Create Interactive Tour

Windows Analysis Report
http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0

Overview

General Information

Sample URL:http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0
Analysis ID:801791
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1980 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1840,i,3828982573537211118,12321912328445182209,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6160 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0Avira URL Cloud: detection malicious, Label: malware
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0 HTTP/1.1Host: webanalyser.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: webanalyser.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0Accept-Encoding: gzip, deflateAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.14.0 (Ubuntu)Date: Wed, 08 Feb 2023 16:58:24 GMTContent-Length: 0Connection: keep-aliveX-Powered-By: ExpressAccess-Control-Allow-Origin: *
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: classification engineClassification label: mal48.win@25/0@6/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1840,i,3828982573537211118,12321912328445182209,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1840,i,3828982573537211118,12321912328445182209,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 801791 URL: http://webanalyser.org/ping... Startdate: 08/02/2023 Architecture: WINDOWS Score: 48 26 Antivirus / Scanner detection for submitted sample 2->26 6 chrome.exe 15 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.1 unknown unknown 6->14 16 192.168.2.7 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 webanalyser.org 24.199.100.220, 49700, 49701, 49702 TWC-12271-NYCUS United States 11->20 22 www.google.com 142.250.180.132, 443, 49703, 49719 GOOGLEUS United States 11->22 24 4 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://webanalyser.org/favicon.ico0%Avira URL Cloudsafe
http://webanalyser.org/favicon.ico4%VirustotalBrowse

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    webanalyser.org
    24.199.100.220
    truefalse
      unknown
      www.google.com
      142.250.180.132
      truefalse
        high
        clients.l.google.com
        142.250.180.174
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://webanalyser.org/favicon.icofalse
              • 4%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0true
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  24.199.100.220
                  webanalyser.orgUnited States
                  12271TWC-12271-NYCUSfalse
                  216.58.209.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.132
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  192.168.2.7
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:801791
                  Start date and time:2023-02-08 17:57:20 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 14s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@25/0@6/8
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.180.131, 34.104.35.123, 142.250.180.163
                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 85
                  • 443 (HTTPS)
                  • 80 (HTTP)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 8, 2023 17:58:22.671659946 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.671734095 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.671881914 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.676562071 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.676616907 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.676692009 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.677568913 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.677608013 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.677683115 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.678309917 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.678345919 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.678415060 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.749878883 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.749926090 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.750790119 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.750835896 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.751156092 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.751176119 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.751607895 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.751651049 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.878875971 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.892999887 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.932035923 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.933408976 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.935475111 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.956585884 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.956631899 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.957226992 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.957269907 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.957576990 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.957638025 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.957865953 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.957891941 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.958538055 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.958561897 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.958674908 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.958923101 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.958955050 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.959022999 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.960838079 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.960946083 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.960953951 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.961010933 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.961148977 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:22.961232901 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:22.961280107 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:22.961349964 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:22.961373091 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.035525084 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.669329882 CET4970080192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.670609951 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.826570034 CET4970280192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.836910009 CET804970024.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:23.837591887 CET4970080192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.838803053 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:23.838916063 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.840106964 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:23.910773039 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.910810947 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.910862923 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.910871983 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.911017895 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.911056995 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.911127090 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.911155939 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.911293983 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.911320925 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.911339045 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.911375046 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.911422014 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.911442995 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.911461115 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.911494017 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.956525087 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.956686020 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.956734896 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.957000971 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.957108974 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.960364103 CET49696443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:23.960410118 CET44349696142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:23.980799913 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.980999947 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.981034994 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.981230021 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.981321096 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.986866951 CET49695443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:23.986908913 CET44349695216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:23.993696928 CET804970224.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:23.993916035 CET4970280192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:24.008172989 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:24.009147882 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:24.035619020 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:24.035684109 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:58:24.074390888 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:24.074526072 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:24.074541092 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:58:24.135720015 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:58:24.268801928 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.268861055 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.268980980 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.270052910 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.270076036 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.273552895 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:58:24.283874989 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:24.347667933 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.348165989 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.348232031 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.349472046 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.349587917 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.353795052 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.353828907 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.354001999 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.435563087 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.435599089 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:24.453059912 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:24.535640001 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:24.573560953 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:33.957305908 CET804970024.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:33.957437992 CET804970224.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:33.957550049 CET4970080192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:33.959990025 CET4970280192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:34.320928097 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:34.321069002 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:34.321228027 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:34.735647917 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:34.735827923 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:37.283282042 CET4970080192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:37.283361912 CET4970280192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:37.283385992 CET4970180192.168.2.424.199.100.220
                  Feb 8, 2023 17:58:37.283421040 CET49703443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:58:37.283446074 CET44349703142.250.180.132192.168.2.4
                  Feb 8, 2023 17:58:37.450299978 CET804970224.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:37.450591087 CET804970024.199.100.220192.168.2.4
                  Feb 8, 2023 17:58:37.451304913 CET804970124.199.100.220192.168.2.4
                  Feb 8, 2023 17:59:09.049134970 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:59:09.049164057 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:59:09.080427885 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:59:09.080462933 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:59:24.049777985 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:59:24.049858093 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:59:24.050041914 CET44349697216.58.209.45192.168.2.4
                  Feb 8, 2023 17:59:24.050084114 CET44349698142.250.180.174192.168.2.4
                  Feb 8, 2023 17:59:24.050175905 CET49697443192.168.2.4216.58.209.45
                  Feb 8, 2023 17:59:24.050175905 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:24.050249100 CET49698443192.168.2.4142.250.180.174
                  Feb 8, 2023 17:59:24.050338984 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.050436974 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:24.051145077 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:24.051206112 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.121413946 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.121829987 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:24.121870041 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.122961044 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.123441935 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:24.123476982 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.123639107 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:24.170753002 CET49719443192.168.2.4142.250.180.132
                  Feb 8, 2023 17:59:34.102483034 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:34.102581978 CET44349719142.250.180.132192.168.2.4
                  Feb 8, 2023 17:59:34.102747917 CET49719443192.168.2.4142.250.180.132
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 8, 2023 17:58:21.032012939 CET5091153192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:21.033358097 CET5968353192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:21.060198069 CET53509118.8.8.8192.168.2.4
                  Feb 8, 2023 17:58:21.061209917 CET53596838.8.8.8192.168.2.4
                  Feb 8, 2023 17:58:22.469114065 CET5968353192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:22.489032984 CET53596838.8.8.8192.168.2.4
                  Feb 8, 2023 17:58:22.676440954 CET5223953192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:22.786611080 CET53522398.8.8.8192.168.2.4
                  Feb 8, 2023 17:58:24.002957106 CET6100753192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:24.029232025 CET53610078.8.8.8192.168.2.4
                  Feb 8, 2023 17:58:24.188469887 CET6068653192.168.2.48.8.8.8
                  Feb 8, 2023 17:58:24.206465006 CET53606868.8.8.8192.168.2.4
                  TimestampSource IPDest IPChecksumCodeType
                  Feb 8, 2023 17:58:22.489214897 CET192.168.2.48.8.8.8d01f(Port unreachable)Destination Unreachable
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 8, 2023 17:58:21.032012939 CET192.168.2.48.8.8.80xf167Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:21.033358097 CET192.168.2.48.8.8.80xd299Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.469114065 CET192.168.2.48.8.8.80xd299Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.676440954 CET192.168.2.48.8.8.80x2feaStandard query (0)webanalyser.orgA (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:24.002957106 CET192.168.2.48.8.8.80xae77Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:24.188469887 CET192.168.2.48.8.8.80x2f71Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 8, 2023 17:58:21.060198069 CET8.8.8.8192.168.2.40xf167No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:21.061209917 CET8.8.8.8192.168.2.40xd299No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 8, 2023 17:58:21.061209917 CET8.8.8.8192.168.2.40xd299No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.489032984 CET8.8.8.8192.168.2.40xd299No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 8, 2023 17:58:22.489032984 CET8.8.8.8192.168.2.40xd299No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.786611080 CET8.8.8.8192.168.2.40x2feaNo error (0)webanalyser.org24.199.100.220A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.786611080 CET8.8.8.8192.168.2.40x2feaNo error (0)webanalyser.org24.199.100.200A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:22.786611080 CET8.8.8.8192.168.2.40x2feaNo error (0)webanalyser.org147.182.248.211A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:24.029232025 CET8.8.8.8192.168.2.40xae77No error (0)www.google.com142.250.180.132A (IP address)IN (0x0001)false
                  Feb 8, 2023 17:58:24.206465006 CET8.8.8.8192.168.2.40x2f71No error (0)www.google.com142.250.180.132A (IP address)IN (0x0001)false
                  • clients2.google.com
                  • accounts.google.com
                  • webanalyser.org
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.449696142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.449695216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  2192.168.2.44970124.199.100.22080C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  Feb 8, 2023 17:58:23.840106964 CET123OUTGET /ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0 HTTP/1.1
                  Host: webanalyser.org
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  Feb 8, 2023 17:58:24.009147882 CET195INHTTP/1.1 200 OK
                  Server: nginx/1.14.0 (Ubuntu)
                  Date: Wed, 08 Feb 2023 16:58:23 GMT
                  Content-Type: application/javascript
                  Transfer-Encoding: chunked
                  Connection: keep-alive
                  X-Powered-By: Express
                  Access-Control-Allow-Origin: *
                  Cache-Control: no-store
                  Cache-Control: no-cache
                  Data Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0
                  Feb 8, 2023 17:58:24.283874989 CET197OUTGET /favicon.ico HTTP/1.1
                  Host: webanalyser.org
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Referer: http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  Feb 8, 2023 17:58:24.453059912 CET462INHTTP/1.1 404 Not Found
                  Server: nginx/1.14.0 (Ubuntu)
                  Date: Wed, 08 Feb 2023 16:58:24 GMT
                  Content-Length: 0
                  Connection: keep-alive
                  X-Powered-By: Express
                  Access-Control-Allow-Origin: *


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.449696142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-08 16:58:23 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  2023-02-08 16:58:23 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-4rjPiD6w-4c7wtBjpQMWnQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Wed, 08 Feb 2023 16:58:23 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5882
                  X-Daystart: 32303
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-08 16:58:23 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 38 32 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 32 33 30 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5882" elapsed_seconds="32303"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-02-08 16:58:23 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-02-08 16:58:23 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.449695216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-08 16:58:23 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  2023-02-08 16:58:23 UTC1OUTData Raw: 20
                  Data Ascii:
                  2023-02-08 16:58:23 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Wed, 08 Feb 2023 16:58:23 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-g-Qjt2HKclbDFQZKQM5png' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-08 16:58:23 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-02-08 16:58:23 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0020406080100MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:17:58:54
                  Start date:08/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:1
                  Start time:17:58:55
                  Start date:08/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1988 --field-trial-handle=1840,i,3828982573537211118,12321912328445182209,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:17:58:56
                  Start date:08/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webanalyser.org/ping.php?guid=72a5ef65-33ca-4c91-b9fb-ce21a5c8ae9e&version=3.0
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly