Edit tour

Windows Analysis Report
https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhc

Overview

General Information

Sample URL:https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/part
Analysis ID:710636
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4596 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1316 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1760 --field-trial-handle=1792,i,871456357474917075,7546000180816737014,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 4136 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709 HTTP/1.1Host: dl-mail.ymail.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00 HTTP/1.1Host: apis.mail.yahoo.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: apis.mail.yahoo.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: dl-mail.ymail.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: classification engineClassification label: clean0.win@26/0@6/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1760 --field-trial-handle=1792,i,871456357474917075,7546000180816737014,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1760 --field-trial-handle=1792,i,871456357474917075,7546000180816737014,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 710636 URL: https://dl-mail.ymail.com/w... Startdate: 27/09/2022 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 edge.gycpi.b.yahoodns.net 87.248.119.251, 443, 49708, 49712 YAHOO-DEBDE United Kingdom 10->17 19 www.google.com 142.250.185.228, 443, 49711, 49741 GOOGLEUS United States 10->19 21 6 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:1330873715617117090%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.185.237
truefalse
    high
    www.google.com
    142.250.185.228
    truefalse
      high
      clients.l.google.com
      172.217.16.142
      truefalse
        high
        edge.gycpi.b.yahoodns.net
        87.248.119.251
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            dl-mail.ymail.com
            unknown
            unknownfalse
              high
              apis.mail.yahoo.com
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709false
                  high
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00false
                      high
                      https://apis.mail.yahoo.com/favicon.icofalse
                        high
                        https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00false
                          high
                          https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                            high
                            • No. of IPs < 25%
                            • 25% < No. of IPs < 50%
                            • 50% < No. of IPs < 75%
                            • 75% < No. of IPs
                            IPDomainCountryFlagASNASN NameMalicious
                            87.248.119.251
                            edge.gycpi.b.yahoodns.netUnited Kingdom
                            203220YAHOO-DEBDEfalse
                            142.250.185.228
                            www.google.comUnited States
                            15169GOOGLEUSfalse
                            239.255.255.250
                            unknownReserved
                            unknownunknownfalse
                            142.250.185.237
                            accounts.google.comUnited States
                            15169GOOGLEUSfalse
                            172.217.16.142
                            clients.l.google.comUnited States
                            15169GOOGLEUSfalse
                            IP
                            192.168.2.1
                            127.0.0.1
                            Joe Sandbox Version:36.0.0 Rainbow Opal
                            Analysis ID:710636
                            Start date and time:2022-09-27 09:32:45 +02:00
                            Joe Sandbox Product:CloudBasic
                            Overall analysis duration:0h 4m 33s
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:browseurl.jbs
                            Sample URL:https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-|pid:9016,ProcessStart:133087371561711709
                            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                            Number of analysed new started processes analysed:9
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • HCA enabled
                            • EGA enabled
                            • HDC enabled
                            • AMSI enabled
                            Analysis Mode:default
                            Analysis stop reason:Timeout
                            Detection:CLEAN
                            Classification:clean0.win@26/0@6/7
                            EGA Information:Failed
                            HDC Information:Failed
                            HCA Information:
                            • Successful, ratio: 100%
                            • Number of executed functions: 0
                            • Number of non-executed functions: 0
                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                            • Excluded IPs from analysis (whitelisted): 142.250.186.35, 34.104.35.123, 20.190.160.22, 40.126.32.136, 40.126.32.138, 40.126.32.74, 40.126.32.76, 20.190.160.14, 40.126.32.133, 40.126.32.140, 20.40.136.238
                            • Excluded domains from analysis (whitelisted): iris-de-prod-azsc-frc-b.francecentral.cloudapp.azure.com, prda.aadg.msidentity.com, edgedl.me.gvt1.com, login.live.com, update.googleapis.com, clientservices.googleapis.com, arc.trafficmanager.net, www.tm.a.prd.aadg.akadns.net, arc.msn.com, login.msa.msidentity.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                            • Not all processes where analyzed, report is missing behavior information
                            • Report size getting too big, too many NtWriteVirtualMemory calls found.
                            No simulations
                            No context
                            No context
                            No context
                            No context
                            No context
                            No created / dropped files found
                            No static file info

                            Download Network PCAP: filteredfull

                            • Total Packets: 74
                            • 443 (HTTPS)
                            • 53 (DNS)
                            TimestampSource PortDest PortSource IPDest IP
                            Sep 27, 2022 09:33:47.349935055 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.349996090 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.350078106 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.351038933 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.351063967 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.351795912 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.351840019 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.351922035 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.352169991 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.352183104 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.353600979 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.353621006 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.353689909 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.353925943 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.353933096 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.384366989 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.384422064 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.384495974 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.384942055 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.384958982 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.413491011 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.414081097 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.414122105 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.414707899 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.414800882 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.416064978 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.416115046 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.429505110 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.430551052 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.434601068 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.434628010 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.434900045 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.434954882 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.435703039 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.435801029 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.436638117 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.436691046 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.436975956 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.437041998 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.445508957 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.445898056 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.445939064 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.447354078 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.447422981 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.777863026 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.777910948 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.778135061 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.778186083 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.778199911 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.778394938 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.778449059 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.778634071 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.778732061 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.778775930 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.779089928 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.779259920 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.779278994 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.779375076 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.779388905 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.779417038 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.780025005 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.780039072 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.810790062 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.810951948 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.810967922 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.811034918 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.813080072 CEST49707443192.168.2.4172.217.16.142
                            Sep 27, 2022 09:33:47.813106060 CEST44349707172.217.16.142192.168.2.4
                            Sep 27, 2022 09:33:47.835038900 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.835243940 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.835269928 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.835393906 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.835469961 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.841830015 CEST49709443192.168.2.4142.250.185.237
                            Sep 27, 2022 09:33:47.841856003 CEST44349709142.250.185.237192.168.2.4
                            Sep 27, 2022 09:33:47.880953074 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.881082058 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.938453913 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:47.938498974 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:47.938559055 CEST49708443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.938604116 CEST4434970887.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.971729040 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.971782923 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:47.971868038 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.972151995 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:47.972172022 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.017641068 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.018832922 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.018898964 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.020147085 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.020278931 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.022377014 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.022511959 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.038559914 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:33:48.048496008 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.048543930 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.048909903 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.049196959 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.049230099 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.138580084 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.298768044 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.298944950 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.299007893 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.326847076 CEST49712443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.326913118 CEST4434971287.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.646459103 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.646512985 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.646589041 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.646960020 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.646992922 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.693146944 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.693583012 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.693628073 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.694581032 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.695147038 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.695180893 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.695336103 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.695426941 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.695437908 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.725164890 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.725281000 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.725349903 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.725383997 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.725416899 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:48.725517035 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.728070021 CEST49714443192.168.2.487.248.119.251
                            Sep 27, 2022 09:33:48.728118896 CEST4434971487.248.119.251192.168.2.4
                            Sep 27, 2022 09:33:57.443835020 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:57.443939924 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:33:57.444142103 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:00.985634089 CEST49711443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:00.985677958 CEST44349711142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.357180119 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:47.357259989 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.357414961 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:47.357795000 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:47.357826948 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.411659002 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.412209988 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:47.412257910 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.412898064 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.413682938 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:47.413707018 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.413835049 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:47.461204052 CEST49741443192.168.2.4142.250.185.228
                            Sep 27, 2022 09:34:57.409203053 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:57.409384012 CEST44349741142.250.185.228192.168.2.4
                            Sep 27, 2022 09:34:57.409606934 CEST49741443192.168.2.4142.250.185.228
                            TimestampSource PortDest PortSource IPDest IP
                            Sep 27, 2022 09:33:47.299053907 CEST5856553192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.304333925 CEST5223953192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.306629896 CEST5680753192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.318954945 CEST53585658.8.8.8192.168.2.4
                            Sep 27, 2022 09:33:47.323626041 CEST53522398.8.8.8192.168.2.4
                            Sep 27, 2022 09:33:47.331914902 CEST6100753192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.334343910 CEST53568078.8.8.8192.168.2.4
                            Sep 27, 2022 09:33:47.349263906 CEST53610078.8.8.8192.168.2.4
                            Sep 27, 2022 09:33:47.361838102 CEST6112453192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.380542994 CEST53611248.8.8.8192.168.2.4
                            Sep 27, 2022 09:33:47.944293022 CEST5944453192.168.2.48.8.8.8
                            Sep 27, 2022 09:33:47.963547945 CEST53594448.8.8.8192.168.2.4
                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                            Sep 27, 2022 09:33:47.299053907 CEST192.168.2.48.8.8.80x1aebStandard query (0)dl-mail.ymail.comA (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.304333925 CEST192.168.2.48.8.8.80x6a56Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.306629896 CEST192.168.2.48.8.8.80x146eStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.331914902 CEST192.168.2.48.8.8.80xef80Standard query (0)www.google.comA (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.361838102 CEST192.168.2.48.8.8.80x1d5bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.944293022 CEST192.168.2.48.8.8.80xbe10Standard query (0)apis.mail.yahoo.comA (IP address)IN (0x0001)false
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Sep 27, 2022 09:33:47.318954945 CEST8.8.8.8192.168.2.40x1aebNo error (0)dl-mail.ymail.comedge.gycpi.b.yahoodns.netCNAME (Canonical name)IN (0x0001)false
                            Sep 27, 2022 09:33:47.318954945 CEST8.8.8.8192.168.2.40x1aebNo error (0)edge.gycpi.b.yahoodns.net87.248.119.251A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.318954945 CEST8.8.8.8192.168.2.40x1aebNo error (0)edge.gycpi.b.yahoodns.net87.248.119.252A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.323626041 CEST8.8.8.8192.168.2.40x6a56No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                            Sep 27, 2022 09:33:47.323626041 CEST8.8.8.8192.168.2.40x6a56No error (0)clients.l.google.com172.217.16.142A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.334343910 CEST8.8.8.8192.168.2.40x146eNo error (0)accounts.google.com142.250.185.237A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.349263906 CEST8.8.8.8192.168.2.40xef80No error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.380542994 CEST8.8.8.8192.168.2.40x1d5bNo error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.963547945 CEST8.8.8.8192.168.2.40xbe10No error (0)apis.mail.yahoo.comedge.gycpi.b.yahoodns.netCNAME (Canonical name)IN (0x0001)false
                            Sep 27, 2022 09:33:47.963547945 CEST8.8.8.8192.168.2.40xbe10No error (0)edge.gycpi.b.yahoodns.net87.248.119.251A (IP address)IN (0x0001)false
                            Sep 27, 2022 09:33:47.963547945 CEST8.8.8.8192.168.2.40xbe10No error (0)edge.gycpi.b.yahoodns.net87.248.119.252A (IP address)IN (0x0001)false
                            • clients2.google.com
                            • accounts.google.com
                            • dl-mail.ymail.com
                            • apis.mail.yahoo.com
                            • https:
                            Session IDSource IPSource PortDestination IPDestination PortProcess
                            0192.168.2.449707172.217.16.142443C:\Program Files\Google\Chrome\Application\chrome.exe
                            TimestampkBytes transferredDirectionData
                            2022-09-27 07:33:47 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                            Host: clients2.google.com
                            Connection: keep-alive
                            X-Goog-Update-Interactivity: fg
                            X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                            X-Goog-Update-Updater: chromecrx-104.0.5112.81
                            Sec-Fetch-Site: none
                            Sec-Fetch-Mode: no-cors
                            Sec-Fetch-Dest: empty
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                            Accept-Encoding: gzip, deflate, br
                            Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                            2022-09-27 07:33:47 UTC2INHTTP/1.1 200 OK
                            Content-Security-Policy: script-src 'report-sample' 'nonce-PebGTWa721PYi079noZ2pw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                            Pragma: no-cache
                            Expires: Mon, 01 Jan 1990 00:00:00 GMT
                            Date: Tue, 27 Sep 2022 07:33:47 GMT
                            Content-Type: text/xml; charset=UTF-8
                            X-Daynum: 5748
                            X-Daystart: 2027
                            X-Content-Type-Options: nosniff
                            X-Frame-Options: SAMEORIGIN
                            X-XSS-Protection: 1; mode=block
                            Server: GSE
                            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                            Accept-Ranges: none
                            Vary: Accept-Encoding
                            Connection: close
                            Transfer-Encoding: chunked
                            2022-09-27 07:33:47 UTC3INData Raw: 32 63 38 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 37 34 38 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 30 32 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22 20
                            Data Ascii: 2c8<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5748" elapsed_seconds="2027"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                            2022-09-27 07:33:47 UTC3INData Raw: 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65
                            Data Ascii: vYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size
                            2022-09-27 07:33:47 UTC3INData Raw: 30 0d 0a 0d 0a
                            Data Ascii: 0


                            Session IDSource IPSource PortDestination IPDestination PortProcess
                            1192.168.2.449709142.250.185.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                            TimestampkBytes transferredDirectionData
                            2022-09-27 07:33:47 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                            Host: accounts.google.com
                            Connection: keep-alive
                            Content-Length: 1
                            Origin: https://www.google.com
                            Content-Type: application/x-www-form-urlencoded
                            Sec-Fetch-Site: none
                            Sec-Fetch-Mode: no-cors
                            Sec-Fetch-Dest: empty
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                            Accept-Encoding: gzip, deflate, br
                            Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                            2022-09-27 07:33:47 UTC1OUTData Raw: 20
                            Data Ascii:
                            2022-09-27 07:33:47 UTC3INHTTP/1.1 200 OK
                            Content-Type: application/json; charset=utf-8
                            Access-Control-Allow-Origin: https://www.google.com
                            Access-Control-Allow-Credentials: true
                            X-Content-Type-Options: nosniff
                            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                            Pragma: no-cache
                            Expires: Mon, 01 Jan 1990 00:00:00 GMT
                            Date: Tue, 27 Sep 2022 07:33:47 GMT
                            Strict-Transport-Security: max-age=31536000; includeSubDomains
                            Content-Security-Policy: script-src 'report-sample' 'nonce-XsLPPx9HGSHGNdqTtrUHiA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                            Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                            Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                            Cross-Origin-Opener-Policy: same-origin
                            Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                            Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                            Server: ESF
                            X-XSS-Protection: 0
                            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                            Accept-Ranges: none
                            Vary: Accept-Encoding
                            Connection: close
                            Transfer-Encoding: chunked
                            2022-09-27 07:33:47 UTC5INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                            Data Ascii: 11["gaia.l.a.r",[]]
                            2022-09-27 07:33:47 UTC5INData Raw: 30 0d 0a 0d 0a
                            Data Ascii: 0


                            Session IDSource IPSource PortDestination IPDestination PortProcess
                            2192.168.2.44970887.248.119.251443C:\Program Files\Google\Chrome\Application\chrome.exe
                            TimestampkBytes transferredDirectionData
                            2022-09-27 07:33:47 UTC1OUTGET /ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709 HTTP/1.1
                            Host: dl-mail.ymail.com
                            Connection: keep-alive
                            sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                            sec-ch-ua-mobile: ?0
                            sec-ch-ua-platform: "Windows"
                            Upgrade-Insecure-Requests: 1
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                            Sec-Fetch-Site: none
                            Sec-Fetch-Mode: navigate
                            Sec-Fetch-User: ?1
                            Sec-Fetch-Dest: document
                            Accept-Encoding: gzip, deflate, br
                            Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                            2022-09-27 07:33:47 UTC5INHTTP/1.1 307 Temporary Redirect
                            Location: https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00
                            X-Server-Response-Time: 0ms
                            X-Server-Chain: jws700125.mail.ir2.yahoo.com
                            X-Server-Timestamp: Tue, 27 Sep 2022 07:33:47 GMT
                            Content-Length: 0
                            Referrer-Policy: no-referrer-when-downgrade
                            Date: Tue, 27 Sep 2022 07:33:47 GMT
                            Age: 0
                            Connection: close
                            Strict-Transport-Security: max-age=15552000
                            Server: ATS
                            Expect-CT: max-age=31536000, report-uri="http://csp.yahoo.com/beacon/csp?src=yahoocom-expect-ct-report-only"
                            X-XSS-Protection: 1; mode=block
                            X-Content-Type-Options: nosniff
                            X-Frame-Options: SAMEORIGIN


                            Session IDSource IPSource PortDestination IPDestination PortProcess
                            3192.168.2.44971287.248.119.251443C:\Program Files\Google\Chrome\Application\chrome.exe
                            TimestampkBytes transferredDirectionData
                            2022-09-27 07:33:48 UTC6OUTGET /ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00 HTTP/1.1
                            Host: apis.mail.yahoo.com
                            Connection: keep-alive
                            Upgrade-Insecure-Requests: 1
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                            Sec-Fetch-Site: none
                            Sec-Fetch-Mode: navigate
                            Sec-Fetch-User: ?1
                            Sec-Fetch-Dest: document
                            sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                            sec-ch-ua-mobile: ?0
                            sec-ch-ua-platform: "Windows"
                            Accept-Encoding: gzip, deflate, br
                            Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                            2022-09-27 07:33:48 UTC7INHTTP/1.1 401 Unauthorized
                            X-Server-Response-Time: 2ms
                            X-Server-Chain: jws700015.mail.ir2.yahoo.com
                            X-Server-Timestamp: Tue, 27 Sep 2022 07:33:48 GMT
                            Content-Type: application/json
                            Content-Length: 79
                            Referrer-Policy: no-referrer-when-downgrade
                            Date: Tue, 27 Sep 2022 07:33:48 GMT
                            Age: 0
                            Connection: close
                            Strict-Transport-Security: max-age=15552000
                            Server: ATS
                            Expect-CT: max-age=31536000, report-uri="http://csp.yahoo.com/beacon/csp?src=yahoocom-expect-ct-report-only"
                            X-XSS-Protection: 1; mode=block
                            X-Content-Type-Options: nosniff
                            X-Frame-Options: SAMEORIGIN
                            2022-09-27 07:33:48 UTC7INData Raw: 7b 22 65 72 72 6f 72 22 3a 7b 22 63 6f 64 65 22 3a 22 45 43 2d 34 30 30 38 22 2c 22 72 65 71 75 65 73 74 49 64 22 3a 22 34 36 65 31 37 61 65 35 2d 38 32 65 63 2d 63 34 33 65 2d 31 63 61 35 2d 61 66 30 30 30 30 30 31 35 64 30 30 22 7d 7d
                            Data Ascii: {"error":{"code":"EC-4008","requestId":"46e17ae5-82ec-c43e-1ca5-af0000015d00"}}


                            Session IDSource IPSource PortDestination IPDestination PortProcess
                            4192.168.2.44971487.248.119.251443C:\Program Files\Google\Chrome\Application\chrome.exe
                            TimestampkBytes transferredDirectionData
                            2022-09-27 07:33:48 UTC7OUTGET /favicon.ico HTTP/1.1
                            Host: apis.mail.yahoo.com
                            Connection: keep-alive
                            sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                            sec-ch-ua-mobile: ?0
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                            sec-ch-ua-platform: "Windows"
                            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                            Sec-Fetch-Site: same-origin
                            Sec-Fetch-Mode: no-cors
                            Sec-Fetch-Dest: image
                            Referer: https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/refresh?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00
                            Accept-Encoding: gzip, deflate, br
                            Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                            2022-09-27 07:33:48 UTC8INHTTP/1.1 200 OK
                            x-amz-id-2: hcXvxZrn5C8nTDJFzRfaXzQEc0VzRxN3Fwp7XI+WJ4AfSF6hBeirHTVg33vy3YMWOj4cjUKS81A=
                            x-amz-request-id: 1S7JW5K0YDKJHWPJ
                            Date: Mon, 26 Sep 2022 13:22:34 GMT
                            Last-Modified: Sun, 25 Sep 2022 21:31:15 GMT
                            x-amz-server-side-encryption: AES256
                            Cache-Control: public,max-age=86400
                            Accept-Ranges: bytes
                            Content-Type: image/vnd.microsoft.icon
                            Server: ATS
                            Content-Length: 2238
                            Referrer-Policy: no-referrer-when-downgrade
                            Etag: "3a07174943f82046370997254100d870"
                            Expires: Mon, 26 Sep 2022 23:00:00 GMT
                            Age: 65476
                            Connection: close
                            Strict-Transport-Security: max-age=15552000
                            Expect-CT: max-age=31536000, report-uri="http://csp.yahoo.com/beacon/csp?src=yahoocom-expect-ct-report-only"
                            X-XSS-Protection: 1; mode=block
                            X-Content-Type-Options: nosniff
                            2022-09-27 07:33:48 UTC9INData Raw: 00 00 01 00 01 00 20 20 00 00 01 00 08 00 a8 08 00 00 16 00 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d2 01 60 00 d2 02 61 00 d2 03 61 00 d2 04 62 00 d2 05 63 00 d3 07 64 00 d3 09 65 00 d3 0b 66 00 d4 0c 67 00 d4 0d 68 00 d4 10 69 00 d5 11 6a 00 d5 13 6b 00 d5 14 6c 00 d6 1b 70 00 d7 1e 72 00 d7 20 73 00 d8 24 76 00 d9 29 79 00 d9 2b 7a 00 da 2e 7c 00 da 30 7d 00 db 36 81 00 dc 39 83 00 dc 3b 84 00 dd 41 88 00 df 4b 8e 00 df 4c 8f 00 e0 50 91 00 e0 52 93 00 e0 54 94 00 e1 58 96 00 e1 59 97 00 e2 5c 99 00 e4 6b a2 00 e5 6c a3 00 e5 6f a5 00 e5 70 a5 00 e7 78 aa 00 e7 79 ab 00 e8 7e ae 00 e8 80 af 00 e8 82 b1 00 ea 88 b4 00 ea 8c b7 00 eb 92 bb 00 ec 94 bc 00 ec 95 bc 00 ec
                            Data Ascii: ( @`aabcdefghijklpr s$v)y+z.|0}69;AKLPRTXY\klopxy~
                            2022-09-27 07:33:48 UTC10INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 15 57 57 57 54 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3b 57 57 57 2c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1b 57 57 57 4c 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1d 57 57 57 57 22 00 00 07 30 48 41 1f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3d 57 57 57 57 45 00 00 2f 57 57 57 56 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 16 57 57 57 57 57 57 1a 00 43 57 57 57 57 2a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 36 57 57 57 57 57 57 3a 00 33 57 57 57 57 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0f 53 57 57 53 4e 57 57 57 13 0d 39 56 53
                            Data Ascii: WWWT;WWW,WWWLWWWW"0HA=WWWWE/WWWVWWWWWWCWWWW*6WWWWWW:3WWWW SWWSNWWW9VS


                            020406080s020406080100

                            Click to jump to process

                            020406080s0.0020406080100MB

                            Click to jump to process

                            • File
                            • Registry

                            Click to dive into process behavior distribution

                            Target ID:0
                            Start time:09:33:40
                            Start date:27/09/2022
                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                            Wow64 process (32bit):false
                            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                            Imagebase:0x7ff683680000
                            File size:2851656 bytes
                            MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:low
                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                            Target ID:1
                            Start time:09:33:42
                            Start date:27/09/2022
                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1760 --field-trial-handle=1792,i,871456357474917075,7546000180816737014,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                            Imagebase:0x7ff683680000
                            File size:2851656 bytes
                            MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:low

                            Target ID:2
                            Start time:09:33:43
                            Start date:27/09/2022
                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                            Wow64 process (32bit):false
                            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-31zd7UYyB1x5_N5g5oHekEXVB6pfpCfDjaWvD_3tva3_j3sXZLlh_0g9FFZTO4jHQJKw7MSSwpgCcu3oh7cEKA/messages/@.id==AG9pERATKfefYzKlFQRFwGBHuy8/content/parts/@.id==2/raw?appid=YMailNodin&ymreqid=46e17ae5-82ec-c43e-1ca5-af0000015d00&token=GGbnG9r89s5NYAWFhcq9hj2kRiq49bS6PqyayS8azkI00IGPc9-7jnB1dvmaTQNdEYl_988B6ocGC3YuDl2ORB8XtrhJoC6j4Z6d3MeS_RbhBLnz2bZQufgc5_eQwIX-%7Cpid:9016,ProcessStart:133087371561711709
                            Imagebase:0x7ff683680000
                            File size:2851656 bytes
                            MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:low

                            No disassembly