Edit tour

Windows Analysis Report
https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6I

Overview

General Information

Sample URL:https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4N
Analysis ID:825378
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4936 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5148 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1796 --field-trial-handle=1904,i,4906911788992748797,12110052494885928107,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5392 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw HTTP/1.1Host: app-gamma.glip.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: app-gamma.glip.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw HTTP/1.1Host: app-gamma.glip.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /404?url=%2Ffavicon.ico HTTP/1.1Host: app-gamma.glip.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: app-gamma.glip.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /404?url=%2Ffavicon.ico HTTP/1.1Host: app-gamma.glip.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /404?url=%2Ffavicon.ico HTTP/1.1Host: app-gamma.glip.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49686
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49685
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49684
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49682
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49685 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49682 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49679
Source: chromecache_105.1.dr, chromecache_104.1.drString found in binary or memory: https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.ico
Source: chromecache_105.1.dr, chromecache_104.1.drString found in binary or memory: https://d2rbro28ib85bu.cloudfront.net/images/logo/rc_logo_big_blue.png
Source: chromecache_105.1.dr, chromecache_104.1.drString found in binary or memory: https://d2rbro28ib85bu.cloudfront.net/images/logo/rc_logo_big_light.png
Source: chromecache_105.1.dr, chromecache_104.1.drString found in binary or memory: https://glip.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: classification engineClassification label: clean0.win@25/3@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1796 --field-trial-handle=1904,i,4906911788992748797,12110052494885928107,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1796 --field-trial-handle=1904,i,4906911788992748797,12110052494885928107,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 825378 URL: https://app-gamma.glip.com/... Startdate: 13/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49685, 49754 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.203.109, 443, 49681 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw0%VirustotalBrowse
https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    app-gamma.glip.com
    34.234.226.80
    truefalse
      high
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://app-gamma.glip.com/favicon.icofalse
                high
                https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwfalse
                  high
                  https://app-gamma.glip.com/404?url=%2Ffavicon.icofalse
                    high
                    https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPwfalse
                      high
                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                        high
                        NameSourceMaliciousAntivirus DetectionReputation
                        https://d2rbro28ib85bu.cloudfront.net/images/logo/rc_logo_big_light.pngchromecache_105.1.dr, chromecache_104.1.drfalse
                          high
                          https://d2rbro28ib85bu.cloudfront.net/images/logo/rc_logo_big_blue.pngchromecache_105.1.dr, chromecache_104.1.drfalse
                            high
                            https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.icochromecache_105.1.dr, chromecache_104.1.drfalse
                              high
                              https://glip.comchromecache_105.1.dr, chromecache_104.1.drfalse
                                high
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                34.234.226.80
                                app-gamma.glip.comUnited States
                                14618AMAZON-AESUSfalse
                                239.255.255.250
                                unknownReserved
                                unknownunknownfalse
                                142.250.203.100
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.203.110
                                clients.l.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.203.109
                                accounts.google.comUnited States
                                15169GOOGLEUSfalse
                                IP
                                192.168.2.1
                                127.0.0.1
                                Joe Sandbox Version:37.0.0 Beryl
                                Analysis ID:825378
                                Start date and time:2023-03-13 13:11:42 +01:00
                                Joe Sandbox Product:CloudBasic
                                Overall analysis duration:0h 4m 47s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:browseurl.jbs
                                Sample URL:https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                Number of analysed new started processes analysed:11
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • HDC enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Detection:CLEAN
                                Classification:clean0.win@25/3@5/7
                                EGA Information:Failed
                                HDC Information:Failed
                                HCA Information:
                                • Successful, ratio: 100%
                                • Number of executed functions: 0
                                • Number of non-executed functions: 0
                                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
                                • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                No simulations
                                No context
                                No context
                                No context
                                No context
                                No context
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text
                                Category:downloaded
                                Size (bytes):3268
                                Entropy (8bit):5.246629476067185
                                Encrypted:false
                                SSDEEP:48:0DeGYknFFELPJ6bVNjFf2hp7G4Ff043aGXkV6f9cf+R1lQVX/G6usGvj:S0wFSTJA264WYa18z10i
                                MD5:0D7197E785E827FBA50CBE7C98F5E337
                                SHA1:09B15B8C6C5C0F3F1DB14C60DE602BA2DCF93A44
                                SHA-256:31DD7FC2EC78FD595A143EAA452CE2715FE9A2146A4F98EE8066E43B5F190C14
                                SHA-512:C79D3E0CD153BEE50E8CD34E0EB3925EA0017B1DA98033D5EBB180C67782BF3A89298C66B29B774768C87AE2566241A7C9BE20C94961035DBE3266694F678CB8
                                Malicious:false
                                Reputation:low
                                URL:https://app-gamma.glip.com/404?url=%2Ffavicon.ico
                                Preview:<!doctype html>.<html>.<head>..<title>Glip &times; Not Found</title>..<link rel="icon" image="image/x-icon" href="https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.ico" />..<script type="text/javascript" src="//use.typekit.net/kde5nht.js"></script>..<script type="text/javascript">try{Typekit.load();}catch(e){}</script>..<style type="text/css">...body {....background-color: #0c5483;....font-family: "proxima-nova", "Helvetica Neue", HelveticaNeue, Helvetica, Arial, sans-serif;....text-rendering: optimizeLegibility;....-webkit-font-smoothing: antialiased;...}.....relative {....position: relative;...}.....content {....left: 50%;....margin: -108px 0 0 -245px;....max-width: 700px;....position: absolute;....text-align: center;....top: 50%;....z-index: 9990;...}.....logo {....height: 64px;....left: 50%;....margin: -100px 0 0 -90px;....position: absolute;....width: 180px;...}.....logo.dark {....opacity: 0;...}....h1 {....color: #0584bd;....display: inline-block;....font-size: 5
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text
                                Category:dropped
                                Size (bytes):3268
                                Entropy (8bit):5.246629476067185
                                Encrypted:false
                                SSDEEP:48:0DeGYknFFELPJ6bVNjFf2hp7G4Ff043aGXkV6f9cf+R1lQVX/G6usGvj:S0wFSTJA264WYa18z10i
                                MD5:0D7197E785E827FBA50CBE7C98F5E337
                                SHA1:09B15B8C6C5C0F3F1DB14C60DE602BA2DCF93A44
                                SHA-256:31DD7FC2EC78FD595A143EAA452CE2715FE9A2146A4F98EE8066E43B5F190C14
                                SHA-512:C79D3E0CD153BEE50E8CD34E0EB3925EA0017B1DA98033D5EBB180C67782BF3A89298C66B29B774768C87AE2566241A7C9BE20C94961035DBE3266694F678CB8
                                Malicious:false
                                Reputation:low
                                Preview:<!doctype html>.<html>.<head>..<title>Glip &times; Not Found</title>..<link rel="icon" image="image/x-icon" href="https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.ico" />..<script type="text/javascript" src="//use.typekit.net/kde5nht.js"></script>..<script type="text/javascript">try{Typekit.load();}catch(e){}</script>..<style type="text/css">...body {....background-color: #0c5483;....font-family: "proxima-nova", "Helvetica Neue", HelveticaNeue, Helvetica, Arial, sans-serif;....text-rendering: optimizeLegibility;....-webkit-font-smoothing: antialiased;...}.....relative {....position: relative;...}.....content {....left: 50%;....margin: -108px 0 0 -245px;....max-width: 700px;....position: absolute;....text-align: center;....top: 50%;....z-index: 9990;...}.....logo {....height: 64px;....left: 50%;....margin: -100px 0 0 -90px;....position: absolute;....width: 180px;...}.....logo.dark {....opacity: 0;...}....h1 {....color: #0584bd;....display: inline-block;....font-size: 5
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:JSON data
                                Category:downloaded
                                Size (bytes):21
                                Entropy (8bit):3.6897037321995474
                                Encrypted:false
                                SSDEEP:3:YAcDK+4:YAgS
                                MD5:CFEB244608FD81E54A47051CD2B6D1E0
                                SHA1:413A2D543E361B9AEDEC58F439812BA662F3AC3B
                                SHA-256:A1FE7A8337014249476CF1B6213330F7C36E3E43673735EB80DA95460BCDC19C
                                SHA-512:967C17222A3D9C21A36F389CF7C6C28B9BA7A25473CC3EA2CD067B2C96E3ECAEE713A4FE76242EDB1FEFC123039A7C60DEF60C6A09C273DB96375F9997643265
                                Malicious:false
                                Reputation:low
                                URL:https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Preview:{"error":"POST only"}
                                No static file info

                                Download Network PCAP: filteredfull

                                • Total Packets: 108
                                • 443 (HTTPS)
                                • 53 (DNS)
                                TimestampSource PortDest PortSource IPDest IP
                                Mar 13, 2023 13:12:47.071763992 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.071837902 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.071945906 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.072401047 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.072460890 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.072542906 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.073066950 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.073100090 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.073637009 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.073685884 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.158411980 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.169487000 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.169552088 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.170258999 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.170360088 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.171112061 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:47.171224117 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:47.184973955 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.322853088 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.704483032 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.704550028 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.706310034 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.706422091 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:47.706473112 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:47.916822910 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.379354000 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:48.379399061 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:48.379512072 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:48.379524946 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:48.379539013 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:48.379755020 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.379792929 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.379962921 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.379975080 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.379997969 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.413714886 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:48.413861036 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:48.414200068 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:48.432765007 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.432904959 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.432956934 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.432992935 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.433291912 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.442209959 CET49681443192.168.2.3142.250.203.109
                                Mar 13, 2023 13:12:48.442267895 CET44349681142.250.203.109192.168.2.3
                                Mar 13, 2023 13:12:48.442759991 CET49679443192.168.2.3142.250.203.110
                                Mar 13, 2023 13:12:48.442812920 CET44349679142.250.203.110192.168.2.3
                                Mar 13, 2023 13:12:49.022784948 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.022856951 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.023015976 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.025311947 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.025352955 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.472673893 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.475809097 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.475853920 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.477129936 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.477243900 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.480191946 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.480211020 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.480341911 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.480736017 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.480756998 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.584417105 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.813343048 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.813446999 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.813512087 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.818934917 CET49682443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.818968058 CET4434968234.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.968808889 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.968859911 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.969007015 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.969505072 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:49.969521999 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:49.987605095 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:49.987668037 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:49.987735987 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:49.988406897 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:49.988430023 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.051286936 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.051630974 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:50.051671028 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.053792000 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.053905010 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:50.056370974 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:50.056396008 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.056587934 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.228235006 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:50.228295088 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:12:50.262427092 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.262909889 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.262944937 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.263637066 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.264508009 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.264525890 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.264661074 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.264799118 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.264807940 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.396641016 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.396701097 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.396794081 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.398768902 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.398789883 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.416696072 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:12:50.552881002 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.553081036 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.553344965 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.560383081 CET49684443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.560444117 CET4434968434.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.568588972 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.568660975 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.568793058 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.569191933 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.569225073 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.696758032 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.697139025 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.697175980 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.698904991 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.699486971 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.699515104 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.699728966 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.699738026 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.699779987 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.781369925 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.868956089 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.869529963 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.869576931 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.870745897 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.872314930 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.872395992 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.872591972 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.872612000 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.872649908 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.984246016 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.984432936 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:50.984594107 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.988699913 CET49686443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:50.988769054 CET4434968634.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.005456924 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.005616903 CET4434968834.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.005745888 CET49688443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.099447012 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.099508047 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.099653006 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.100156069 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.100183964 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.394543886 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.395512104 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.395551920 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.396881104 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.397001982 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.397854090 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.397867918 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.397985935 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.398015022 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.398024082 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.481354952 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.481399059 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.581363916 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.684344053 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.684465885 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.684573889 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.699265003 CET49691443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.699311018 CET4434969134.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.705212116 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.705285072 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:51.705475092 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.707791090 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:51.707830906 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.000838995 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.025866032 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.025917053 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.026581049 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.034346104 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.034392118 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.034588099 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.034806967 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.034831047 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.297103882 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.297141075 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.297234058 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.297245026 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.297297001 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.323055029 CET49693443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.323108912 CET4434969334.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.385366917 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.385430098 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.385560989 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.386396885 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.386426926 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.679106951 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.710280895 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.710319996 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.711098909 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.714160919 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.714183092 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.714354038 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.715246916 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:52.715259075 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.969218969 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.969284058 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.969460964 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:12:52.969784021 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:53.105530977 CET49695443192.168.2.334.234.226.80
                                Mar 13, 2023 13:12:53.105566025 CET4434969534.234.226.80192.168.2.3
                                Mar 13, 2023 13:13:00.045747995 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:00.045857906 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:00.046015978 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:07.541090965 CET49685443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:07.541130066 CET44349685142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.054601908 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:50.054685116 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.054821014 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:50.055720091 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:50.055752993 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.110677004 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.110990047 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:50.111017942 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.111506939 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.112067938 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:13:50.112101078 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.112178087 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:13:50.156838894 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:14:00.093543053 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:14:00.093637943 CET44349754142.250.203.100192.168.2.3
                                Mar 13, 2023 13:14:00.093729019 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:14:00.358747959 CET49754443192.168.2.3142.250.203.100
                                Mar 13, 2023 13:14:00.358783960 CET44349754142.250.203.100192.168.2.3
                                TimestampSource PortDest PortSource IPDest IP
                                Mar 13, 2023 13:12:46.976383924 CET5426453192.168.2.38.8.8.8
                                Mar 13, 2023 13:12:46.982017994 CET5897453192.168.2.38.8.8.8
                                Mar 13, 2023 13:12:46.993623018 CET53542648.8.8.8192.168.2.3
                                Mar 13, 2023 13:12:46.999625921 CET53589748.8.8.8192.168.2.3
                                Mar 13, 2023 13:12:47.848495007 CET6372253192.168.2.38.8.8.8
                                Mar 13, 2023 13:12:47.866076946 CET53637228.8.8.8192.168.2.3
                                Mar 13, 2023 13:12:49.968036890 CET5932453192.168.2.38.8.8.8
                                Mar 13, 2023 13:12:49.985555887 CET53593248.8.8.8192.168.2.3
                                Mar 13, 2023 13:13:50.023267984 CET6501753192.168.2.38.8.8.8
                                Mar 13, 2023 13:13:50.051439047 CET53650178.8.8.8192.168.2.3
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Mar 13, 2023 13:12:46.976383924 CET192.168.2.38.8.8.80xb338Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:46.982017994 CET192.168.2.38.8.8.80x9825Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.848495007 CET192.168.2.38.8.8.80xd5ecStandard query (0)app-gamma.glip.comA (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:49.968036890 CET192.168.2.38.8.8.80x47d7Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                Mar 13, 2023 13:13:50.023267984 CET192.168.2.38.8.8.80x7feStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Mar 13, 2023 13:12:46.993623018 CET8.8.8.8192.168.2.30xb338No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:46.999625921 CET8.8.8.8192.168.2.30x9825No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                Mar 13, 2023 13:12:46.999625921 CET8.8.8.8192.168.2.30x9825No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com34.234.226.80A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com54.208.94.170A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com34.226.254.77A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com18.213.238.18A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com44.196.101.14A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com52.206.215.86A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com3.232.116.251A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:47.866076946 CET8.8.8.8192.168.2.30xd5ecNo error (0)app-gamma.glip.com44.195.138.113A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:12:49.985555887 CET8.8.8.8192.168.2.30x47d7No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                Mar 13, 2023 13:13:50.051439047 CET8.8.8.8192.168.2.30x7feNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                • clients2.google.com
                                • accounts.google.com
                                • app-gamma.glip.com
                                • https:
                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                0192.168.2.349679142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:48 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                Host: clients2.google.com
                                Connection: keep-alive
                                X-Goog-Update-Interactivity: fg
                                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:48 UTC1INHTTP/1.1 200 OK
                                Content-Security-Policy: script-src 'report-sample' 'nonce-GDU5YyrNUZkgnOCNfaW06A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Mon, 13 Mar 2023 12:12:48 GMT
                                Content-Type: text/xml; charset=UTF-8
                                X-Daynum: 5915
                                X-Daystart: 18768
                                X-Content-Type-Options: nosniff
                                X-Frame-Options: SAMEORIGIN
                                X-XSS-Protection: 1; mode=block
                                Server: GSE
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2023-03-13 12:12:48 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 31 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 38 37 36 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5915" elapsed_seconds="18768"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                2023-03-13 12:12:48 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                2023-03-13 12:12:48 UTC2INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                1192.168.2.349681142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:48 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                Host: accounts.google.com
                                Connection: keep-alive
                                Content-Length: 1
                                Origin: https://www.google.com
                                Content-Type: application/x-www-form-urlencoded
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: empty
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
                                2023-03-13 12:12:48 UTC1OUTData Raw: 20
                                Data Ascii:
                                2023-03-13 12:12:48 UTC2INHTTP/1.1 200 OK
                                Content-Type: application/json; charset=utf-8
                                Access-Control-Allow-Origin: https://www.google.com
                                Access-Control-Allow-Credentials: true
                                X-Content-Type-Options: nosniff
                                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                Pragma: no-cache
                                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                Date: Mon, 13 Mar 2023 12:12:48 GMT
                                Strict-Transport-Security: max-age=31536000; includeSubDomains
                                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                Content-Security-Policy: script-src 'report-sample' 'nonce-ud5qxWmFUbPSLDtdowUksw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                Cross-Origin-Opener-Policy: same-origin
                                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                                Server: ESF
                                X-XSS-Protection: 0
                                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                Accept-Ranges: none
                                Vary: Accept-Encoding
                                Connection: close
                                Transfer-Encoding: chunked
                                2023-03-13 12:12:48 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                Data Ascii: 11["gaia.l.a.r",[]]
                                2023-03-13 12:12:48 UTC4INData Raw: 30 0d 0a 0d 0a
                                Data Ascii: 0


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                2192.168.2.34968234.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:49 UTC4OUTGET /badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                sec-ch-ua-platform: "Windows"
                                Upgrade-Insecure-Requests: 1
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: navigate
                                Sec-Fetch-User: ?1
                                Sec-Fetch-Dest: document
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:49 UTC5INHTTP/1.1 400 Bad Request
                                Date: Mon, 13 Mar 2023 12:12:49 GMT
                                Content-Type: application/json; charset=utf-8
                                Content-Length: 21
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                X-Frame-Options: DENY
                                ETag: W/"15-QTotVD42G5rt7Fj0OYErpmLzrDs"
                                Vary: Accept-Encoding
                                2023-03-13 12:12:49 UTC5INData Raw: 7b 22 65 72 72 6f 72 22 3a 22 50 4f 53 54 20 6f 6e 6c 79 22 7d
                                Data Ascii: {"error":"POST only"}


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                3192.168.2.34968434.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:50 UTC5OUTGET /favicon.ico HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:50 UTC6INHTTP/1.1 302 Found
                                Date: Mon, 13 Mar 2023 12:12:50 GMT
                                Content-Type: text/plain; charset=utf-8
                                Content-Length: 45
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                Location: /404?url=%2Ffavicon.ico
                                Vary: Accept, Accept-Encoding
                                2023-03-13 12:12:50 UTC6INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 2f 34 30 34 3f 75 72 6c 3d 25 32 46 66 61 76 69 63 6f 6e 2e 69 63 6f
                                Data Ascii: Found. Redirecting to /404?url=%2Ffavicon.ico


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                4192.168.2.34968634.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:50 UTC6OUTGET /badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                Cache-Control: max-age=0
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                sec-ch-ua-platform: "Windows"
                                Upgrade-Insecure-Requests: 1
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: navigate
                                Sec-Fetch-Dest: document
                                Referer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:50 UTC9INHTTP/1.1 400 Bad Request
                                Date: Mon, 13 Mar 2023 12:12:50 GMT
                                Content-Type: application/json; charset=utf-8
                                Content-Length: 21
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                X-Frame-Options: DENY
                                ETag: W/"15-QTotVD42G5rt7Fj0OYErpmLzrDs"
                                Vary: Accept-Encoding
                                2023-03-13 12:12:50 UTC9INData Raw: 7b 22 65 72 72 6f 72 22 3a 22 50 4f 53 54 20 6f 6e 6c 79 22 7d
                                Data Ascii: {"error":"POST only"}


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                5192.168.2.34968834.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:50 UTC8OUTGET /404?url=%2Ffavicon.ico HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                6192.168.2.34969134.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:51 UTC9OUTGET /favicon.ico HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:51 UTC10INHTTP/1.1 302 Found
                                Date: Mon, 13 Mar 2023 12:12:51 GMT
                                Content-Type: text/plain; charset=utf-8
                                Content-Length: 45
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                Location: /404?url=%2Ffavicon.ico
                                Vary: Accept, Accept-Encoding
                                2023-03-13 12:12:51 UTC10INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 2f 34 30 34 3f 75 72 6c 3d 25 32 46 66 61 76 69 63 6f 6e 2e 69 63 6f
                                Data Ascii: Found. Redirecting to /404?url=%2Ffavicon.ico


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                7192.168.2.34969334.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:52 UTC10OUTGET /404?url=%2Ffavicon.ico HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                                sec-ch-ua-mobile: ?0
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                sec-ch-ua-platform: "Windows"
                                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                Sec-Fetch-Site: same-origin
                                Sec-Fetch-Mode: no-cors
                                Sec-Fetch-Dest: image
                                Referer: https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:52 UTC11INHTTP/1.1 200 OK
                                Date: Mon, 13 Mar 2023 12:12:52 GMT
                                Content-Type: text/html; charset=utf-8
                                Content-Length: 3268
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                X-Frame-Options: DENY
                                ETag: W/"cc4-CbFbjGxcDz8dsUxg3mArotz5OkQ"
                                Vary: Accept-Encoding
                                2023-03-13 12:12:52 UTC12INData Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 09 3c 74 69 74 6c 65 3e 47 6c 69 70 20 26 74 69 6d 65 73 3b 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 09 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 69 6d 61 67 65 3d 22 69 6d 61 67 65 2f 78 2d 69 63 6f 6e 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 64 32 72 62 72 6f 32 38 69 62 38 35 62 75 2e 63 6c 6f 75 64 66 72 6f 6e 74 2e 6e 65 74 2f 69 6d 61 67 65 73 2f 6c 6f 67 6f 2f 72 63 2d 66 61 76 69 63 6f 6e 2d 63 6c 65 61 72 2e 69 63 6f 22 20 2f 3e 0a 09 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 2f 75 73 65 2e 74 79 70 65 6b 69 74 2e 6e 65 74 2f 6b 64 65 35 6e 68 74 2e 6a 73 22
                                Data Ascii: <!doctype html><html><head><title>Glip &times; Not Found</title><link rel="icon" image="image/x-icon" href="https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.ico" /><script type="text/javascript" src="//use.typekit.net/kde5nht.js"


                                Session IDSource IPSource PortDestination IPDestination PortProcess
                                8192.168.2.34969534.234.226.80443C:\Program Files\Google\Chrome\Application\chrome.exe
                                TimestampkBytes transferredDirectionData
                                2023-03-13 12:12:52 UTC15OUTGET /404?url=%2Ffavicon.ico HTTP/1.1
                                Host: app-gamma.glip.com
                                Connection: keep-alive
                                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                Accept: */*
                                Sec-Fetch-Site: none
                                Sec-Fetch-Mode: cors
                                Sec-Fetch-Dest: empty
                                Accept-Encoding: gzip, deflate, br
                                Accept-Language: en-US,en;q=0.9
                                2023-03-13 12:12:52 UTC15INHTTP/1.1 200 OK
                                Date: Mon, 13 Mar 2023 12:12:52 GMT
                                Content-Type: text/html; charset=utf-8
                                Content-Length: 3268
                                Connection: close
                                Strict-Transport-Security: max-age=86400; includeSubDomains
                                X-Frame-Options: DENY
                                ETag: W/"cc4-CbFbjGxcDz8dsUxg3mArotz5OkQ"
                                Vary: Accept-Encoding
                                2023-03-13 12:12:52 UTC15INData Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 09 3c 74 69 74 6c 65 3e 47 6c 69 70 20 26 74 69 6d 65 73 3b 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 09 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 69 6d 61 67 65 3d 22 69 6d 61 67 65 2f 78 2d 69 63 6f 6e 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 64 32 72 62 72 6f 32 38 69 62 38 35 62 75 2e 63 6c 6f 75 64 66 72 6f 6e 74 2e 6e 65 74 2f 69 6d 61 67 65 73 2f 6c 6f 67 6f 2f 72 63 2d 66 61 76 69 63 6f 6e 2d 63 6c 65 61 72 2e 69 63 6f 22 20 2f 3e 0a 09 3c 73 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 2f 2f 75 73 65 2e 74 79 70 65 6b 69 74 2e 6e 65 74 2f 6b 64 65 35 6e 68 74 2e 6a 73 22
                                Data Ascii: <!doctype html><html><head><title>Glip &times; Not Found</title><link rel="icon" image="image/x-icon" href="https://d2rbro28ib85bu.cloudfront.net/images/logo/rc-favicon-clear.ico" /><script type="text/javascript" src="//use.typekit.net/kde5nht.js"


                                020406080s020406080100

                                Click to jump to process

                                020406080s0.0020406080100MB

                                Click to jump to process

                                • File
                                • Registry

                                Click to dive into process behavior distribution

                                Target ID:0
                                Start time:13:12:42
                                Start date:13/03/2023
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low
                                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                Target ID:1
                                Start time:13:12:43
                                Start date:13/03/2023
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1796 --field-trial-handle=1904,i,4906911788992748797,12110052494885928107,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                Target ID:2
                                Start time:13:12:44
                                Start date:13/03/2023
                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app-gamma.glip.com/badge-api/v2.0/umi?state_id=112532914183&t=eyJhbGciOiJIUzUxMiIsInR5cCI6IkpXVCJ9.eyJ0b2tlbl9pZCI6MTYwNzk2MTQxMDk0MCwidHlwZSI6IndlYiIsInVpZCI6MTM5NTgzMzM2NDQ4MywiY2lkIjoyMTk4NTg2MTYzMywicmNfZXh0X2lkIjozNjkwMTQ2MDIwLCJpYXQiOjE2MDc5NjE0MTAsImlzcyI6ImFwaS5nbGlwLmNvbSIsInN1YiI6ImdsaXAifQ.Q5Bzbb4LqYPWVXwAu6ReOFH74HczfejQ15vIr0Ycn-sPC72CltqZv7xY-YnG_6OweLG1rtNXMtcWbX9X2sGzPw
                                Imagebase:0x7ff614650000
                                File size:2851656 bytes
                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:low

                                No disassembly