Edit tour

Windows Analysis Report
http://xfs.bxss.me/

Overview

General Information

Sample URL:http://xfs.bxss.me/
Analysis ID:818835
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Sample execution stops while process was sleeping (likely an evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1836 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • conhost.exe (PID: 2948 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • chrome.exe (PID: 5260 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1852 --field-trial-handle=2028,i,14998589907082851508,5152070478593164440,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5528 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://xfs.bxss.me/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49687
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49686
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49685
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49685 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49687 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2948:120:WilError_01
Source: classification engineClassification label: clean0.win@31/1@9/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1852 --field-trial-handle=2028,i,14998589907082851508,5152070478593164440,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://xfs.bxss.me/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1852 --field-trial-handle=2028,i,14998589907082851508,5152070478593164440,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 818835 URL: http://xfs.bxss.me/ Startdate: 02/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 3 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 192.168.2.1 unknown unknown 5->15 17 239.255.255.250 unknown Reserved 5->17 10 chrome.exe 1 5->10         started        13 conhost.exe 5->13         started        process4 dnsIp5 19 www.google.com 142.250.203.100, 443, 49687, 49723 GOOGLEUS United States 10->19 21 accounts.google.com 142.250.203.109, 443, 49686 GOOGLEUS United States 10->21 23 5 other IPs or domains 10->23

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://xfs.bxss.me/2%VirustotalBrowse
http://xfs.bxss.me/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.168.14
truefalse
    high
    accounts.google.com
    142.250.203.109
    truefalse
      high
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            xfs.bxss.me
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.203.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.110
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.109
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:37.0.0 Beryl
                  Analysis ID:818835
                  Start date and time:2023-03-02 18:17:07 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 47s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://xfs.bxss.me/
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:14
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@31/1@9/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):322
                  Entropy (8bit):5.366517947926678
                  Encrypted:false
                  SSDEEP:6:uL9pGGbmWLi0e//EALLIfdk+vojdsoGukMuKuRsM0FwOk5RxZpGAXA5DaBoEYv:uLiMLPekALElkzj7rkSuiXFwOKnnGAXu
                  MD5:CD5A3633CF9D49413C89E235246E1260
                  SHA1:0B9D43603B20621B0A8A310541C8492430101F12
                  SHA-256:7DC55D232A295BB88B98A43F36DAB5EA6EF556D018B5B681E10BB071A1D1E986
                  SHA-512:37C25A2182CD639A7ECB7F9CFF7CEF9D8EE9A6B50ECC29565FB2C53717FA838DB7BCD56144FAF303AEB25DA5A3260EB219A140077E358840239A02919BBB52E7
                  Malicious:false
                  Reputation:low
                  Preview:[1836:5240:0302/181807.899:ERROR:external_registry_loader_win.cc(144)] Missing value path for key Software\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj...[1836:2792:0302/181812.499:ERROR:device_event_log_impl.cc(214)] [18:18:12.471] Bluetooth: bluetooth_adapter_winrt.cc:1074 Getting Default Adapter failed...
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 47
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 2, 2023 18:18:10.577956915 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:10.577989101 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.578084946 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:10.579459906 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:10.579483032 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.593631983 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:10.593678951 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:10.593760014 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:10.594337940 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:10.594360113 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:10.671163082 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:10.673388958 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:10.673413038 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:10.675272942 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:10.675389051 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:10.679023981 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.679409981 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:10.679449081 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.680546999 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.680653095 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:10.682578087 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:10.682666063 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.569456100 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.569483995 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:11.569683075 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:11.570060968 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:11.570087910 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.570235968 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.570875883 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.570902109 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:11.571084023 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:11.571110010 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.606882095 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:11.607038975 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:11.607052088 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.607109070 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.625046015 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.625240088 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:11.625277996 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.626178980 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.626247883 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:11.639369965 CET49686443192.168.2.3142.250.203.109
                  Mar 2, 2023 18:18:11.639399052 CET44349686142.250.203.109192.168.2.3
                  Mar 2, 2023 18:18:11.640592098 CET49685443192.168.2.3142.250.203.110
                  Mar 2, 2023 18:18:11.640614986 CET44349685142.250.203.110192.168.2.3
                  Mar 2, 2023 18:18:13.522825956 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.522880077 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.522989988 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.523255110 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.523271084 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.582170010 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.589066982 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.589106083 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.590574980 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.590706110 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.592856884 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.592878103 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.593053102 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.659657001 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:13.659679890 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:13.760591984 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:23.595303059 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:23.595454931 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:18:23.595590115 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:25.061234951 CET49687443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:18:25.061269999 CET44349687142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.522824049 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:13.522908926 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.523031950 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:13.523586988 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:13.523631096 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.582519054 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.582976103 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:13.583019018 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.583452940 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.584134102 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:13.584172964 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.584253073 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:13.638448000 CET49723443192.168.2.3142.250.203.100
                  Mar 2, 2023 18:19:23.564371109 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:23.564471960 CET44349723142.250.203.100192.168.2.3
                  Mar 2, 2023 18:19:23.564625978 CET49723443192.168.2.3142.250.203.100
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 2, 2023 18:18:10.444806099 CET6372253192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:10.456420898 CET6552253192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:10.471985102 CET53637228.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:10.495801926 CET53655228.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:12.367939949 CET5932453192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:12.567320108 CET53593248.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:13.438005924 CET6162653192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:13.457700968 CET53616268.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:13.569988966 CET5892153192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:13.570656061 CET6270453192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:13.595391989 CET53589218.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:13.596283913 CET53627048.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:14.612972021 CET5784053192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:14.801035881 CET53578408.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:19.859008074 CET5692453192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:20.059322119 CET53569248.8.8.8192.168.2.3
                  Mar 2, 2023 18:18:50.121618986 CET5113953192.168.2.38.8.8.8
                  Mar 2, 2023 18:18:50.325968027 CET53511398.8.8.8192.168.2.3
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Mar 2, 2023 18:18:10.444806099 CET192.168.2.38.8.8.80xe5ccStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:10.456420898 CET192.168.2.38.8.8.80x68fbStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:12.367939949 CET192.168.2.38.8.8.80x7eedStandard query (0)xfs.bxss.meA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.438005924 CET192.168.2.38.8.8.80x4412Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.569988966 CET192.168.2.38.8.8.80x3f6Standard query (0)google.comA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.570656061 CET192.168.2.38.8.8.80xb6d6Standard query (0)google.comA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:14.612972021 CET192.168.2.38.8.8.80x497aStandard query (0)xfs.bxss.meA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:19.859008074 CET192.168.2.38.8.8.80x2536Standard query (0)xfs.bxss.meA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:50.121618986 CET192.168.2.38.8.8.80xa4fcStandard query (0)xfs.bxss.meA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Mar 2, 2023 18:18:10.471985102 CET8.8.8.8192.168.2.30xe5ccNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Mar 2, 2023 18:18:10.471985102 CET8.8.8.8192.168.2.30xe5ccNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:10.495801926 CET8.8.8.8192.168.2.30x68fbNo error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:12.567320108 CET8.8.8.8192.168.2.30x7eedName error (3)xfs.bxss.menonenoneA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.457700968 CET8.8.8.8192.168.2.30x4412No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.595391989 CET8.8.8.8192.168.2.30x3f6No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:13.596283913 CET8.8.8.8192.168.2.30xb6d6No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:14.801035881 CET8.8.8.8192.168.2.30x497aName error (3)xfs.bxss.menonenoneA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:20.059322119 CET8.8.8.8192.168.2.30x2536Name error (3)xfs.bxss.menonenoneA (IP address)IN (0x0001)false
                  Mar 2, 2023 18:18:50.325968027 CET8.8.8.8192.168.2.30xa4fcName error (3)xfs.bxss.menonenoneA (IP address)IN (0x0001)false
                  • clients2.google.com
                  • accounts.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.349685142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-02 17:18:11 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-03-02 17:18:11 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce--4JFdX5WNNtWsh1ziV9uyQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 02 Mar 2023 17:18:11 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5904
                  X-Daystart: 33491
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-02 17:18:11 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 30 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 33 34 39 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5904" elapsed_seconds="33491"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-03-02 17:18:11 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-03-02 17:18:11 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.349686142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-02 17:18:11 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
                  2023-03-02 17:18:11 UTC1OUTData Raw: 20
                  Data Ascii:
                  2023-03-02 17:18:11 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 02 Mar 2023 17:18:11 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Content-Security-Policy: script-src 'report-sample' 'nonce-aba5buzbiB5mB-065zxUBQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Cross-Origin-Opener-Policy: same-origin
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-02 17:18:11 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-03-02 17:18:11 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  [1836:2792:0302/181813.199:INFO:CONSOLE(6774)] "crbug/1173575, non-JS module files deprecated.", source: chrome-error://chromewebdata/ (6774)
                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0020406080100MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:18:18:06
                  Start date:02/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff614650000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:1
                  Start time:18:18:06
                  Start date:02/03/2023
                  Path:C:\Windows\System32\conhost.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Imagebase:0x7ff745070000
                  File size:625664 bytes
                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:18:07
                  Start date:02/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1852 --field-trial-handle=2028,i,14998589907082851508,5152070478593164440,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff614650000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:3
                  Start time:18:18:09
                  Start date:02/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://xfs.bxss.me/
                  Imagebase:0x7ff614650000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly