Create Interactive Tour

Windows Analysis Report
http://vip0x008.map2.ssl.hwcdn.net

Overview

General Information

Sample URL:http://vip0x008.map2.ssl.hwcdn.net
Analysis ID:779473
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6088 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4044 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,4158719939519646701,13058157795661225019,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5500 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://vip0x008.map2.ssl.hwcdn.net MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: clean0.win@25/0@4/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,4158719939519646701,13058157795661225019,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://vip0x008.map2.ssl.hwcdn.net
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,4158719939519646701,13058157795661225019,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 779473 URL: http://vip0x008.map2.ssl.hw... Startdate: 06/01/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.184.228, 443, 49707, 49730 GOOGLEUS United States 10->17 19 clients.l.google.com 142.250.185.78, 443, 49697, 49701 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://vip0x008.map2.ssl.hwcdn.net0%Avira URL Cloudsafe
http://vip0x008.map2.ssl.hwcdn.net0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.16.205
truefalse
    high
    www.google.com
    142.250.184.228
    truefalse
      high
      clients.l.google.com
      142.250.185.78
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.185.78
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.217.16.205
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              142.250.184.228
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              127.0.0.1
              Joe Sandbox Version:36.0.0 Rainbow Opal
              Analysis ID:779473
              Start date and time:2023-01-06 22:23:55 +01:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 3m 45s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://vip0x008.map2.ssl.hwcdn.net
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:12
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@25/0@4/6
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.18.99, 209.197.3.8, 34.104.35.123
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com, vip0x008.map2.ssl.hwcdn.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 69
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Jan 6, 2023 22:24:53.245134115 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.245189905 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.245270967 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.245635033 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.245719910 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.245815992 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.247267008 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.247307062 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.247400045 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.247606993 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.247621059 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.247685909 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.248188972 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.248212099 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.255251884 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.255346060 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.256373882 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.256408930 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.256786108 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.256808043 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.340734959 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.366219044 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.376200914 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.382906914 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.406183958 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.416977882 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.417483091 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.457905054 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.546952963 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.546991110 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.547249079 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.547291994 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.547588110 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.547620058 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.548213005 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.548230886 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.548685074 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.548763037 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.549403906 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.549458027 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.549547911 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.549726009 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.550225973 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.550291061 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:53.550801992 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:53.550889015 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:53.552033901 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:53.552125931 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.118514061 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.118609905 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.118685007 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.118748903 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.119071007 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.119076014 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.119448900 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.119489908 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.120738029 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.120790005 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.121033907 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.121102095 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.121191025 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.121398926 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.121469021 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.121501923 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.153114080 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.153309107 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.153393984 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.153456926 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.153536081 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.155401945 CET49701443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.155445099 CET44349701142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.175049067 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.175153971 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.175188065 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.175538063 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.175616980 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.178886890 CET49700443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.178916931 CET44349700172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.225275040 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.225323915 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:24:55.262900114 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:55.262945890 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:24:55.325952053 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:24:55.362884045 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:24:56.565524101 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.565587044 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.565675020 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.566061020 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.566118956 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.624635935 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.625031948 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.625082970 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.626334906 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.626440048 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.628588915 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.628608942 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.628726006 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.797585011 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:24:56.797602892 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:24:56.939434052 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:06.609328032 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:06.609469891 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:06.609565973 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:08.401422977 CET49707443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:08.401458025 CET44349707142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:40.236315966 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:25:40.236346006 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:25:40.267549992 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:25:40.267594099 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:25:56.622827053 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:25:56.622951984 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:25:56.623002052 CET44349696172.217.16.205192.168.2.3
              Jan 6, 2023 22:25:56.623105049 CET49696443192.168.2.3172.217.16.205
              Jan 6, 2023 22:25:56.623136044 CET44349697142.250.185.78192.168.2.3
              Jan 6, 2023 22:25:56.623258114 CET49697443192.168.2.3142.250.185.78
              Jan 6, 2023 22:25:56.623996019 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:56.624068975 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.624208927 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:56.624682903 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:56.624720097 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.678495884 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.679287910 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:56.679332972 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.680444956 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.681623936 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:25:56.681689024 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.681809902 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:25:56.722230911 CET49730443192.168.2.3142.250.184.228
              Jan 6, 2023 22:26:06.693604946 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:26:06.693840981 CET44349730142.250.184.228192.168.2.3
              Jan 6, 2023 22:26:06.693958998 CET49730443192.168.2.3142.250.184.228
              TimestampSource PortDest PortSource IPDest IP
              Jan 6, 2023 22:24:52.867233038 CET6270453192.168.2.38.8.8.8
              Jan 6, 2023 22:24:52.869843960 CET4997753192.168.2.38.8.8.8
              Jan 6, 2023 22:24:52.884911060 CET53627048.8.8.8192.168.2.3
              Jan 6, 2023 22:24:52.897661924 CET53499778.8.8.8192.168.2.3
              Jan 6, 2023 22:24:56.539262056 CET5295553192.168.2.38.8.8.8
              Jan 6, 2023 22:24:56.558521986 CET53529558.8.8.8192.168.2.3
              Jan 6, 2023 22:25:56.601066113 CET6074953192.168.2.38.8.8.8
              Jan 6, 2023 22:25:56.620794058 CET53607498.8.8.8192.168.2.3
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jan 6, 2023 22:24:52.867233038 CET192.168.2.38.8.8.80xaaf8Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Jan 6, 2023 22:24:52.869843960 CET192.168.2.38.8.8.80xeb52Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Jan 6, 2023 22:24:56.539262056 CET192.168.2.38.8.8.80x6806Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Jan 6, 2023 22:25:56.601066113 CET192.168.2.38.8.8.80xde1dStandard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jan 6, 2023 22:24:52.884911060 CET8.8.8.8192.168.2.30xaaf8No error (0)accounts.google.com172.217.16.205A (IP address)IN (0x0001)false
              Jan 6, 2023 22:24:52.897661924 CET8.8.8.8192.168.2.30xeb52No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Jan 6, 2023 22:24:52.897661924 CET8.8.8.8192.168.2.30xeb52No error (0)clients.l.google.com142.250.185.78A (IP address)IN (0x0001)false
              Jan 6, 2023 22:24:56.558521986 CET8.8.8.8192.168.2.30x6806No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              Jan 6, 2023 22:25:56.620794058 CET8.8.8.8192.168.2.30xde1dNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              • accounts.google.com
              • clients2.google.com
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349700172.217.16.205443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-01-06 21:24:55 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
              2023-01-06 21:24:55 UTC0OUTData Raw: 20
              Data Ascii:
              2023-01-06 21:24:55 UTC3INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Fri, 06 Jan 2023 21:24:55 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
              Content-Security-Policy: script-src 'report-sample' 'nonce-hNa958JitD2oN0yIE6ouSA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-01-06 21:24:55 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-01-06 21:24:55 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349701142.250.185.78443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-01-06 21:24:55 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-01-06 21:24:55 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-POjcjjGsqPwLS1QI34NPdw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Fri, 06 Jan 2023 21:24:55 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5849
              X-Daystart: 48295
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-01-06 21:24:55 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 34 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 38 32 39 35 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5849" elapsed_seconds="48295"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-01-06 21:24:55 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
              Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
              2023-01-06 21:24:55 UTC3INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Target ID:0
              Start time:22:24:49
              Start date:06/01/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:1
              Start time:22:24:51
              Start date:06/01/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,4158719939519646701,13058157795661225019,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:22:24:52
              Start date:06/01/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://vip0x008.map2.ssl.hwcdn.net
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly