Edit tour

Windows Analysis Report
https://analytics.tiktok.com/i18n/pixel/static

Overview

General Information

Sample URL:https://analytics.tiktok.com/i18n/pixel/static
Analysis ID:825673
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1688 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2040 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1612,i,11339883867280552140,18214597683948828006,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 3092 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://analytics.tiktok.com/i18n/pixel/static MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: classification engineClassification label: clean0.win@25/0@5/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1612,i,11339883867280552140,18214597683948828006,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://analytics.tiktok.com/i18n/pixel/static
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1612,i,11339883867280552140,18214597683948828006,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 825673 URL: https://analytics.tiktok.co... Startdate: 13/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49704, 49768 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.203.109, 443, 49697, 49703 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://analytics.tiktok.com/i18n/pixel/static0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    www.google.com
    142.250.203.100
    truefalse
      high
      clients.l.google.com
      142.250.203.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          analytics.tiktok.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://analytics.tiktok.com/i18n/pixel/staticfalse
                unknown
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.203.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.110
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.109
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:37.0.0 Beryl
                  Analysis ID:825673
                  Start date and time:2023-03-13 17:55:29 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 6m 0s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://analytics.tiktok.com/i18n/pixel/static
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@25/0@5/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.203.99, 104.109.250.122, 80.67.82.138, 80.67.82.176, 80.67.82.131, 173.222.109.138, 104.109.250.132, 173.222.109.153, 173.222.109.145, 80.67.82.184, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, analytics.tiktok.com.bytewlb.akadns.net, update.googleapis.com, clientservices.googleapis.com, e35058.api13.akamaiedge.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  • VT rate limit hit for: https://analytics.tiktok.com/i18n/pixel/static
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 67
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 13, 2023 17:56:37.002221107 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.002289057 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.002372980 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.004412889 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.004453897 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.004544973 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.025861979 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.025909901 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.026197910 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.034682035 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.034800053 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.034914970 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.035329103 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.035387993 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.036230087 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.036257029 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.037189007 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.037208080 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.037451982 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.037483931 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.076864958 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.076914072 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.076988935 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.077567101 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.077605963 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.159323931 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.160248995 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.160295963 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.162342072 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.162448883 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.210625887 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.222507954 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.227072001 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.227097988 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.227500916 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.227535009 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.227917910 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.228010893 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.229027033 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.229137897 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.229399920 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.229505062 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.265906096 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.270543098 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.300739050 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.300817966 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.301326990 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.301379919 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.302359104 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.302489996 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.303515911 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.303641081 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.303951979 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.304035902 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.774317026 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.774382114 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.774614096 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.774646044 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.774679899 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.774880886 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.775229931 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.775269985 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.775469065 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.775564909 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.775613070 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.776774883 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.776808023 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.776976109 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.777199030 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.777225018 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.777370930 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.778893948 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.778934002 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.812515974 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.812621117 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.812640905 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.812728882 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.812800884 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.814948082 CET49702443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.814973116 CET44349702142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.821494102 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.822171926 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.822205067 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:37.828579903 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.828917980 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.829005003 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.835263014 CET49697443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.835302114 CET44349697142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:37.926480055 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:37.948496103 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:37.948537111 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:56:37.948616028 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:37.948661089 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:56:38.048547983 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:56:38.050297022 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:56:47.162503958 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:47.162590027 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:56:47.162794113 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:48.525037050 CET49704443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:56:48.525082111 CET44349704142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:22.956044912 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:57:22.956088066 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:57:22.956142902 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:57:22.956176043 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:57:36.299683094 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:36.299757957 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.299854040 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:36.300319910 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:36.300347090 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.353646994 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.354182959 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:36.354204893 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.355379105 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.356139898 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:36.356173992 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.356256962 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:36.410290003 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:38.731461048 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:57:38.731564999 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:57:38.731682062 CET44349703142.250.203.109192.168.2.4
                  Mar 13, 2023 17:57:38.731798887 CET49703443192.168.2.4142.250.203.109
                  Mar 13, 2023 17:57:38.731865883 CET44349699142.250.203.110192.168.2.4
                  Mar 13, 2023 17:57:38.731957912 CET49699443192.168.2.4142.250.203.110
                  Mar 13, 2023 17:57:46.341398001 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:46.341574907 CET44349768142.250.203.100192.168.2.4
                  Mar 13, 2023 17:57:46.341705084 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:46.756043911 CET49768443192.168.2.4142.250.203.100
                  Mar 13, 2023 17:57:46.756094933 CET44349768142.250.203.100192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 13, 2023 17:56:36.725347042 CET6416753192.168.2.48.8.8.8
                  Mar 13, 2023 17:56:36.726288080 CET5856553192.168.2.48.8.8.8
                  Mar 13, 2023 17:56:36.734005928 CET5223953192.168.2.48.8.8.8
                  Mar 13, 2023 17:56:36.752872944 CET53641678.8.8.8192.168.2.4
                  Mar 13, 2023 17:56:36.761110067 CET53522398.8.8.8192.168.2.4
                  Mar 13, 2023 17:56:36.999928951 CET5680753192.168.2.48.8.8.8
                  Mar 13, 2023 17:56:37.027829885 CET53568078.8.8.8192.168.2.4
                  Mar 13, 2023 17:56:37.051661015 CET6100753192.168.2.48.8.8.8
                  Mar 13, 2023 17:56:37.071461916 CET53610078.8.8.8192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Mar 13, 2023 17:56:36.725347042 CET192.168.2.48.8.8.80xa965Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:36.726288080 CET192.168.2.48.8.8.80x329bStandard query (0)analytics.tiktok.comA (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:36.734005928 CET192.168.2.48.8.8.80xb63Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:36.999928951 CET192.168.2.48.8.8.80xba41Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:37.051661015 CET192.168.2.48.8.8.80xa197Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Mar 13, 2023 17:56:36.752872944 CET8.8.8.8192.168.2.40xa965No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Mar 13, 2023 17:56:36.752872944 CET8.8.8.8192.168.2.40xa965No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:36.761110067 CET8.8.8.8192.168.2.40xb63No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:36.764098883 CET8.8.8.8192.168.2.40x329bNo error (0)analytics.tiktok.comanalytics.tiktok.com.bytewlb.akadns.netCNAME (Canonical name)IN (0x0001)false
                  Mar 13, 2023 17:56:37.027829885 CET8.8.8.8192.168.2.40xba41No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                  Mar 13, 2023 17:56:37.071461916 CET8.8.8.8192.168.2.40xa197No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.449697142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-13 16:56:37 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  2023-03-13 16:56:37 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-03-13 16:56:37 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 13 Mar 2023 16:56:37 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-vYPRWlN_fLHrTSvpTHhnxw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Cross-Origin-Opener-Policy: same-origin
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-13 16:56:37 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-03-13 16:56:37 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.449702142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-13 16:56:37 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                  2023-03-13 16:56:37 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-HXkorKkxQmhdorZeJ0yrNg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 13 Mar 2023 16:56:37 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5915
                  X-Daystart: 35797
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-13 16:56:37 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 31 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 35 37 39 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5915" elapsed_seconds="35797"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-03-13 16:56:37 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-03-13 16:56:37 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0020406080100MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:17:56:29
                  Start date:13/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:1
                  Start time:17:56:30
                  Start date:13/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1612,i,11339883867280552140,18214597683948828006,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:17:56:31
                  Start date:13/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://analytics.tiktok.com/i18n/pixel/static
                  Imagebase:0x7ff683680000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly