Edit tour

Windows Analysis Report
https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png

Overview

General Information

Sample URL:https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png
Analysis ID:824073
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5360 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5156 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,12819251200817856026,17660112722848726206,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5124 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
Source: classification engineClassification label: clean0.win@25/2@5/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,12819251200817856026,17660112722848726206,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,12819251200817856026,17660112722848726206,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 824073 URL: https://res.cdn.office.net/... Startdate: 10/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49720, 49786 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.203.109, 443, 49713, 49714 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png1%VirustotalBrowse
https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    www.google.com
    142.250.203.100
    truefalse
      high
      clients.l.google.com
      142.250.203.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.203.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              142.250.203.110
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              142.250.203.109
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              127.0.0.1
              Joe Sandbox Version:37.0.0 Beryl
              Analysis ID:824073
              Start date and time:2023-03-10 13:51:55 +01:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 4m 28s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:10
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@25/2@5/6
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.203.99, 104.109.250.194, 104.109.250.187, 104.109.250.172, 104.109.250.170, 104.109.250.180, 104.109.250.149, 104.109.250.189, 104.109.250.179, 34.104.35.123
              • Excluded domains from analysis (whitelisted): www.bing.com, e40491.dscg.akamaiedge.net, client.wns.windows.com, fs.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, res-prod.trafficmanager.net, owamail.public.cdn.office.net.edgekey.net, edgedl.me.gvt1.com, update.googleapis.com, owamail.public.cdn.office.net.edgekey.net.globalredir.akadns.net, res.cdn.office.net, res-1-tls.cdn.office.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
              Category:downloaded
              Size (bytes):144
              Entropy (8bit):5.694778733555366
              Encrypted:false
              SSDEEP:3:yionv//thPl9vt3lUkC9/h+qOef/nx5eoKkPxO/o9h5YPGwHRtsup:6v/lhPU3+qO6x5Zhh/wxeup
              MD5:E06BF183DB660F2327897036FD13D149
              SHA1:C8F0CBCDE837E86CEB109EBC92C08816A0047A81
              SHA-256:74E33FADBA887770E73E3BBA12EFFB49AEE834E7DD593FA2D3FF2622B701FA92
              SHA-512:8641E669B582508B82B9B105DEC9CDCDCA4032DC868870335E690FAB2D367014D50ECFE28574A36E5C02DD6D26F719FD49156AA66101EF34124B9537D39F427E
              Malicious:false
              Reputation:low
              URL:https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png
              Preview:.PNG........IHDR................a....gAMA......a....GIDAT8Oc..XYY..]].6B... ..~...W.^.j(:....j...0H.N...G..5...g.%........c.....4.....IEND.B`.
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
              Category:downloaded
              Size (bytes):226
              Entropy (8bit):5.283689221751446
              Encrypted:false
              SSDEEP:6:JiMVBdgqZj8DHgWdzRiAU2uvxV1uWDv2WCnHoAWAg6n:MMHdVBMHgWdzR05BDDCHoAWF6
              MD5:76707744898079486CD57CE41C00D5D0
              SHA1:84FB6EB62B3BD97BD0AA2804A99F77DE4073E7B5
              SHA-256:BC0EF1E863FF71D5B8681A9E43FE216CF68C4F5AF13A000E658A1F0BDA5D3EE9
              SHA-512:56286D887218A9B670EFF32FFFACACF51DCD32E7304D5F4DE931A81E3B8F83A32E228773C8AB071BCD8F0EED43ED20F9F3B1E2AF0128252C55572D17F81AF7AA
              Malicious:false
              Reputation:low
              URL:https://res.cdn.office.net/favicon.ico
              Preview:.<?xml version="1.0" encoding="utf-8"?><Error><Code>OutOfRangeInput</Code><Message>One of the request inputs is out of range..RequestId:947d218b-901e-000e-474f-53d627000000.Time:2023-03-10T12:52:59.0242171Z</Message></Error>
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 69
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Mar 10, 2023 13:52:57.412384987 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.412431002 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.412520885 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.415251970 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.415311098 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.415383101 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.415610075 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.415637016 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.416099072 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.416112900 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.489087105 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.494798899 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:57.531388998 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:57.541348934 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.447490931 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.447561979 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.447714090 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.447751999 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.449394941 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.449434042 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.449451923 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.449505091 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.449558020 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.449580908 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.449610949 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.450438023 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.450493097 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.450575113 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.452964067 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.453052998 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.453104019 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.453176022 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.479825974 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.479865074 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.480279922 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.480314970 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.481028080 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.481087923 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.481403112 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.481432915 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.481628895 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.481640100 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.481683969 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.482095003 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.516316891 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.516436100 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.516473055 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.516690016 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.516793013 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.528702021 CET49712443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.528739929 CET44349712142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.571608067 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.571635008 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:52:58.591173887 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.591202021 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.598560095 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.598618984 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.598779917 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.598809958 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.600087881 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.600183010 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.600207090 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.600274086 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.642244101 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.642292976 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.642487049 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.643002033 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.643037081 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.643263102 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.643312931 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.643349886 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.691456079 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.691498995 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.697096109 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.697269917 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.697309971 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.697465897 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.697556019 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.706269979 CET49714443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:58.706331968 CET44349714142.250.203.109192.168.2.6
              Mar 10, 2023 13:52:58.762186050 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:52:58.791407108 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:52:59.674230099 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.674302101 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.674385071 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.675390959 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.675429106 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.739063978 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.739427090 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.739474058 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.741677999 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.741820097 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.753680944 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.753721952 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.754029036 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.891556978 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:52:59.891606092 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:52:59.991549015 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:09.786345959 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:09.786468029 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:09.786613941 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:14.545773029 CET49720443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:14.545830011 CET44349720142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:43.580347061 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:53:43.580374956 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:53:43.705336094 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:53:43.705368042 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:53:59.649588108 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:53:59.649674892 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:53:59.649791956 CET44349713142.250.203.109192.168.2.6
              Mar 10, 2023 13:53:59.649878979 CET49713443192.168.2.6142.250.203.109
              Mar 10, 2023 13:53:59.650126934 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:59.650172949 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.650248051 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:59.650356054 CET44349711142.250.203.110192.168.2.6
              Mar 10, 2023 13:53:59.650434017 CET49711443192.168.2.6142.250.203.110
              Mar 10, 2023 13:53:59.650883913 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:59.650907040 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.706499100 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.707103968 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:59.707155943 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.707833052 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.708508968 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:53:59.708544016 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.708656073 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:53:59.753532887 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:54:09.703752041 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:54:09.703862906 CET44349786142.250.203.100192.168.2.6
              Mar 10, 2023 13:54:09.704020977 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:54:11.515899897 CET49786443192.168.2.6142.250.203.100
              Mar 10, 2023 13:54:11.515928984 CET44349786142.250.203.100192.168.2.6
              TimestampSource PortDest PortSource IPDest IP
              Mar 10, 2023 13:52:56.086560965 CET4944853192.168.2.68.8.8.8
              Mar 10, 2023 13:52:56.113842964 CET53494488.8.8.8192.168.2.6
              Mar 10, 2023 13:52:56.115852118 CET5908253192.168.2.68.8.8.8
              Mar 10, 2023 13:52:56.155571938 CET53590828.8.8.8192.168.2.6
              Mar 10, 2023 13:52:59.567552090 CET5490353192.168.2.68.8.8.8
              Mar 10, 2023 13:52:59.586787939 CET53549038.8.8.8192.168.2.6
              Mar 10, 2023 13:52:59.650439024 CET5153053192.168.2.68.8.8.8
              Mar 10, 2023 13:52:59.669697046 CET53515308.8.8.8192.168.2.6
              Mar 10, 2023 13:53:59.596425056 CET5675053192.168.2.68.8.8.8
              Mar 10, 2023 13:53:59.613883018 CET53567508.8.8.8192.168.2.6
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 10, 2023 13:52:56.086560965 CET192.168.2.68.8.8.80xf39fStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:56.115852118 CET192.168.2.68.8.8.80x2956Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:59.567552090 CET192.168.2.68.8.8.80x2ffbStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:59.650439024 CET192.168.2.68.8.8.80x8b8dStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Mar 10, 2023 13:53:59.596425056 CET192.168.2.68.8.8.80x6f4dStandard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 10, 2023 13:52:56.113842964 CET8.8.8.8192.168.2.60xf39fNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Mar 10, 2023 13:52:56.113842964 CET8.8.8.8192.168.2.60xf39fNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:56.155571938 CET8.8.8.8192.168.2.60x2956No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:59.586787939 CET8.8.8.8192.168.2.60x2ffbNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
              Mar 10, 2023 13:52:59.669697046 CET8.8.8.8192.168.2.60x8b8dNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
              Mar 10, 2023 13:53:59.613883018 CET8.8.8.8192.168.2.60x6f4dNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
              • clients2.google.com
              • accounts.google.com
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.649712142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-03-10 12:52:58 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-03-10 12:52:58 UTC0INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-59wG7R9Amcx9cxJ9RKq1_g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Fri, 10 Mar 2023 12:52:58 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5912
              X-Daystart: 17578
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-03-10 12:52:58 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 31 32 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 37 35 37 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5912" elapsed_seconds="17578"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-03-10 12:52:58 UTC1INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-03-10 12:52:58 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.649714142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-03-10 12:52:58 UTC2OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
              2023-03-10 12:52:58 UTC2OUTData Raw: 20
              Data Ascii:
              2023-03-10 12:52:58 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Fri, 10 Mar 2023 12:52:58 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
              Cross-Origin-Opener-Policy: same-origin
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Content-Security-Policy: script-src 'report-sample' 'nonce-walNFVS7QftyWpWTXQrWYg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-03-10 12:52:58 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-03-10 12:52:58 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Target ID:0
              Start time:13:52:52
              Start date:10/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:1
              Start time:13:52:53
              Start date:10/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1792,i,12819251200817856026,17660112722848726206,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:13:52:54
              Start date:10/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://res.cdn.office.net/assets/mail/file-icon/png/folder_16x16.png
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly