Edit tour

Windows Analysis Report
http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/

Overview

General Information

Sample URL:http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/
Analysis ID:845079
Infos:
Errors
  • URL not reachable

Detection

Score:20
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Uses TOR for connection hidding

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w7x64
  • chrome.exe (PID: 2548 cmdline: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 6ACAE527E744C80997B25EF2A0485D5E)
    • chrome.exe (PID: 3024 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1008,8397083868730616882,18242825326804217298,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1352 /prefetch:8 MD5: 6ACAE527E744C80997B25EF2A0485D5E)
  • chrome.exe (PID: 2940 cmdline: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/ MD5: 6ACAE527E744C80997B25EF2A0485D5E)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Networking

barindex
Source: unknownDNS query: name: bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion
Source: unknownDNS query: name: bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion
Source: unknownDNS query: name: bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-84.0.4147.135Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: bgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-84.0.4147.135Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49176
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49175
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49174
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49173
Source: unknownNetwork traffic detected: HTTP traffic on port 49175 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49176 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49173 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49174 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=WP.289365
Source: classification engineClassification label: sus20.troj.win@27/0@9/4
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1008,8397083868730616882,18242825326804217298,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1352 /prefetch:8
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1008,8397083868730616882,18242825326804217298,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1352 /prefetch:8Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Multi-hop Proxy
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration3
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer4
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
Proxy
Manipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 Channel1
Ingress Tool Transfer
Jamming or Denial of ServiceAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 845079 URL: http://bbzzzsvqcrqtki6umym6... Startdate: 12/04/2023 Architecture: WINDOWS Score: 20 22 Uses TOR for connection hidding 2->22 6 chrome.exe 12 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 239.255.255.250 unknown Reserved 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion 11->16 18 accounts.google.com 172.217.168.45, 443, 49174, 49176 GOOGLEUS United States 11->18 20 4 other IPs or domains 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.168.14
truefalse
    high
    accounts.google.com
    172.217.168.45
    truefalse
      high
      clients.l.google.com
      216.58.215.238
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion
          unknown
          unknowntrue
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26ucfalse
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  172.217.168.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.215.238
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  127.0.0.1
                  Joe Sandbox Version:37.0.0 Beryl
                  Analysis ID:845079
                  Start date and time:2023-04-12 01:45:52 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 2m 41s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/
                  Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                  Number of analysed new started processes analysed:3
                  Number of new started drivers analysed:2
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:SUS
                  Classification:sus20.troj.win@27/0@9/4
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • URL browsing timeout or error
                  • URL not reachable
                  • Exclude process from analysis (whitelisted): vga.dll
                  • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 52
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 12, 2023 01:46:46.959016085 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:46.959088087 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:46.959172964 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:46.963222027 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:46.963263988 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:46.963339090 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.005285025 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.005336046 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.005464077 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.052310944 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.052386999 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.052474976 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.273818016 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.273871899 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.278275013 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.278312922 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.278502941 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.278542995 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.278702974 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.278723955 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.352900028 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.396102905 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.432727098 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.432768106 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.433018923 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.433053017 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.434892893 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.434921980 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.435000896 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.435631037 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.435730934 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.439543962 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.439650059 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.439798117 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.439857960 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.474283934 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.474314928 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.474572897 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:47.474627018 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.475696087 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.475785017 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.477679968 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:47.477751970 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:47.477936983 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:47.478020906 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.133696079 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.133759022 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.134047985 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.134107113 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.134150028 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.134260893 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.134293079 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.134419918 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.134444952 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.134557962 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.134848118 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.134903908 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.134942055 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.135092020 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.135219097 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.135248899 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.169131041 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.169253111 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.169286966 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.169487953 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.169557095 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.218216896 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.218364954 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.218419075 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.218760967 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.218848944 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.333404064 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.333420038 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.333429098 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.333470106 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.339832067 CEST49173443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.339870930 CEST44349173216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:49.485282898 CEST49174443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:49.485327005 CEST44349174172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:49.533512115 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:49.535478115 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:53.145220041 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:53.145287037 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:53.179924965 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:53.180295944 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:53.180433035 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:53.181474924 CEST49175443192.168.2.22216.58.215.238
                  Apr 12, 2023 01:46:53.181526899 CEST44349175216.58.215.238192.168.2.22
                  Apr 12, 2023 01:46:59.785418034 CEST49176443192.168.2.22172.217.168.45
                  Apr 12, 2023 01:46:59.785621881 CEST44349176172.217.168.45192.168.2.22
                  Apr 12, 2023 01:46:59.785701990 CEST49176443192.168.2.22172.217.168.45
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 12, 2023 01:46:46.754419088 CEST5440853192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:46.773123026 CEST5010853192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:46.792968035 CEST53501088.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:46.795059919 CEST53544088.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:47.324469090 CEST5472353192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:47.353352070 CEST53547238.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:48.556099892 CEST5670553192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:48.587359905 CEST5670653192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:48.597820044 CEST53567058.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:48.607455969 CEST53567068.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:49.020879030 CEST5524453192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:49.044634104 CEST53552448.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:54.285790920 CEST6428153192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:54.306458950 CEST53642818.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:54.330121040 CEST6428253192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:54.341614962 CEST6428353192.168.2.228.8.8.8
                  Apr 12, 2023 01:46:54.371325016 CEST53642828.8.8.8192.168.2.22
                  Apr 12, 2023 01:46:54.375040054 CEST53642838.8.8.8192.168.2.22
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Apr 12, 2023 01:46:46.754419088 CEST192.168.2.228.8.8.80x1f97Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:46.773123026 CEST192.168.2.228.8.8.80xf71fStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:47.324469090 CEST192.168.2.228.8.8.80x9122Standard query (0)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:48.556099892 CEST192.168.2.228.8.8.80x9358Standard query (0)google.comA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:48.587359905 CEST192.168.2.228.8.8.80xcef8Standard query (0)google.comA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:49.020879030 CEST192.168.2.228.8.8.80x7b4fStandard query (0)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.285790920 CEST192.168.2.228.8.8.80x4b54Standard query (0)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.330121040 CEST192.168.2.228.8.8.80xfb1eStandard query (0)google.comA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.341614962 CEST192.168.2.228.8.8.80xe4ddStandard query (0)google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Apr 12, 2023 01:46:46.792968035 CEST8.8.8.8192.168.2.220xf71fNo error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:46.795059919 CEST8.8.8.8192.168.2.220x1f97No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Apr 12, 2023 01:46:46.795059919 CEST8.8.8.8192.168.2.220x1f97No error (0)clients.l.google.com216.58.215.238A (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:47.353352070 CEST8.8.8.8192.168.2.220x9122Name error (3)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionnonenoneA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:48.597820044 CEST8.8.8.8192.168.2.220x9358No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:48.607455969 CEST8.8.8.8192.168.2.220xcef8No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:49.044634104 CEST8.8.8.8192.168.2.220x7b4fName error (3)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionnonenoneA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.306458950 CEST8.8.8.8192.168.2.220x4b54Name error (3)bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onionnonenoneA (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.371325016 CEST8.8.8.8192.168.2.220xfb1eNo error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Apr 12, 2023 01:46:54.375040054 CEST8.8.8.8192.168.2.220xe4ddNo error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.2249174172.217.168.45443C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-04-11 23:46:49 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: CONSENT=WP.289365
                  2023-04-11 23:46:49 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-04-11 23:46:49 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 11 Apr 2023 23:46:49 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Content-Security-Policy: script-src 'report-sample' 'nonce-9JcUJ-BzAfQdcG0xeQ4HGA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Cross-Origin-Opener-Policy: same-origin
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-04-11 23:46:49 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-04-11 23:46:49 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.2249173216.58.215.238443C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-04-11 23:46:49 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfm
                  X-Goog-Update-Updater: chromecrx-84.0.4147.135
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-04-11 23:46:49 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-KIu7emKrpaLHnAfKjUNbDQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 11 Apr 2023 23:46:49 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5944
                  X-Daystart: 60409
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-04-11 23:46:49 UTC2INData Raw: 33 31 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 34 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 36 30 34 30 39 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 31a<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5944" elapsed_seconds="60409"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-04-11 23:46:49 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 70 6b 65 64 63 6a 6b 64 65 66 67 70 64 65 6c 70 62 63 6d 62 6d 65 6f 6d 63 6a 62 65 65 6d 66 6d 22 20 73 74 61 74 75 73 3d 22 65 72 72 6f 72 2d 75 6e 6b 6e 6f 77 6e
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app><app appid="pkedcjkdefgpdelpbcmbmeomcjbeemfm" status="error-unknown
                  2023-04-11 23:46:49 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  2192.168.2.2249175216.58.215.238443C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-04-11 23:46:53 UTC4OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: bg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfm
                  X-Goog-Update-Updater: chromecrx-84.0.4147.135
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-04-11 23:46:53 UTC5INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-QjVBs6i2AR6rN12qLowk6g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 11 Apr 2023 23:46:53 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5944
                  X-Daystart: 60413
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-04-11 23:46:53 UTC5INData Raw: 33 31 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 34 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 36 30 34 31 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 31a<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5944" elapsed_seconds="60413"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-04-11 23:46:53 UTC6INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 70 6b 65 64 63 6a 6b 64 65 66 67 70 64 65 6c 70 62 63 6d 62 6d 65 6f 6d 63 6a 62 65 65 6d 66 6d 22 20 73 74 61 74 75 73 3d 22 65 72 72 6f 72 2d 75 6e 6b 6e 6f 77 6e
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app><app appid="pkedcjkdefgpdelpbcmbmeomcjbeemfm" status="error-unknown
                  2023-04-11 23:46:53 UTC6INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  0510152025s020406080100

                  Click to jump to process

                  0510152025s0.0020406080MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:01:46:16
                  Start date:12/04/2023
                  Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x13f830000
                  File size:1820656 bytes
                  MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:1
                  Start time:01:46:17
                  Start date:12/04/2023
                  Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1008,8397083868730616882,18242825326804217298,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1352 /prefetch:8
                  Imagebase:0x13f830000
                  File size:1820656 bytes
                  MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:4
                  Start time:01:46:18
                  Start date:12/04/2023
                  Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "http://bbzzzsvqcrqtki6umym6itiixfhni37ybtt7mkbjyxn2pgllzxf2qgyd.onion/showcase/
                  Imagebase:0x13f830000
                  File size:1820656 bytes
                  MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly