Create Interactive Tour

Windows Analysis Report
http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280

Overview

General Information

Sample URL:http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280
Analysis ID:766245
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6908 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1760,i,11009787719523609371,13770241238713093197,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280 HTTP/1.1Host: docs.google.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: docs.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: docs.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Tue, 13 Dec 2022 15:46:20 GMTContent-Type: text/html; charset=utf-8Content-Encoding: gzipTransfer-Encoding: chunkedx-chromium-appcache-fallback-override: disallow-fallbackOrigin-Trial: Arlbm3aYP4F8jryBe5TXZ49CJDmGTgEpjkLwYKtvJpvg65pxTRq/0LtrY3S/FMwogUWu6GvOhoCX1WWtJ8wVXQkAAABpeyJvcmlnaW4iOiJodHRwczovL2dvb2dsZS5jb206NDQzIiwiZmVhdHVyZSI6IlVzZXJBZ2VudFJlZHVjdGlvbiIsImV4cGlyeSI6MTY1MDQxMjc5OSwiaXNTdWJkb21haW4iOnRydWV9Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version, Sec-CH-UA-ReducedPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*Referrer-Policy: strict-origin-when-cross-originContent-Security-Policy: base-uri 'self';object-src 'self';report-uri https://docs.google.com/spreadsheets/cspreport;script-src 'report-sample' 'nonce-_9AfEpfug_MX5oABcG_ovA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';worker-src 'self' blob:X-Content-Type-OptionData Raw: Data Ascii:
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=YES+srp.gws-20210525-0-RC1.de+FX+704
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: clean0.win@25/0@11/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1760,i,11009787719523609371,13770241238713093197,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1760,i,11009787719523609371,13770241238713093197,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 766245 URL: http://docs.google.com/spre... Startdate: 13/12/2022 Architecture: WINDOWS Score: 0 12 docs.google.com 2->12 6 chrome.exe 14 1 2->6         started        process3 dnsIp4 14 239.255.255.250 unknown Reserved 6->14 9 chrome.exe 6->9         started        process5 dnsIp6 16 beacons-handoff.gcp.gvt2.com 142.250.180.99, 443, 49800 GOOGLEUS United States 9->16 18 docs.google.com 142.250.181.238, 49720, 49721, 80 GOOGLEUS United States 9->18 20 10 other IPs or domains 9->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=19739392800%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://beacons.gcp.gvt2.com/domainreliability/upload0%URL Reputationsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
docs.google.com
142.250.181.238
truefalse
    high
    accounts.google.com
    172.217.16.141
    truefalse
      high
      beacons-handoff.gcp.gvt2.com
      142.250.180.99
      truefalse
        unknown
        drive.google.com
        142.250.186.78
        truefalse
          high
          support.google.com
          172.217.18.14
          truefalse
            high
            www.google.com
            142.250.185.228
            truefalse
              high
              clients.l.google.com
              142.250.186.174
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  beacons.gcp.gvt2.com
                  unknown
                  unknownfalse
                    unknown
                    NameMaliciousAntivirus DetectionReputation
                    http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280false
                      high
                      http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280false
                        high
                        https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                          high
                          https://beacons.gcp.gvt2.com/domainreliability/uploadfalse
                          • URL Reputation: safe
                          unknown
                          https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                            high
                            http://docs.google.com/favicon.icofalse
                              high
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              142.250.184.196
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.186.174
                              clients.l.google.comUnited States
                              15169GOOGLEUSfalse
                              142.250.181.238
                              docs.google.comUnited States
                              15169GOOGLEUSfalse
                              239.255.255.250
                              unknownReserved
                              unknownunknownfalse
                              142.250.184.228
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.180.99
                              beacons-handoff.gcp.gvt2.comUnited States
                              15169GOOGLEUSfalse
                              172.217.16.141
                              accounts.google.comUnited States
                              15169GOOGLEUSfalse
                              IP
                              127.0.0.1
                              Joe Sandbox Version:36.0.0 Rainbow Opal
                              Analysis ID:766245
                              Start date and time:2022-12-13 16:45:44 +01:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 3m 45s
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                              Sample URL:http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280
                              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                              Number of analysed new started processes analysed:5
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:CLEAN
                              Classification:clean0.win@25/0@11/8
                              EGA Information:Failed
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 100%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 0
                              • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
                              • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.186.42, 142.250.185.99, 142.250.185.163, 172.217.16.195, 34.104.35.123, 172.217.18.3, 142.250.181.227
                              • Excluded domains from analysis (whitelisted): client.wns.windows.com, fonts.googleapis.com, ssl.gstatic.com, edgedl.me.gvt1.com, login.live.com, slscr.update.microsoft.com, fonts.gstatic.com, update.googleapis.com, clientservices.googleapis.com
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                              No simulations
                              No context
                              No context
                              No context
                              No context
                              No context
                              No created / dropped files found
                              No static file info

                              Download Network PCAP: filteredfull

                              • Total Packets: 76
                              • 443 (HTTPS)
                              • 80 (HTTP)
                              • 53 (DNS)
                              TimestampSource PortDest PortSource IPDest IP
                              Dec 13, 2022 16:46:20.234273911 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.234321117 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.234419107 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.236301899 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.236320972 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.243305922 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.243563890 CET4972180192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.246764898 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.246809959 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.246890068 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.247317076 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.247328043 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.259526014 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.259615898 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.259983063 CET8049721142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.260070086 CET4972180192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.268668890 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.284848928 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.292324066 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.292907000 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.292923927 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.294234991 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.294315100 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.304378033 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.362898111 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.362916946 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.363569021 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.363583088 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.363653898 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.364731073 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.364849091 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.364859104 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.439656019 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.439687014 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.439748049 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.439865112 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.439914942 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.439963102 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.443135023 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:20.503094912 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.503098011 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:20.851165056 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.851217031 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.851382017 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.851844072 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.851874113 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.852001905 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.852035999 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.852067947 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.853684902 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.853703022 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.882544994 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.882637024 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.882654905 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.882671118 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.882726908 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.899148941 CET49722443192.168.2.2142.250.186.174
                              Dec 13, 2022 16:46:20.899168015 CET44349722142.250.186.174192.168.2.2
                              Dec 13, 2022 16:46:20.903078079 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.912866116 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.914448023 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:20.914571047 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.921864986 CET49719443192.168.2.2172.217.16.141
                              Dec 13, 2022 16:46:20.921907902 CET44349719172.217.16.141192.168.2.2
                              Dec 13, 2022 16:46:21.138679981 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:21.154851913 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:21.163147926 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:46:21.203098059 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:46:23.911245108 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.911330938 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.911437035 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.911736012 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.911773920 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.978451967 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.985090971 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.985165119 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.986540079 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.986689091 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.988900900 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:23.988925934 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:23.989115000 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:24.103365898 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:24.103431940 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:24.203412056 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:33.960861921 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:33.960939884 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:46:33.961066008 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:35.360035896 CET49736443192.168.2.2142.250.184.228
                              Dec 13, 2022 16:46:35.360105038 CET44349736142.250.184.228192.168.2.2
                              Dec 13, 2022 16:47:05.263777971 CET4972180192.168.2.2142.250.181.238
                              Dec 13, 2022 16:47:05.280620098 CET8049721142.250.181.238192.168.2.2
                              Dec 13, 2022 16:47:06.166829109 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:47:06.183335066 CET8049720142.250.181.238192.168.2.2
                              Dec 13, 2022 16:47:21.363213062 CET4972180192.168.2.2142.250.181.238
                              Dec 13, 2022 16:47:21.380003929 CET8049721142.250.181.238192.168.2.2
                              Dec 13, 2022 16:47:21.380108118 CET4972180192.168.2.2142.250.181.238
                              Dec 13, 2022 16:47:21.395564079 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.395616055 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.395725012 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.396047115 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.396089077 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.481852055 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.482182980 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.482213020 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.483568907 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.483648062 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.486104012 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.486118078 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.486238003 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.486316919 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.486335993 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.527163029 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.553863049 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.554018974 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:21.554101944 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.554549932 CET49800443192.168.2.2142.250.180.99
                              Dec 13, 2022 16:47:21.554573059 CET44349800142.250.180.99192.168.2.2
                              Dec 13, 2022 16:47:23.956427097 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:23.956479073 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:23.956574917 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:23.956846952 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:23.956882954 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.025136948 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.027607918 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:24.027638912 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.028251886 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.028687954 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:24.028739929 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.028824091 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:24.068250895 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:34.000541925 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:34.000636101 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:34.000699997 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:35.370954037 CET49805443192.168.2.2142.250.184.196
                              Dec 13, 2022 16:47:35.371001005 CET44349805142.250.184.196192.168.2.2
                              Dec 13, 2022 16:47:51.186496019 CET4972080192.168.2.2142.250.181.238
                              Dec 13, 2022 16:47:51.203007936 CET8049720142.250.181.238192.168.2.2
                              TimestampSource PortDest PortSource IPDest IP
                              Dec 13, 2022 16:46:20.149494886 CET4989953192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:20.155056000 CET4983153192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:20.155689955 CET5105953192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:20.166953087 CET53498991.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:20.172126055 CET53498311.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:20.173644066 CET53510591.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:20.677026033 CET6466753192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:20.678956985 CET5578353192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:20.696012020 CET53557831.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:20.698873997 CET53646671.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:22.282774925 CET6047253192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:22.300312996 CET53604721.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:23.859236956 CET6287753192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:23.876971960 CET53628771.1.1.1192.168.2.2
                              Dec 13, 2022 16:46:23.892472982 CET5333253192.168.2.21.1.1.1
                              Dec 13, 2022 16:46:23.909991026 CET53533321.1.1.1192.168.2.2
                              Dec 13, 2022 16:47:21.372140884 CET5267253192.168.2.21.1.1.1
                              Dec 13, 2022 16:47:21.390327930 CET53526721.1.1.1192.168.2.2
                              Dec 13, 2022 16:47:23.915107012 CET5839853192.168.2.21.1.1.1
                              Dec 13, 2022 16:47:23.933476925 CET53583981.1.1.1192.168.2.2
                              Dec 13, 2022 16:47:23.936851978 CET6390453192.168.2.21.1.1.1
                              Dec 13, 2022 16:47:23.955334902 CET53639041.1.1.1192.168.2.2
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Dec 13, 2022 16:46:20.149494886 CET192.168.2.21.1.1.10x5ef7Standard query (0)docs.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.155056000 CET192.168.2.21.1.1.10x6721Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.155689955 CET192.168.2.21.1.1.10xff6Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.677026033 CET192.168.2.21.1.1.10xf0e7Standard query (0)support.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.678956985 CET192.168.2.21.1.1.10xa95Standard query (0)drive.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:22.282774925 CET192.168.2.21.1.1.10x8bb4Standard query (0)docs.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:23.859236956 CET192.168.2.21.1.1.10x5f60Standard query (0)www.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:23.892472982 CET192.168.2.21.1.1.10x713cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:21.372140884 CET192.168.2.21.1.1.10xa48bStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:23.915107012 CET192.168.2.21.1.1.10x1d9bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:23.936851978 CET192.168.2.21.1.1.10x600aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Dec 13, 2022 16:46:20.166953087 CET1.1.1.1192.168.2.20x5ef7No error (0)docs.google.com142.250.181.238A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.172126055 CET1.1.1.1192.168.2.20x6721No error (0)accounts.google.com172.217.16.141A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.173644066 CET1.1.1.1192.168.2.20xff6No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                              Dec 13, 2022 16:46:20.173644066 CET1.1.1.1192.168.2.20xff6No error (0)clients.l.google.com142.250.186.174A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.696012020 CET1.1.1.1192.168.2.20xa95No error (0)drive.google.com142.250.186.78A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:20.698873997 CET1.1.1.1192.168.2.20xf0e7No error (0)support.google.com172.217.18.14A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:22.300312996 CET1.1.1.1192.168.2.20x8bb4No error (0)docs.google.com142.250.185.206A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:23.876971960 CET1.1.1.1192.168.2.20x5f60No error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:46:23.909991026 CET1.1.1.1192.168.2.20x713cNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:21.390327930 CET1.1.1.1192.168.2.20xa48bNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                              Dec 13, 2022 16:47:21.390327930 CET1.1.1.1192.168.2.20xa48bNo error (0)beacons-handoff.gcp.gvt2.com142.250.180.99A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:23.933476925 CET1.1.1.1192.168.2.20x1d9bNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
                              Dec 13, 2022 16:47:23.955334902 CET1.1.1.1192.168.2.20x600aNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
                              • accounts.google.com
                              • clients2.google.com
                              • beacons.gcp.gvt2.com
                              • docs.google.com
                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              0192.168.2.249719172.217.16.141443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              1192.168.2.249722142.250.186.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              2192.168.2.249800142.250.180.99443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              3192.168.2.249720142.250.181.23880C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData
                              Dec 13, 2022 16:46:20.268668890 CET54OUTGET /spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280 HTTP/1.1
                              Host: docs.google.com
                              Connection: keep-alive
                              Upgrade-Insecure-Requests: 1
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                              Accept-Encoding: gzip, deflate
                              Accept-Language: en-US,en;q=0.9
                              Dec 13, 2022 16:46:20.439656019 CET72INHTTP/1.1 404 Not Found
                              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                              Pragma: no-cache
                              Expires: Mon, 01 Jan 1990 00:00:00 GMT
                              Date: Tue, 13 Dec 2022 15:46:20 GMT
                              Content-Type: text/html; charset=utf-8
                              Content-Encoding: gzip
                              Transfer-Encoding: chunked
                              x-chromium-appcache-fallback-override: disallow-fallback
                              Origin-Trial: Arlbm3aYP4F8jryBe5TXZ49CJDmGTgEpjkLwYKtvJpvg65pxTRq/0LtrY3S/FMwogUWu6GvOhoCX1WWtJ8wVXQkAAABpeyJvcmlnaW4iOiJodHRwczovL2dvb2dsZS5jb206NDQzIiwiZmVhdHVyZSI6IlVzZXJBZ2VudFJlZHVjdGlvbiIsImV4cGlyeSI6MTY1MDQxMjc5OSwiaXNTdWJkb21haW4iOnRydWV9
                              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version, Sec-CH-UA-Reduced
                              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                              Referrer-Policy: strict-origin-when-cross-origin
                              Content-Security-Policy: base-uri 'self';object-src 'self';report-uri https://docs.google.com/spreadsheets/cspreport;script-src 'report-sample' 'nonce-_9AfEpfug_MX5oABcG_ovA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';worker-src 'self' blob:
                              X-Content-Type-Option
                              Data Raw:
                              Data Ascii:
                              Dec 13, 2022 16:46:20.439687014 CET72INData Raw: 3a 20 6e 6f 73 6e 69 66 66 0d 0a 58 2d 58 53 53 2d 50 72 6f 74 65 63 74 69 6f 6e 3a 20 31 3b 20 6d 6f 64 65 3d 62 6c 6f 63 6b 0d 0a 53 65 72 76 65 72 3a 20 47 53 45 0d 0a 0d 0a
                              Data Ascii: : nosniffX-XSS-Protection: 1; mode=blockServer: GSE
                              Dec 13, 2022 16:46:20.439865112 CET73INData Raw: 35 37 43 0d 0a 1f 8b 08 00 00 00 00 00 00 00 b4 57 6d 6f db 36 10 fe be 5f 71 53 30 a4 4d 2d 4b 72 92 b6 93 62 6f 69 bb 74 c3 3a 34 7d 01 86 ed 4b 40 53 94 c4 86 22 09 92 7e ab e1 ff be 23 65 3b 72 1b b4 1d 86 7d 88 22 91 77 c7 7b 79 ee e1 f9 e2
                              Data Ascii: 57CWmo6_qS0M-Krboit:4}K@S"~#e;r}"w{yh\+&z17#e$-G%pP%nPmerYjaY o2+Vl.xq8|K8Dq6L%og}4o2\ab3q$v
                              Dec 13, 2022 16:46:20.439914942 CET73INData Raw: d8 35 ce 69 9b e3 38 e6 5d e9 43 0f 41 65 5c 42 d0 e1 68 f2 85 4d 8f 97 ee 88 3e 68 0e 9e 5d 33 7e d3 e0 13 26 87 f5 be b7 53 ec 6d 50 78 65 56 42 2d b0 97 66 4e 15 9b 8e fa be 2c 73 74 d8 f2 b0 9b 2f ba 6d 3f d4 c6 db a2 3e f1 00 45 85 43 2a d8
                              Data Ascii: 5i8]CAe\BhM>h]3~&SmPxeVB-fN,st/m?>EC*)vqd:oY`-96
                              Dec 13, 2022 16:46:20.443135023 CET73INData Raw: 41 0d 0a 03 00 0f 4b 34 ca 2b 0c 00 00 0d 0a 30 0d 0a 0d 0a
                              Data Ascii: AK4+0
                              Dec 13, 2022 16:46:21.138679981 CET152OUTGET /favicon.ico HTTP/1.1
                              Host: docs.google.com
                              Connection: keep-alive
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                              Referer: http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280
                              Accept-Encoding: gzip, deflate
                              Accept-Language: en-US,en;q=0.9
                              Dec 13, 2022 16:46:21.163147926 CET153INHTTP/1.1 302 Found
                              Location: http://ssl.gstatic.com/images/branding/product/1x/drive_2020q4_32dp.png
                              Cache-Control: private
                              Cross-Origin-Resource-Policy: cross-origin
                              Content-Type: text/html; charset=UTF-8
                              X-Content-Type-Options: nosniff
                              Date: Tue, 13 Dec 2022 15:46:21 GMT
                              Server: sffe
                              Content-Length: 268
                              X-XSS-Protection: 0
                              Data Raw: 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 54 49 54 4c 45 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 54 49 54 4c 45 3e 3c 2f 48 45 41 44 3e 3c 42 4f 44 59 3e 0a 3c 48 31 3e 33 30 32 20 4d 6f 76 65 64 3c 2f 48 31 3e 0a 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 0a 3c 41 20 48 52 45 46 3d 22 68 74 74 70 3a 2f 2f 73 73 6c 2e 67 73 74 61 74 69 63 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 70 72 6f 64 75 63 74 2f 31 78 2f 64 72 69 76 65 5f 32 30 32 30 71 34 5f 33 32 64 70 2e 70 6e 67 22 3e 68 65 72 65 3c 2f 41 3e 2e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                              Data Ascii: <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF="http://ssl.gstatic.com/images/branding/product/1x/drive_2020q4_32dp.png">here</A>.</BODY></HTML>
                              Dec 13, 2022 16:47:06.166829109 CET485OUTData Raw: 00
                              Data Ascii:
                              Dec 13, 2022 16:47:51.186496019 CET6268OUTData Raw: 00
                              Data Ascii:


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              4192.168.2.249721142.250.181.23880C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData
                              Dec 13, 2022 16:47:05.263777971 CET485OUTData Raw: 00
                              Data Ascii:


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              0192.168.2.249719172.217.16.141443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData
                              2022-12-13 15:46:20 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                              Host: accounts.google.com
                              Connection: keep-alive
                              Content-Length: 1
                              Origin: https://www.google.com
                              Content-Type: application/x-www-form-urlencoded
                              Sec-Fetch-Site: none
                              Sec-Fetch-Mode: no-cors
                              Sec-Fetch-Dest: empty
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                              Accept-Encoding: gzip, deflate, br
                              Accept-Language: en-US,en;q=0.9
                              Cookie: CONSENT=YES+srp.gws-20210525-0-RC1.de+FX+704
                              2022-12-13 15:46:20 UTC0OUTData Raw: 20
                              Data Ascii:
                              2022-12-13 15:46:20 UTC2INHTTP/1.1 200 OK
                              Content-Type: application/json; charset=utf-8
                              Access-Control-Allow-Origin: https://www.google.com
                              Access-Control-Allow-Credentials: true
                              X-Content-Type-Options: nosniff
                              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                              Pragma: no-cache
                              Expires: Mon, 01 Jan 1990 00:00:00 GMT
                              Date: Tue, 13 Dec 2022 15:46:20 GMT
                              Strict-Transport-Security: max-age=31536000; includeSubDomains
                              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                              Content-Security-Policy: script-src 'report-sample' 'nonce-G1uaEm51yyYWRgh83JFLmg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                              Cross-Origin-Opener-Policy: same-origin
                              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                              Server: ESF
                              X-XSS-Protection: 0
                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                              Accept-Ranges: none
                              Vary: Accept-Encoding
                              Connection: close
                              Transfer-Encoding: chunked
                              2022-12-13 15:46:20 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                              Data Ascii: 11["gaia.l.a.r",[]]
                              2022-12-13 15:46:20 UTC4INData Raw: 30 0d 0a 0d 0a
                              Data Ascii: 0


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              1192.168.2.249722142.250.186.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData
                              2022-12-13 15:46:20 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                              Host: clients2.google.com
                              Connection: keep-alive
                              X-Goog-Update-Interactivity: fg
                              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                              X-Goog-Update-Updater: chromecrx-104.0.5112.102
                              Sec-Fetch-Site: none
                              Sec-Fetch-Mode: no-cors
                              Sec-Fetch-Dest: empty
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                              Accept-Encoding: gzip, deflate, br
                              Accept-Language: en-US,en;q=0.9
                              2022-12-13 15:46:20 UTC1INHTTP/1.1 200 OK
                              Content-Security-Policy: script-src 'report-sample' 'nonce-2gsMZBGM5t23Zkbh0jFobA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                              Pragma: no-cache
                              Expires: Mon, 01 Jan 1990 00:00:00 GMT
                              Date: Tue, 13 Dec 2022 15:46:20 GMT
                              Content-Type: text/xml; charset=UTF-8
                              X-Daynum: 5825
                              X-Daystart: 27980
                              X-Content-Type-Options: nosniff
                              X-Frame-Options: SAMEORIGIN
                              X-XSS-Protection: 1; mode=block
                              Server: GSE
                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                              Accept-Ranges: none
                              Vary: Accept-Encoding
                              Connection: close
                              Transfer-Encoding: chunked
                              2022-12-13 15:46:20 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 32 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 37 39 38 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5825" elapsed_seconds="27980"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                              2022-12-13 15:46:20 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                              Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                              2022-12-13 15:46:20 UTC2INData Raw: 30 0d 0a 0d 0a
                              Data Ascii: 0


                              Session IDSource IPSource PortDestination IPDestination PortProcess
                              2192.168.2.249800142.250.180.99443C:\Program Files\Google\Chrome\Application\chrome.exe
                              TimestampkBytes transferredDirectionData
                              2022-12-13 15:47:21 UTC4OUTPOST /domainreliability/upload HTTP/1.1
                              Host: beacons.gcp.gvt2.com
                              Connection: keep-alive
                              Content-Length: 276
                              Content-Type: application/json; charset=utf-8
                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                              Accept-Encoding: gzip, deflate, br
                              Accept-Language: en-US,en;q=0.9
                              2022-12-13 15:47:21 UTC4OUTData Raw: 7b 22 65 6e 74 72 69 65 73 22 3a 5b 7b 22 68 74 74 70 5f 72 65 73 70 6f 6e 73 65 5f 63 6f 64 65 22 3a 34 30 34 2c 22 6e 65 74 77 6f 72 6b 5f 63 68 61 6e 67 65 64 22 3a 66 61 6c 73 65 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 48 54 54 50 22 2c 22 72 65 71 75 65 73 74 5f 61 67 65 5f 6d 73 22 3a 36 32 30 33 36 2c 22 72 65 71 75 65 73 74 5f 65 6c 61 70 73 65 64 5f 6d 73 22 3a 31 31 34 36 2c 22 73 61 6d 70 6c 65 5f 72 61 74 65 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 34 32 2e 32 35 30 2e 31 38 31 2e 32 33 38 3a 38 30 22 2c 22 73 74 61 74 75 73 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 22 2c 22 77 61 73 5f 70 72 6f 78 69 65 64 22 3a 66 61 6c 73 65 7d 5d
                              Data Ascii: {"entries":[{"http_response_code":404,"network_changed":false,"protocol":"HTTP","request_age_ms":62036,"request_elapsed_ms":1146,"sample_rate":1.0,"server_ip":"142.250.181.238:80","status":"http.error","url":"http://docs.google.com/","was_proxied":false}]
                              2022-12-13 15:47:21 UTC5INHTTP/1.1 200 OK
                              Report-To: {"endpoints":[{"priority":1,"url":"https://beacons.gcp.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":1,"url":"https://beacons.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":1,"url":"https://beacons2.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":1,"url":"https://beacons3.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":1,"url":"https://beacons4.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":1,"url":"https://clients2.google.com/domainreliability/upload-nel","weight":1},{"priority":2,"url":"https://beacons5.gvt2.com/domainreliability/upload-nel","weight":1},{"priority":2,"url":"https://beacons5.gvt3.com/domainreliability/upload-nel","weight":1}],"group":"nel","max_age":300}
                              NEL: {"failure_fraction":1,"include_subdomains":false,"max_age":300,"report_to":"nel","success_fraction":0.25}
                              Content-Type: application/javascript; charset=utf-8
                              Date: Tue, 13 Dec 2022 15:47:21 GMT
                              Server: Domain Reliability Server
                              Content-Length: 0
                              X-XSS-Protection: 0
                              X-Frame-Options: SAMEORIGIN
                              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                              Connection: close


                              050100s020406080100

                              Click to jump to process

                              050100s0.0050100MB

                              Click to jump to process

                              • File
                              • Registry

                              Click to dive into process behavior distribution

                              Click to jump to process

                              Target ID:0
                              Start time:16:46:55
                              Start date:13/12/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://docs.google.com/spreadsheets/d/17s15EL6FMKTMdzRZv5ygrEl-RSjRfVJl_RSBf7uJnvU/edit*gid=1973939280
                              Imagebase:0x7ff600460000
                              File size:2852640 bytes
                              MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                              Target ID:1
                              Start time:16:46:57
                              Start date:13/12/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1760,i,11009787719523609371,13770241238713093197,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                              Imagebase:0x7ff600460000
                              File size:2852640 bytes
                              MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                              No disassembly