Create Interactive Tour

Windows Analysis Report
http://bisrtb.cootlogix.com/

Overview

General Information

Sample URL:http://bisrtb.cootlogix.com/
Analysis ID:771201
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2560 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5988 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1648,i,8701377389053521038,14775514066190182850,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5224 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bisrtb.cootlogix.com/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bisrtb.cootlogix.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bisrtb.cootlogix.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://bisrtb.cootlogix.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundaccess-control-allow-origin: *access-control-allow-headers: *p3p: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"content-type: application/json; charset=utf-8content-length: 43date: Wed, 21 Dec 2022 06:43:22 GMTkeep-alive: timeout=5Data Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 22 7d Data Ascii: {"statusCode":404,"message":"Cannot GET /"}
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundaccess-control-allow-origin: *access-control-allow-headers: *p3p: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"content-type: application/json; charset=utf-8content-length: 54date: Wed, 21 Dec 2022 06:43:23 GMTkeep-alive: timeout=5Data Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 7d Data Ascii: {"statusCode":404,"message":"Cannot GET /favicon.ico"}
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: clean0.win@25/0@4/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1648,i,8701377389053521038,14775514066190182850,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bisrtb.cootlogix.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1648,i,8701377389053521038,14775514066190182850,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 771201 URL: http://bisrtb.cootlogix.com/ Startdate: 21/12/2022 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49710, 49730 GOOGLEUS United States 10->17 19 clients.l.google.com 142.250.203.110, 443, 49697, 49701 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bisrtb.cootlogix.com/0%VirustotalBrowse
http://bisrtb.cootlogix.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://bisrtb.cootlogix.com/favicon.ico0%Avira URL Cloudsafe
http://bisrtb.cootlogix.com/0%VirustotalBrowse

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
bisrtb.cootlogix.com
159.223.132.215
truefalse
    unknown
    accounts.google.com
    172.217.168.45
    truefalse
      high
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://bisrtb.cootlogix.com/falseunknown
              http://bisrtb.cootlogix.com/falseunknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://bisrtb.cootlogix.com/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.217.168.45
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.203.100
                www.google.comUnited States
                15169GOOGLEUSfalse
                159.223.132.215
                bisrtb.cootlogix.comUnited States
                46118CELANESE-USfalse
                142.250.203.110
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.1
                127.0.0.1
                Joe Sandbox Version:36.0.0 Rainbow Opal
                Analysis ID:771201
                Start date and time:2022-12-21 07:42:23 +01:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 4m 9s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://bisrtb.cootlogix.com/
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:12
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@25/0@4/7
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info

                Download Network PCAP: filteredfull

                • Total Packets: 81
                • 443 (HTTPS)
                • 80 (HTTP)
                • 53 (DNS)
                TimestampSource PortDest PortSource IPDest IP
                Dec 21, 2022 07:43:20.451395988 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.451426029 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.451503992 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.451688051 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.451700926 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.451771975 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.453454971 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.453511953 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.453584909 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.454005003 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.454031944 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.454097986 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.455602884 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.455622911 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.455908060 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.455921888 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.456516027 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.456559896 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.457036972 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.457061052 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.605424881 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.618222952 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:20.638700962 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.639882088 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:20.648709059 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.658735991 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:20.679692984 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:20.681734085 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.217005968 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.217063904 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.217170954 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.217246056 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.217374086 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.217428923 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.219089985 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.219217062 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.221266031 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.221306086 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.221359968 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.221404076 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.221735001 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.221868992 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.238522053 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.238581896 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.239937067 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.240072012 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.242086887 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.242202997 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.246133089 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.246174097 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.246469021 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.249172926 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.249228954 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.249449968 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.250169039 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.250205994 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.250303984 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.250329971 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.250431061 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.250534058 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.250802040 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.250839949 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.251190901 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.251218081 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.285811901 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.285933018 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.285979033 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.286082029 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.286159039 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.308500051 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.308626890 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.308676004 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.308917999 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.309000015 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.311018944 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.311069012 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.340009928 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.340042114 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.410862923 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.539525986 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.660391092 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:22.661688089 CET49698443192.168.2.3172.217.168.45
                Dec 21, 2022 07:43:22.661726952 CET44349698172.217.168.45192.168.2.3
                Dec 21, 2022 07:43:22.666310072 CET49697443192.168.2.3142.250.203.110
                Dec 21, 2022 07:43:22.666335106 CET44349697142.250.203.110192.168.2.3
                Dec 21, 2022 07:43:22.679733992 CET4970380192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:22.763248920 CET8049702159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:22.763442993 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:22.763732910 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:22.782140970 CET8049703159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:22.782393932 CET4970380192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:22.868220091 CET8049702159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:22.910857916 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:23.046159983 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:23.149677038 CET8049702159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:23.223582983 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:24.063137054 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.063199997 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.063298941 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.063647032 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.063676119 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.133094072 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.133645058 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.133666992 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.135298967 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.135411978 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.192092896 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.192141056 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.192423105 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.238439083 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:24.238471985 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:24.344129086 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:34.107939005 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:34.108084917 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:34.108201027 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:36.039468050 CET49710443192.168.2.3142.250.203.100
                Dec 21, 2022 07:43:36.039515972 CET44349710142.250.203.100192.168.2.3
                Dec 21, 2022 07:43:52.884056091 CET8049703159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:52.884279966 CET4970380192.168.2.3159.223.132.215
                Dec 21, 2022 07:43:53.150233984 CET8049702159.223.132.215192.168.2.3
                Dec 21, 2022 07:43:53.150397062 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:44:07.326059103 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:44:07.326091051 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:44:07.357255936 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:44:07.357294083 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:44:24.018718004 CET4970380192.168.2.3159.223.132.215
                Dec 21, 2022 07:44:24.018814087 CET4970280192.168.2.3159.223.132.215
                Dec 21, 2022 07:44:24.018827915 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:44:24.018964052 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:44:24.019064903 CET44349701142.250.203.110192.168.2.3
                Dec 21, 2022 07:44:24.019200087 CET49701443192.168.2.3142.250.203.110
                Dec 21, 2022 07:44:24.019270897 CET44349700172.217.168.45192.168.2.3
                Dec 21, 2022 07:44:24.019289970 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:24.019354105 CET49700443192.168.2.3172.217.168.45
                Dec 21, 2022 07:44:24.019366980 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.019459963 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:24.019917011 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:24.019952059 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.081681013 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.082165003 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:24.082233906 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.082900047 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.083379030 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:24.083416939 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.083528996 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:24.121113062 CET8049702159.223.132.215192.168.2.3
                Dec 21, 2022 07:44:24.121172905 CET8049703159.223.132.215192.168.2.3
                Dec 21, 2022 07:44:24.124294996 CET49730443192.168.2.3142.250.203.100
                Dec 21, 2022 07:44:34.076194048 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:34.076304913 CET44349730142.250.203.100192.168.2.3
                Dec 21, 2022 07:44:34.076598883 CET49730443192.168.2.3142.250.203.100
                TimestampSource PortDest PortSource IPDest IP
                Dec 21, 2022 07:43:20.133732080 CET4997753192.168.2.38.8.8.8
                Dec 21, 2022 07:43:20.134834051 CET5784053192.168.2.38.8.8.8
                Dec 21, 2022 07:43:20.151757002 CET53499778.8.8.8192.168.2.3
                Dec 21, 2022 07:43:20.160919905 CET53578408.8.8.8192.168.2.3
                Dec 21, 2022 07:43:20.514507055 CET5799053192.168.2.38.8.8.8
                Dec 21, 2022 07:43:20.536075115 CET53579908.8.8.8192.168.2.3
                Dec 21, 2022 07:43:23.957665920 CET5113953192.168.2.38.8.8.8
                Dec 21, 2022 07:43:23.984164953 CET53511398.8.8.8192.168.2.3
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 21, 2022 07:43:20.133732080 CET192.168.2.38.8.8.80x2714Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:20.134834051 CET192.168.2.38.8.8.80x10bfStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:20.514507055 CET192.168.2.38.8.8.80x35a8Standard query (0)bisrtb.cootlogix.comA (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:23.957665920 CET192.168.2.38.8.8.80xdddbStandard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 21, 2022 07:43:20.151757002 CET8.8.8.8192.168.2.30x2714No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:20.160919905 CET8.8.8.8192.168.2.30x10bfNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Dec 21, 2022 07:43:20.160919905 CET8.8.8.8192.168.2.30x10bfNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:20.536075115 CET8.8.8.8192.168.2.30x35a8No error (0)bisrtb.cootlogix.com159.223.132.215A (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:20.536075115 CET8.8.8.8192.168.2.30x35a8No error (0)bisrtb.cootlogix.com157.245.243.16A (IP address)IN (0x0001)false
                Dec 21, 2022 07:43:23.984164953 CET8.8.8.8192.168.2.30xdddbNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                • accounts.google.com
                • clients2.google.com
                • bisrtb.cootlogix.com
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349698172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349697142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.349702159.223.132.21580C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Dec 21, 2022 07:43:22.763732910 CET198OUTGET / HTTP/1.1
                Host: bisrtb.cootlogix.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Dec 21, 2022 07:43:22.868220091 CET198INHTTP/1.1 404 Not Found
                access-control-allow-origin: *
                access-control-allow-headers: *
                p3p: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
                content-type: application/json; charset=utf-8
                content-length: 43
                date: Wed, 21 Dec 2022 06:43:22 GMT
                keep-alive: timeout=5
                Data Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 22 7d
                Data Ascii: {"statusCode":404,"message":"Cannot GET /"}
                Dec 21, 2022 07:43:23.046159983 CET459OUTGET /favicon.ico HTTP/1.1
                Host: bisrtb.cootlogix.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Referer: http://bisrtb.cootlogix.com/
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Dec 21, 2022 07:43:23.149677038 CET464INHTTP/1.1 404 Not Found
                access-control-allow-origin: *
                access-control-allow-headers: *
                p3p: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
                content-type: application/json; charset=utf-8
                content-length: 54
                date: Wed, 21 Dec 2022 06:43:23 GMT
                keep-alive: timeout=5
                Data Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 7d
                Data Ascii: {"statusCode":404,"message":"Cannot GET /favicon.ico"}


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349698172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-12-21 06:43:22 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                2022-12-21 06:43:22 UTC0OUTData Raw: 20
                Data Ascii:
                2022-12-21 06:43:22 UTC3INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Dec 2022 06:43:22 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                Content-Security-Policy: script-src 'report-sample' 'nonce-JvOvIxuxSn3EONdkq3SPrA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-12-21 06:43:22 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2022-12-21 06:43:22 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349697142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-12-21 06:43:22 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-12-21 06:43:22 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-DEpZDnYhdwQeYp5LGRIKFg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Wed, 21 Dec 2022 06:43:22 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5832
                X-Daystart: 81802
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-12-21 06:43:22 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 33 32 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 38 31 38 30 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5832" elapsed_seconds="81802"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2022-12-21 06:43:22 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                2022-12-21 06:43:22 UTC3INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                020406080s020406080100

                Click to jump to process

                020406080s0.0020406080100MB

                Click to jump to process

                • File
                • Registry

                Click to dive into process behavior distribution

                Target ID:0
                Start time:07:43:16
                Start date:21/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                Target ID:1
                Start time:07:43:17
                Start date:21/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1648,i,8701377389053521038,14775514066190182850,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:2
                Start time:07:43:18
                Start date:21/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bisrtb.cootlogix.com/
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly