Edit tour

Windows Analysis Report
http://stun.fpapi.io

Overview

General Information

Sample URL:http://stun.fpapi.io
Analysis ID:838156
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2512 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1896,i,6944820425322924281,10168230220844843514,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 2376 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stun.fpapi.io MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@30/0@9/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1896,i,6944820425322924281,10168230220844843514,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stun.fpapi.io
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1896,i,6944820425322924281,10168230220844843514,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 838156 URL: http://stun.fpapi.io Startdate: 30/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 accounts.google.com 142.251.209.13, 443, 49689 GOOGLEUS United States 10->17 19 www.google.com 142.251.209.4, 443, 49691, 49743 GOOGLEUS United States 10->19 21 5 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://stun.fpapi.io0%VirustotalBrowse
http://stun.fpapi.io0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.110
truefalse
    high
    accounts.google.com
    142.251.209.13
    truefalse
      high
      www.google.com
      142.251.209.4
      truefalse
        high
        clients.l.google.com
        216.58.209.46
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            stun.fpapi.io
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.251.209.13
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.251.209.4
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  216.58.209.46
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:37.0.0 Beryl
                  Analysis ID:838156
                  Start date and time:2023-03-30 16:25:29 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 17s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://stun.fpapi.io
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:11
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@30/0@9/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.251.209.35, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 51
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 30, 2023 16:26:30.917798042 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:30.917898893 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:30.917994976 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:30.918646097 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:30.918730021 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:30.918792963 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:30.920377016 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:30.920449018 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:30.920794010 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:30.920839071 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.057687998 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.057744980 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.130470037 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.150234938 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.150265932 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.151122093 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.151175022 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.151309967 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.151364088 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.151393890 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.153357029 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.153384924 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.153419018 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.153552055 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.153556108 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.153584003 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.278275013 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.339268923 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.470082045 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.470113039 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.470453978 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.470792055 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.470812082 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.471728086 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.471761942 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.471990108 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.472527981 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.472557068 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.477360010 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.477406979 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.477498055 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.477921963 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.477945089 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.515165091 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.515275002 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.515296936 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.515449047 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.515530109 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.529922009 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.553253889 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.563646078 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.563863993 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.563896894 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.563921928 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.564052105 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.565459013 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.565498114 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.565763950 CEST49690443192.168.2.7216.58.209.46
                  Mar 30, 2023 16:26:31.565785885 CEST44349690216.58.209.46192.168.2.7
                  Mar 30, 2023 16:26:31.567267895 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.567408085 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.568977118 CEST49689443192.168.2.7142.251.209.13
                  Mar 30, 2023 16:26:31.569019079 CEST44349689142.251.209.13192.168.2.7
                  Mar 30, 2023 16:26:31.576608896 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.576632023 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.576891899 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.630322933 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:31.630356073 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:31.730299950 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:41.533138037 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:41.533241987 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:26:41.533382893 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:44.751209974 CEST49691443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:26:44.751261950 CEST44349691142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.337620974 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:31.337711096 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.337842941 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:31.339682102 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:31.339704037 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.409008026 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.409698009 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:31.409727097 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.410360098 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.411221981 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:31.411247015 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.411370039 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:31.458548069 CEST49743443192.168.2.7142.251.209.4
                  Mar 30, 2023 16:27:41.391494036 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:41.391609907 CEST44349743142.251.209.4192.168.2.7
                  Mar 30, 2023 16:27:41.391690016 CEST49743443192.168.2.7142.251.209.4
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 30, 2023 16:26:30.858557940 CEST5905853192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:30.859177113 CEST5487553192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:30.861608028 CEST5947753192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:30.882757902 CEST53548758.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:30.892863989 CEST53594778.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:30.901499987 CEST53590588.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:31.376019955 CEST5947753192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:31.392100096 CEST5575253192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:31.417434931 CEST53594778.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:31.421416044 CEST53557528.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:31.453383923 CEST5658853192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:31.473659039 CEST53565888.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:32.351053953 CEST5083553192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:32.370851040 CEST53508358.8.8.8192.168.2.7
                  Mar 30, 2023 16:26:37.426362991 CEST5333653192.168.2.78.8.8.8
                  Mar 30, 2023 16:26:37.450268984 CEST53533368.8.8.8192.168.2.7
                  Mar 30, 2023 16:27:07.774260998 CEST5113953192.168.2.78.8.8.8
                  Mar 30, 2023 16:27:07.790169954 CEST53511398.8.8.8192.168.2.7
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Mar 30, 2023 16:26:30.858557940 CEST192.168.2.78.8.8.80x70c1Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:30.859177113 CEST192.168.2.78.8.8.80x7eeaStandard query (0)stun.fpapi.ioA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:30.861608028 CEST192.168.2.78.8.8.80x2c4dStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.376019955 CEST192.168.2.78.8.8.80xbbfdStandard query (0)google.comA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.392100096 CEST192.168.2.78.8.8.80xb6a0Standard query (0)google.comA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.453383923 CEST192.168.2.78.8.8.80x6eb0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:32.351053953 CEST192.168.2.78.8.8.80xa238Standard query (0)stun.fpapi.ioA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:37.426362991 CEST192.168.2.78.8.8.80xb846Standard query (0)stun.fpapi.ioA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:27:07.774260998 CEST192.168.2.78.8.8.80x1adaStandard query (0)stun.fpapi.ioA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Mar 30, 2023 16:26:30.882757902 CEST8.8.8.8192.168.2.70x7eeaName error (3)stun.fpapi.iononenoneA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:30.892863989 CEST8.8.8.8192.168.2.70x2c4dNo error (0)accounts.google.com142.251.209.13A (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:30.901499987 CEST8.8.8.8192.168.2.70x70c1No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Mar 30, 2023 16:26:30.901499987 CEST8.8.8.8192.168.2.70x70c1No error (0)clients.l.google.com216.58.209.46A (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.417434931 CEST8.8.8.8192.168.2.70xbbfdNo error (0)google.com142.250.184.110A (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.421416044 CEST8.8.8.8192.168.2.70xb6a0No error (0)google.com142.250.184.110A (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:31.473659039 CEST8.8.8.8192.168.2.70x6eb0No error (0)www.google.com142.251.209.4A (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:32.370851040 CEST8.8.8.8192.168.2.70xa238Name error (3)stun.fpapi.iononenoneA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:26:37.450268984 CEST8.8.8.8192.168.2.70xb846Name error (3)stun.fpapi.iononenoneA (IP address)IN (0x0001)false
                  Mar 30, 2023 16:27:07.790169954 CEST8.8.8.8192.168.2.70x1adaName error (3)stun.fpapi.iononenoneA (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.749689142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-30 14:26:31 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-03-30 14:26:31 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-03-30 14:26:31 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 30 Mar 2023 14:26:31 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Content-Security-Policy: script-src 'report-sample' 'nonce-W7SOTXc2pBCSq2Wxbbg2nQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-30 14:26:31 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-03-30 14:26:31 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.749690216.58.209.46443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-03-30 14:26:31 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-03-30 14:26:31 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-JObO3tinIai4a6dkUBtozg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Thu, 30 Mar 2023 14:26:31 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5932
                  X-Daystart: 26791
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-03-30 14:26:31 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 33 32 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 36 37 39 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5932" elapsed_seconds="26791"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-03-30 14:26:31 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-03-30 14:26:31 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0020406080100MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:16:26:24
                  Start date:30/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:1
                  Start time:16:26:25
                  Start date:30/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1832 --field-trial-handle=1896,i,6944820425322924281,10168230220844843514,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:16:26:26
                  Start date:30/03/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://stun.fpapi.io
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly