Edit tour

Windows Analysis Report
http://trace.popin.cc

Overview

General Information

Sample URL:http://trace.popin.cc
Analysis ID:847200
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5272 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1836 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1740,i,15941755939994410873,16651756934312648869,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1020 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trace.popin.cc MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:192.168.2.38.8.8.852387532027758 04/15/23-08:43:01.225141
SID:2027758
Source Port:52387
Destination Port:53
Protocol:UDP
Classtype:Potentially Bad Traffic

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior

Networking

barindex
Source: TrafficSnort IDS: 2027758 ET DNS Query for .cc TLD 192.168.2.3:52387 -> 8.8.8.8:53
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: trace.popin.ccConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: trace.popin.ccConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://trace.popin.cc/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: trace.popin.ccConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://trace.popin.cc/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.20.1Date: Sat, 15 Apr 2023 06:43:01 GMTContent-Type: text/plainContent-Length: 18Via: 1.1 googleData Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 Data Ascii: 404 page not found
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.20.1Date: Sat, 15 Apr 2023 06:43:02 GMTContent-Type: text/plainContent-Length: 18Via: 1.1 googleData Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 Data Ascii: 404 page not found
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.20.1Date: Sat, 15 Apr 2023 06:43:02 GMTContent-Type: text/plainContent-Length: 18Via: 1.1 googleData Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 Data Ascii: 404 page not found
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: classification engineClassification label: mal48.win@24/2@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1740,i,15941755939994410873,16651756934312648869,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trace.popin.cc
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1740,i,15941755939994410873,16651756934312648869,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 847200 URL: http://trace.popin.cc Startdate: 15/04/2023 Architecture: WINDOWS Score: 48 24 Snort IDS alert for network traffic 2->24 6 chrome.exe 14 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.1 unknown unknown 6->14 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 clients.l.google.com 142.250.184.110, 443, 49697 GOOGLEUS United States 11->18 20 www.google.com 142.250.184.68, 443, 49703, 49771 GOOGLEUS United States 11->20 22 4 other IPs or domains 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://trace.popin.cc0%Avira URL Cloudsafe
http://trace.popin.cc0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.209.13
truefalse
    high
    www.google.com
    142.250.184.68
    truefalse
      high
      clients.l.google.com
      142.250.184.110
      truefalse
        high
        trace.popin.cc
        35.213.89.133
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://trace.popin.cc/favicon.icofalse
                high
                http://trace.popin.cc/false
                  high
                  http://trace.popin.cc/false
                    high
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      142.250.184.110
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      142.251.209.13
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      142.250.184.68
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      35.213.89.133
                      trace.popin.ccUnited States
                      19527GOOGLE-2USfalse
                      IP
                      192.168.2.1
                      127.0.0.1
                      Joe Sandbox Version:37.0.0 Beryl
                      Analysis ID:847200
                      Start date and time:2023-04-15 08:42:05 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 3m 55s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:http://trace.popin.cc
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:12
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal48.win@24/2@5/7
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 23.0.174.114, 23.0.174.90, 23.0.174.96, 23.0.174.98, 23.0.174.97, 23.0.174.113, 23.0.174.99, 23.0.174.112, 23.0.174.91, 209.197.3.8, 93.184.221.240, 142.250.184.67, 34.104.35.123, 142.250.184.99
                      • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, cds.d2s7q6s2.hwcdn.net, www-www.bing.com.trafficmanager.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, e86303.dscx.akamaiedge.net, www.bing.com.edgekey.net, edgedl.me.gvt1.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtWriteVirtualMemory calls found.
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):18
                      Entropy (8bit):3.5724312513221195
                      Encrypted:false
                      SSDEEP:3:uZuUeB:u5eB
                      MD5:53AF239EE5D3E261545DEDEDCB6FFD57
                      SHA1:04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190
                      SHA-256:99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094
                      SHA-512:C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3
                      Malicious:false
                      Reputation:low
                      URL:http://trace.popin.cc/
                      Preview:404 page not found
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):18
                      Entropy (8bit):3.5724312513221195
                      Encrypted:false
                      SSDEEP:3:uZuUeB:u5eB
                      MD5:53AF239EE5D3E261545DEDEDCB6FFD57
                      SHA1:04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190
                      SHA-256:99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094
                      SHA-512:C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3
                      Malicious:false
                      Reputation:low
                      URL:http://trace.popin.cc/favicon.ico
                      Preview:404 page not found
                      No static file info

                      Download Network PCAP: filteredfull

                      TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                      192.168.2.38.8.8.852387532027758 04/15/23-08:43:01.225141UDP2027758ET DNS Query for .cc TLD5238753192.168.2.38.8.8.8
                      • Total Packets: 64
                      • 443 (HTTPS)
                      • 80 (HTTP)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      Apr 15, 2023 08:42:59.417309999 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.417383909 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.417474031 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.417695999 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.417730093 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:42:59.417815924 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.543749094 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.543811083 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.543952942 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.543986082 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:42:59.685343981 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:42:59.685530901 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.726500988 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.727427959 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.754430056 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.754467964 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.754785061 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.754843950 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:42:59.756266117 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.756419897 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:42:59.759649992 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:42:59.759779930 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:42:59.759788036 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:42:59.759881020 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.587807894 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.588112116 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.588136911 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.588233948 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.589176893 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:43:00.589508057 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:00.589540005 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:43:00.631361961 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.631433010 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:00.631491899 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.631539106 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.631766081 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.631850004 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.643337011 CEST49697443192.168.2.3142.250.184.110
                      Apr 15, 2023 08:43:00.643383026 CEST44349697142.250.184.110192.168.2.3
                      Apr 15, 2023 08:43:00.656877041 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:00.656984091 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:43:00.657006025 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:00.657325029 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:00.657426119 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:43:00.658858061 CEST49698443192.168.2.3142.251.209.13
                      Apr 15, 2023 08:43:00.658888102 CEST44349698142.251.209.13192.168.2.3
                      Apr 15, 2023 08:43:01.459573984 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.460629940 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.586040974 CEST4970280192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.757162094 CEST804969935.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:01.757371902 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.757839918 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.762634039 CEST804970135.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:01.762778044 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:01.882791042 CEST804970235.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:01.882987976 CEST4970280192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.055171013 CEST804969935.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.058057070 CEST804969935.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.064153910 CEST804970135.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.064390898 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.152570009 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.270543098 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.504532099 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.528795958 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.528884888 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.529014111 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.529350996 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.529397964 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.575237036 CEST804969935.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.610204935 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.610677958 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.610726118 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.612091064 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.612248898 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.614532948 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.614736080 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.652652025 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:02.752640009 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.752674103 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:02.811358929 CEST804970135.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.813173056 CEST804970135.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:02.852691889 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:02.953393936 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:12.585650921 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:12.585777044 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:12.585882902 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:14.129688978 CEST49703443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:43:14.129744053 CEST44349703142.250.184.68192.168.2.3
                      Apr 15, 2023 08:43:46.897001028 CEST4970280192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:47.193767071 CEST804970235.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:47.584467888 CEST4969980192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:47.818908930 CEST4970180192.168.2.335.213.89.133
                      Apr 15, 2023 08:43:47.881859064 CEST804969935.213.89.133192.168.2.3
                      Apr 15, 2023 08:43:48.121164083 CEST804970135.213.89.133192.168.2.3
                      Apr 15, 2023 08:44:02.475379944 CEST4970280192.168.2.335.213.89.133
                      Apr 15, 2023 08:44:02.599229097 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.599297047 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.599446058 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.600925922 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.600961924 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.670622110 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.671574116 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.671598911 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.672172070 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.674597025 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.674741983 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:02.720172882 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:02.772325039 CEST804970235.213.89.133192.168.2.3
                      Apr 15, 2023 08:44:02.772510052 CEST4970280192.168.2.335.213.89.133
                      Apr 15, 2023 08:44:12.662020922 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:12.662193060 CEST44349771142.250.184.68192.168.2.3
                      Apr 15, 2023 08:44:12.662331104 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:14.483042955 CEST49771443192.168.2.3142.250.184.68
                      Apr 15, 2023 08:44:14.483094931 CEST44349771142.250.184.68192.168.2.3
                      TimestampSource PortDest PortSource IPDest IP
                      Apr 15, 2023 08:42:59.308366060 CEST4997753192.168.2.38.8.8.8
                      Apr 15, 2023 08:42:59.308813095 CEST5784053192.168.2.38.8.8.8
                      Apr 15, 2023 08:42:59.340636969 CEST53499778.8.8.8192.168.2.3
                      Apr 15, 2023 08:42:59.350716114 CEST53578408.8.8.8192.168.2.3
                      Apr 15, 2023 08:43:01.225141048 CEST5238753192.168.2.38.8.8.8
                      Apr 15, 2023 08:43:01.249718904 CEST53523878.8.8.8192.168.2.3
                      Apr 15, 2023 08:43:02.502571106 CEST4930253192.168.2.38.8.8.8
                      Apr 15, 2023 08:43:02.527071953 CEST53493028.8.8.8192.168.2.3
                      Apr 15, 2023 08:44:02.573712111 CEST6551153192.168.2.38.8.8.8
                      Apr 15, 2023 08:44:02.594825983 CEST53655118.8.8.8192.168.2.3
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Apr 15, 2023 08:42:59.308366060 CEST192.168.2.38.8.8.80xcaedStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                      Apr 15, 2023 08:42:59.308813095 CEST192.168.2.38.8.8.80x9482Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                      Apr 15, 2023 08:43:01.225141048 CEST192.168.2.38.8.8.80x5b79Standard query (0)trace.popin.ccA (IP address)IN (0x0001)false
                      Apr 15, 2023 08:43:02.502571106 CEST192.168.2.38.8.8.80xf1aeStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      Apr 15, 2023 08:44:02.573712111 CEST192.168.2.38.8.8.80x339fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Apr 15, 2023 08:42:59.340636969 CEST8.8.8.8192.168.2.30xcaedNo error (0)accounts.google.com142.251.209.13A (IP address)IN (0x0001)false
                      Apr 15, 2023 08:42:59.350716114 CEST8.8.8.8192.168.2.30x9482No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Apr 15, 2023 08:42:59.350716114 CEST8.8.8.8192.168.2.30x9482No error (0)clients.l.google.com142.250.184.110A (IP address)IN (0x0001)false
                      Apr 15, 2023 08:43:01.249718904 CEST8.8.8.8192.168.2.30x5b79No error (0)trace.popin.cc35.213.89.133A (IP address)IN (0x0001)false
                      Apr 15, 2023 08:43:02.527071953 CEST8.8.8.8192.168.2.30xf1aeNo error (0)www.google.com142.250.184.68A (IP address)IN (0x0001)false
                      Apr 15, 2023 08:44:02.594825983 CEST8.8.8.8192.168.2.30x339fNo error (0)www.google.com142.250.184.68A (IP address)IN (0x0001)false
                      • clients2.google.com
                      • accounts.google.com
                      • trace.popin.cc
                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.349697142.250.184.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.349698142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      2192.168.2.34969935.213.89.13380C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      Apr 15, 2023 08:43:01.757839918 CEST629OUTGET / HTTP/1.1
                      Host: trace.popin.cc
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      Apr 15, 2023 08:43:02.058057070 CEST630INHTTP/1.1 404 Not Found
                      Server: nginx/1.20.1
                      Date: Sat, 15 Apr 2023 06:43:01 GMT
                      Content-Type: text/plain
                      Content-Length: 18
                      Via: 1.1 google
                      Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64
                      Data Ascii: 404 page not found
                      Apr 15, 2023 08:43:02.270543098 CEST630OUTGET /favicon.ico HTTP/1.1
                      Host: trace.popin.cc
                      Connection: keep-alive
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Referer: http://trace.popin.cc/
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      Apr 15, 2023 08:43:02.575237036 CEST632INHTTP/1.1 404 Not Found
                      Server: nginx/1.20.1
                      Date: Sat, 15 Apr 2023 06:43:02 GMT
                      Content-Type: text/plain
                      Content-Length: 18
                      Via: 1.1 google
                      Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64
                      Data Ascii: 404 page not found
                      Apr 15, 2023 08:43:47.584467888 CEST647OUTData Raw: 00
                      Data Ascii:


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      3192.168.2.34970135.213.89.13380C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      Apr 15, 2023 08:43:02.504532099 CEST631OUTGET / HTTP/1.1
                      Host: trace.popin.cc
                      Connection: keep-alive
                      Cache-Control: max-age=0
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Referer: http://trace.popin.cc/
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      Apr 15, 2023 08:43:02.813173056 CEST637INHTTP/1.1 404 Not Found
                      Server: nginx/1.20.1
                      Date: Sat, 15 Apr 2023 06:43:02 GMT
                      Content-Type: text/plain
                      Content-Length: 18
                      Via: 1.1 google
                      Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64
                      Data Ascii: 404 page not found
                      Apr 15, 2023 08:43:47.818908930 CEST647OUTData Raw: 00
                      Data Ascii:


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      4192.168.2.34970235.213.89.13380C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      Apr 15, 2023 08:43:46.897001028 CEST646OUTData Raw: 00
                      Data Ascii:


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.349697142.250.184.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-04-15 06:43:00 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                      Host: clients2.google.com
                      Connection: keep-alive
                      X-Goog-Update-Interactivity: fg
                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                      X-Goog-Update-Updater: chromecrx-104.0.5112.81
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-04-15 06:43:00 UTC1INHTTP/1.1 200 OK
                      Content-Security-Policy: script-src 'report-sample' 'nonce-x2d121Z5mbRdEzEZHPGkfA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Sat, 15 Apr 2023 06:43:00 GMT
                      Content-Type: text/xml; charset=UTF-8
                      X-Daynum: 5947
                      X-Daystart: 85380
                      X-Content-Type-Options: nosniff
                      X-Frame-Options: SAMEORIGIN
                      X-XSS-Protection: 1; mode=block
                      Server: GSE
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-04-15 06:43:00 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 34 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 38 35 33 38 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                      Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5947" elapsed_seconds="85380"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                      2023-04-15 06:43:00 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                      Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                      2023-04-15 06:43:00 UTC2INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.349698142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-04-15 06:43:00 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                      Host: accounts.google.com
                      Connection: keep-alive
                      Content-Length: 1
                      Origin: https://www.google.com
                      Content-Type: application/x-www-form-urlencoded
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
                      2023-04-15 06:43:00 UTC1OUTData Raw: 20
                      Data Ascii:
                      2023-04-15 06:43:00 UTC2INHTTP/1.1 200 OK
                      Content-Type: application/json; charset=utf-8
                      Access-Control-Allow-Origin: https://www.google.com
                      Access-Control-Allow-Credentials: true
                      X-Content-Type-Options: nosniff
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Sat, 15 Apr 2023 06:43:00 GMT
                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                      Content-Security-Policy: script-src 'report-sample' 'nonce-p4Zu1bIcNpRmJYfdqTQJ9A' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                      Cross-Origin-Opener-Policy: same-origin
                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                      Server: ESF
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-04-15 06:43:00 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                      Data Ascii: 11["gaia.l.a.r",[]]
                      2023-04-15 06:43:00 UTC4INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      020406080s020406080100

                      Click to jump to process

                      020406080s0.0020406080100MB

                      Click to jump to process

                      • File
                      • Registry

                      Click to dive into process behavior distribution

                      Target ID:0
                      Start time:08:42:56
                      Start date:15/04/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      Target ID:1
                      Start time:08:42:57
                      Start date:15/04/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1740,i,15941755939994410873,16651756934312648869,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      Target ID:2
                      Start time:08:43:00
                      Start date:15/04/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://trace.popin.cc
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      No disassembly