0zsm69431gfebd.xyz/favicon.icoAvira URL Cloud: Label: phishing
Source: http://cdn.ayc0zsm69431gfebd.xyz/Avira URL Cloud: Label: phishing
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: cdn.ayc0zsm69431gfebd.xyz
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: cdn.ayc0zsm69431gfebd.xyzConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cdn.ayc0zsm69431gfebd.xyzConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://cdn.ayc0zsm69431gfebd.xyz/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: x-ms-request-id,Server,Content-Length,Date,Transfer-EncodingContent-Type: application/xmlDate: Tue, 06 Sep 2022 16:34:38 GMTServer: Blob Service Version 1.0 Microsoft-HTTPAPI/2.0x-ms-request-id: 4e599a07-501e-0061-690e-c2d4fd000000Content-Length: 223Data Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 52 65 73 6f 75 72 63 65 4e 6f 74 46 6f 75 6e 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 72 65 73 6f 75 72 63 65 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 0a 52 65 71 75 65 73 74 49 64 3a 34 65 35 39 39 61 30 37 2d 35 30 31 65 2d 30 30 36 31 2d 36 39 30 65 2d 63 32 64 34 66 64 30 30 30 30 30 30 0a 54 69 6d 65 3a 32 30 32 32 2d 30 39 2d 30 36 54 31 36 3a 33 34 3a 33 38 2e 32 31 33 36 38 31 33 5a 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e Data Ascii: <?xml version="1.0" encoding="utf-8"?><Error><Code>ResourceNotFound</Code><Message>The specified resource does not exist.RequestId:4e599a07-501e-0061-690e-c2d4fd000000Time:2022-09-06T16:34:38.2136813Z</Message></Error>
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Length,Date,Transfer-EncodingContent-Type: application/xmlDate: Tue, 06 Sep 2022 16:34:38 GMTServer: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0x-ms-request-id: 9b8f4ffc-f01e-0035-790e-c29baa000000x-ms-version: 2009-09-19Content-Length: 215Data Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 42 6c 6f 62 4e 6f 74 46 6f 75 6e 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 62 6c 6f 62 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 0a 52 65 71 75 65 73 74 49 64 3a 39 62 38 66 34 66 66 63 2d 66 30 31 65 2d 30 30 33 35 2d 37 39 30 65 2d 63 32 39 62 61 61 30 30 30 30 30 30 0a 54 69 6d 65 3a 32 30 32 32 2d 30 39 2d 30 36 54 31 36 3a 33 34 3a 33 38 2e 37 33 32 30 35 33 31 5a 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e Data Ascii: <?xml version="1.0" encoding="utf-8"?><Error><Code>BlobNotFound</Code><Message>The specified blob does not exist.RequestId:9b8f4ffc-f01e-0035-790e-c29baa000000Time:2022-09-06T16:34:38.7320531Z</Message></Error>
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: mal60.troj.win@32/0@4/10
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1568 --field-trial-handle=1776,i,1772263521914058094,11622399945766028648,131072 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.ayc0zsm69431gfebd.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1568 --field-trial-handle=1776,i,1772263521914058094,11622399945766028648,131072 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://cdn.ayc0zsm69431gfebd.xyz5%VirustotalBrowse
http://cdn.ayc0zsm69431gfebd.xyz100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://cdn.ayc0zsm69431gfebd.xyz/favicon.ico0%VirustotalBrowse
http://cdn.ayc0zsm69431gfebd.xyz/favicon.ico100%Avira URL Cloudphishing
http://cdn.ayc0zsm69431gfebd.xyz/5%VirustotalBrowse
http://cdn.ayc0zsm69431gfebd.xyz/100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.184.237
truefalse
    high
    www.google.com
    142.250.185.164
    truefalse
      high
      clients.l.google.com
      142.250.186.142
      truefalse
        high
        sni1gl.wpc.thetacdn.net
        152.199.21.175
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            cdn.ayc0zsm69431gfebd.xyz
            unknown
            unknowntrue
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                http://cdn.ayc0zsm69431gfebd.xyz/favicon.icotrue
                • 0%, Virustotal, Browse
                • Avira URL Cloud: phishing
                unknown
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  http://cdn.ayc0zsm69431gfebd.xyz/true
                  • 5%, Virustotal, Browse
                  • Avira URL Cloud: phishing
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.185.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.186.142
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  152.199.21.175
                  sni1gl.wpc.thetacdn.netUnited States
                  15133EDGECASTUSfalse
                  142.250.184.237
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  192.168.2.3
                  192.168.2.6
                  192.168.2.5
                  127.0.0.1
                  Joe Sandbox Version:35.0.0 Citrine
                  Analysis ID:698366
                  Start date and time:2022-09-06 18:33:24 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 54s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://cdn.ayc0zsm69431gfebd.xyz
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:16
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal60.troj.win@32/0@4/10
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Adjust boot time
                  • Enable AMSI
                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, SgrmBroker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.186.78, 74.125.160.202, 142.250.181.234, 142.250.186.131
                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, r5.sn-4g5lznez.gvt1.com, connext-cdn.ec.azureedge.net, ris.api.iris.microsoft.com, connext-cdn.azureedge.net, ocsp.digicert.com, redirector.gvt1.com, store-images.s-microsoft.com, login.live.com, update.googleapis.com, img-prod-cms-rt-microsoft-com.akamaized.net, r5---sn-4g5lznez.gvt1.com, r4---sn-4g5lznez.gvt1.com, optimizationguide-pa.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 6, 2022 18:34:36.652101040 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:36.652168989 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.652286053 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:36.658926010 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:36.658961058 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.661179066 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.661227942 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.661344051 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.661652088 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.661667109 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.717051029 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.723200083 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.811337948 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.811372995 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.811541080 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:36.811569929 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.812206984 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.812227011 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.812303066 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.813829899 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:36.813939095 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.814018011 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:36.814558983 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:36.814563036 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.650341988 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:37.650554895 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.650705099 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:37.650752068 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.650964022 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.651120901 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.651259899 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.651285887 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.676861048 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.676903963 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.677000999 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.678826094 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.678844929 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.680073977 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.680181026 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:37.680207968 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.680754900 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.680845022 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:37.682075024 CEST49751443192.168.2.7142.250.186.142
                  Sep 6, 2022 18:34:37.682100058 CEST44349751142.250.186.142192.168.2.7
                  Sep 6, 2022 18:34:37.699194908 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.699310064 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.699332952 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.699368954 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.699430943 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.702739954 CEST49750443192.168.2.7142.250.184.237
                  Sep 6, 2022 18:34:37.702759027 CEST44349750142.250.184.237192.168.2.7
                  Sep 6, 2022 18:34:37.738864899 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.750940084 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.750972033 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.752305031 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.752423048 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.771322012 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:37.771502972 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.979387045 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:37.979554892 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:38.053613901 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.054346085 CEST4975680192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.073147058 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.073307037 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.073889971 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.074564934 CEST8049756152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.074654102 CEST4975680192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.093010902 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.270005941 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.390328884 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.592516899 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:38.611756086 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.788891077 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:34:38.907375097 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:34:47.727879047 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:47.728014946 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:34:47.728108883 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:48.231432915 CEST49752443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:34:48.231467962 CEST44349752142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:23.097642899 CEST4975680192.168.2.7152.199.21.175
                  Sep 6, 2022 18:35:23.117643118 CEST8049756152.199.21.175192.168.2.7
                  Sep 6, 2022 18:35:23.908956051 CEST4975580192.168.2.7152.199.21.175
                  Sep 6, 2022 18:35:23.928302050 CEST8049755152.199.21.175192.168.2.7
                  Sep 6, 2022 18:35:37.376127005 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:37.376184940 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.376327038 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:37.376627922 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:37.376681089 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.431119919 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.431538105 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:37.431566000 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.433374882 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.433954000 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:37.434087992 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:37.608143091 CEST49818443192.168.2.7142.250.185.164
                  Sep 6, 2022 18:35:38.449559927 CEST8049756152.199.21.175192.168.2.7
                  Sep 6, 2022 18:35:38.449656010 CEST4975680192.168.2.7152.199.21.175
                  Sep 6, 2022 18:35:47.418324947 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:47.418417931 CEST44349818142.250.185.164192.168.2.7
                  Sep 6, 2022 18:35:47.418556929 CEST49818443192.168.2.7142.250.185.164
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 6, 2022 18:34:36.028139114 CEST5083553192.168.2.78.8.8.8
                  Sep 6, 2022 18:34:36.030297041 CEST5050553192.168.2.78.8.8.8
                  Sep 6, 2022 18:34:36.047522068 CEST53505058.8.8.8192.168.2.7
                  Sep 6, 2022 18:34:36.047835112 CEST53508358.8.8.8192.168.2.7
                  Sep 6, 2022 18:34:37.641674995 CEST6392653192.168.2.78.8.8.8
                  Sep 6, 2022 18:34:37.661170006 CEST53639268.8.8.8192.168.2.7
                  Sep 6, 2022 18:34:38.004843950 CEST5051353192.168.2.78.8.8.8
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                  Sep 6, 2022 18:34:36.028139114 CEST192.168.2.78.8.8.80x70b0Standard query (0)clients2.google.comA (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:36.030297041 CEST192.168.2.78.8.8.80x4986Standard query (0)accounts.google.comA (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:37.641674995 CEST192.168.2.78.8.8.80x34b0Standard query (0)www.google.comA (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:38.004843950 CEST192.168.2.78.8.8.80x824eStandard query (0)cdn.ayc0zsm69431gfebd.xyzA (IP address)IN (0x0001)
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                  Sep 6, 2022 18:34:36.047522068 CEST8.8.8.8192.168.2.70x4986No error (0)accounts.google.com142.250.184.237A (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:36.047835112 CEST8.8.8.8192.168.2.70x70b0No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                  Sep 6, 2022 18:34:36.047835112 CEST8.8.8.8192.168.2.70x70b0No error (0)clients.l.google.com142.250.186.142A (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:37.661170006 CEST8.8.8.8192.168.2.70x34b0No error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)
                  Sep 6, 2022 18:34:38.027753115 CEST8.8.8.8192.168.2.70x824eNo error (0)cdn.ayc0zsm69431gfebd.xyzconnext-cdn.azureedge.netCNAME (Canonical name)IN (0x0001)
                  Sep 6, 2022 18:34:38.027753115 CEST8.8.8.8192.168.2.70x824eNo error (0)scdn1.wpc.45235.thetacdn.netsni1gl.wpc.thetacdn.netCNAME (Canonical name)IN (0x0001)
                  Sep 6, 2022 18:34:38.027753115 CEST8.8.8.8192.168.2.70x824eNo error (0)sni1gl.wpc.thetacdn.net152.199.21.175A (IP address)IN (0x0001)
                  • clients2.google.com
                  • accounts.google.com
                  • cdn.ayc0zsm69431gfebd.xyz
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.749751142.250.186.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.749750142.250.184.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  2192.168.2.749755152.199.21.17580C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  Sep 6, 2022 18:34:38.073889971 CEST1183OUTGET / HTTP/1.1
                  Host: cdn.ayc0zsm69431gfebd.xyz
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Sep 6, 2022 18:34:38.270005941 CEST1430INHTTP/1.1 404 Not Found
                  Access-Control-Allow-Origin: *
                  Access-Control-Expose-Headers: x-ms-request-id,Server,Content-Length,Date,Transfer-Encoding
                  Content-Type: application/xml
                  Date: Tue, 06 Sep 2022 16:34:38 GMT
                  Server: Blob Service Version 1.0 Microsoft-HTTPAPI/2.0
                  x-ms-request-id: 4e599a07-501e-0061-690e-c2d4fd000000
                  Content-Length: 223
                  Data Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 52 65 73 6f 75 72 63 65 4e 6f 74 46 6f 75 6e 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 72 65 73 6f 75 72 63 65 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 0a 52 65 71 75 65 73 74 49 64 3a 34 65 35 39 39 61 30 37 2d 35 30 31 65 2d 30 30 36 31 2d 36 39 30 65 2d 63 32 64 34 66 64 30 30 30 30 30 30 0a 54 69 6d 65 3a 32 30 32 32 2d 30 39 2d 30 36 54 31 36 3a 33 34 3a 33 38 2e 32 31 33 36 38 31 33 5a 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><Error><Code>ResourceNotFound</Code><Message>The specified resource does not exist.RequestId:4e599a07-501e-0061-690e-c2d4fd000000Time:2022-09-06T16:34:38.2136813Z</Message></Error>
                  Sep 6, 2022 18:34:38.592516899 CEST1441OUTGET /favicon.ico HTTP/1.1
                  Host: cdn.ayc0zsm69431gfebd.xyz
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Referer: http://cdn.ayc0zsm69431gfebd.xyz/
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Sep 6, 2022 18:34:38.788891077 CEST1445INHTTP/1.1 404 Not Found
                  Access-Control-Allow-Origin: *
                  Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Length,Date,Transfer-Encoding
                  Content-Type: application/xml
                  Date: Tue, 06 Sep 2022 16:34:38 GMT
                  Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
                  x-ms-request-id: 9b8f4ffc-f01e-0035-790e-c29baa000000
                  x-ms-version: 2009-09-19
                  Content-Length: 215
                  Data Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 42 6c 6f 62 4e 6f 74 46 6f 75 6e 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 62 6c 6f 62 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 0a 52 65 71 75 65 73 74 49 64 3a 39 62 38 66 34 66 66 63 2d 66 30 31 65 2d 30 30 33 35 2d 37 39 30 65 2d 63 32 39 62 61 61 30 30 30 30 30 30 0a 54 69 6d 65 3a 32 30 32 32 2d 30 39 2d 30 36 54 31 36 3a 33 34 3a 33 38 2e 37 33 32 30 35 33 31 5a 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><Error><Code>BlobNotFound</Code><Message>The specified blob does not exist.RequestId:9b8f4ffc-f01e-0035-790e-c29baa000000Time:2022-09-06T16:34:38.7320531Z</Message></Error>
                  Sep 6, 2022 18:35:23.908956051 CEST36776OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  3192.168.2.749756152.199.21.17580C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  Sep 6, 2022 18:35:23.097642899 CEST36776OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.749751142.250.186.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2022-09-06 16:34:37 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2022-09-06 16:34:37 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-rO48Nq81aelJykBnw8sT1g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 06 Sep 2022 16:34:37 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5727
                  X-Daystart: 34477
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2022-09-06 16:34:37 UTC2INData Raw: 32 63 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 37 32 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 34 34 37 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2ca<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5727" elapsed_seconds="34477"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2022-09-06 16:34:37 UTC2INData Raw: 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f
                  Data Ascii: mmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></
                  2022-09-06 16:34:37 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.749750142.250.184.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2022-09-06 16:34:37 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2022-09-06 16:34:37 UTC1OUTData Raw: 20
                  Data Ascii:
                  2022-09-06 16:34:37 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 06 Sep 2022 16:34:37 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Content-Security-Policy: script-src 'report-sample' 'nonce-h7_fG7W30blXQwXQkcJpYA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2022-09-06 16:34:37 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2022-09-06 16:34:37 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:18:34:28
                  Start date:06/09/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:34:31
                  Start date:06/09/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1568 --field-trial-handle=1776,i,1772263521914058094,11622399945766028648,131072 /prefetch:8
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:4
                  Start time:18:34:32
                  Start date:06/09/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cdn.ayc0zsm69431gfebd.xyz
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly