Edit tour

Windows Analysis Report
http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d

Overview

General Information

Sample URL:http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKU
Analysis ID:847893
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5412 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1800 --field-trial-handle=1724,i,12622367353433022462,13027316402469830943,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 4788 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: classification engineClassification label: clean0.win@25/2@4/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1800 --field-trial-handle=1724,i,12622367353433022462,13027316402469830943,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1800 --field-trial-handle=1724,i,12622367353433022462,13027316402469830943,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 847893 URL: http://11.tlu.dl.delivery.m... Startdate: 17/04/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 clients.l.google.com 142.250.184.110, 443, 49690 GOOGLEUS United States 10->17 19 www.google.com 142.250.184.68, 443, 49695, 49768 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.209.13
truefalse
    high
    www.google.com
    142.250.184.68
    truefalse
      high
      clients.l.google.com
      142.250.184.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.184.110
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              142.251.209.13
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              142.250.184.68
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              IP
              192.168.2.1
              127.0.0.1
              Joe Sandbox Version:37.0.0 Beryl
              Analysis ID:847893
              Start date and time:2023-04-17 06:59:58 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 3m 58s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:14
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@25/2@4/6
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.184.67, 34.104.35.123, 93.184.221.240, 142.250.184.99
              • Excluded domains from analysis (whitelisted): www.bing.com, tlu-dcat.ec.azureedge.net, fs.microsoft.com, edgedl.me.gvt1.com, tlu-dcat.azureedge.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, wu.wpc.apr-52dd2.edgecastdns.net, 11.tlu.dl.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text
              Category:downloaded
              Size (bytes):345
              Entropy (8bit):5.308834490275622
              Encrypted:false
              SSDEEP:6:TMVBdoIUnWn8FX0wa9Fgc4svquXsLwFcn4mc4sVI/iHI0aXgsoGH4CmL0Xgs0JQL:TMHdoIWWnMEwKFcuX4wp57iwsoTCmL0P
              MD5:A7B900BEC0B7B386DFD18AD22C9ED411
              SHA1:72E09EC6E4D46F8D96907F6E55BC4F26975C4C4F
              SHA-256:D9F7E0AA1BFF501986995B7C69742A14F373819AB6ECD599AF29D67F9D8B4794
              SHA-512:D7D43F3326FB0E45ED17BC8F3054EA4A45AD8A32C6407A6158F18562F7950D596F9F3E280C00E2374A029A59C1FD4AFE519926678590405300315D0F0C9AE53F
              Malicious:false
              Reputation:low
              URL:http://11.tlu.dl.delivery.mp.microsoft.com/favicon.ico
              Preview:<?xml version="1.0" encoding="iso-8859-1"?>.<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN". "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">.<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">..<head>...<title>403 - Forbidden</title>..</head>..<body>...<h1>403 - Forbidden</h1>..</body>.</html>.
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text
              Category:downloaded
              Size (bytes):345
              Entropy (8bit):5.308834490275622
              Encrypted:false
              SSDEEP:6:TMVBdoIUnWn8FX0wa9Fgc4svquXsLwFcn4mc4sVI/iHI0aXgsoGH4CmL0Xgs0JQL:TMHdoIWWnMEwKFcuX4wp57iwsoTCmL0P
              MD5:A7B900BEC0B7B386DFD18AD22C9ED411
              SHA1:72E09EC6E4D46F8D96907F6E55BC4F26975C4C4F
              SHA-256:D9F7E0AA1BFF501986995B7C69742A14F373819AB6ECD599AF29D67F9D8B4794
              SHA-512:D7D43F3326FB0E45ED17BC8F3054EA4A45AD8A32C6407A6158F18562F7950D596F9F3E280C00E2374A029A59C1FD4AFE519926678590405300315D0F0C9AE53F
              Malicious:false
              Reputation:low
              URL:http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d
              Preview:<?xml version="1.0" encoding="iso-8859-1"?>.<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN". "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">.<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">..<head>...<title>403 - Forbidden</title>..</head>..<body>...<h1>403 - Forbidden</h1>..</body>.</html>.
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 45
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2023 07:00:51.315288067 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.315352917 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.315462112 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.315568924 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.315598011 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.315803051 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.316442966 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.316504955 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.316566944 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.316596031 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.477699995 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.477931023 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.528397083 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.578536987 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.921164036 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.921224117 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.921426058 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.921514988 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.923048019 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.923171043 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.926307917 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.926372051 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:51.926425934 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:51.926449060 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:51.926515102 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:51.992594957 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.463015079 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:52.463490963 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:52.463516951 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:52.464333057 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.464652061 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.464767933 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.464812040 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.505651951 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:52.505789995 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:52.505830050 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:52.505943060 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:52.506032944 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:52.526633978 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.526747942 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.526770115 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.527237892 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.527328014 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.893951893 CEST49691443192.168.2.3142.251.209.13
              Apr 17, 2023 07:00:52.893985987 CEST44349691142.251.209.13192.168.2.3
              Apr 17, 2023 07:00:52.895442963 CEST49690443192.168.2.3142.250.184.110
              Apr 17, 2023 07:00:52.895488977 CEST44349690142.250.184.110192.168.2.3
              Apr 17, 2023 07:00:54.638293028 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.638348103 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.638430119 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.638817072 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.638850927 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.715250969 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.715734959 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.715774059 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.717196941 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.717312098 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.719764948 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:00:54.719892979 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.927455902 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:00:54.927584887 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:04.685942888 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:04.686086893 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:04.686176062 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:06.213278055 CEST49695443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:06.213326931 CEST44349695142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.739871979 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:54.739933014 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.740041971 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:54.740375996 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:54.740411043 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.809323072 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.818860054 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:54.818903923 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.819725037 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.820230007 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:01:54.820413113 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:01:54.869082928 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:02:04.784984112 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:02:04.785060883 CEST44349768142.250.184.68192.168.2.3
              Apr 17, 2023 07:02:04.785171032 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:02:04.878268003 CEST49768443192.168.2.3142.250.184.68
              Apr 17, 2023 07:02:04.878319979 CEST44349768142.250.184.68192.168.2.3
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2023 07:00:51.268927097 CEST5932453192.168.2.38.8.8.8
              Apr 17, 2023 07:00:51.270100117 CEST5901453192.168.2.38.8.8.8
              Apr 17, 2023 07:00:51.290518999 CEST53590148.8.8.8192.168.2.3
              Apr 17, 2023 07:00:51.301224947 CEST53593248.8.8.8192.168.2.3
              Apr 17, 2023 07:00:54.615520000 CEST4997753192.168.2.38.8.8.8
              Apr 17, 2023 07:00:54.636240959 CEST53499778.8.8.8192.168.2.3
              Apr 17, 2023 07:01:54.714056969 CEST5342853192.168.2.38.8.8.8
              Apr 17, 2023 07:01:54.737488031 CEST53534288.8.8.8192.168.2.3
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 17, 2023 07:00:51.268927097 CEST192.168.2.38.8.8.80x67e8Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Apr 17, 2023 07:00:51.270100117 CEST192.168.2.38.8.8.80x73baStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Apr 17, 2023 07:00:54.615520000 CEST192.168.2.38.8.8.80xf745Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 17, 2023 07:01:54.714056969 CEST192.168.2.38.8.8.80xbf13Standard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 17, 2023 07:00:51.290518999 CEST8.8.8.8192.168.2.30x73baNo error (0)accounts.google.com142.251.209.13A (IP address)IN (0x0001)false
              Apr 17, 2023 07:00:51.301224947 CEST8.8.8.8192.168.2.30x67e8No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2023 07:00:51.301224947 CEST8.8.8.8192.168.2.30x67e8No error (0)clients.l.google.com142.250.184.110A (IP address)IN (0x0001)false
              Apr 17, 2023 07:00:54.636240959 CEST8.8.8.8192.168.2.30xf745No error (0)www.google.com142.250.184.68A (IP address)IN (0x0001)false
              Apr 17, 2023 07:01:54.737488031 CEST8.8.8.8192.168.2.30xbf13No error (0)www.google.com142.250.184.68A (IP address)IN (0x0001)false
              • clients2.google.com
              • accounts.google.com
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349690142.250.184.110443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-04-17 05:00:52 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-04-17 05:00:52 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-TbPx-7BJPdlN1XwpdMT9BA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Mon, 17 Apr 2023 05:00:52 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5949
              X-Daystart: 79252
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-04-17 05:00:52 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 34 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 37 39 32 35 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5949" elapsed_seconds="79252"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-04-17 05:00:52 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-04-17 05:00:52 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349691142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-04-17 05:00:52 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
              2023-04-17 05:00:52 UTC1OUTData Raw: 20
              Data Ascii:
              2023-04-17 05:00:52 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Mon, 17 Apr 2023 05:00:52 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Content-Security-Policy: script-src 'report-sample' 'nonce-qgtoZd4pRiDa-oTIjG-tDw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
              Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
              Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-04-17 05:00:52 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-04-17 05:00:52 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Target ID:0
              Start time:07:00:47
              Start date:17/04/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:1
              Start time:07:00:48
              Start date:17/04/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1800 --field-trial-handle=1724,i,12622367353433022462,13027316402469830943,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:07:00:51
              Start date:17/04/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://11.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1680562156&P2=404&P3=2&P4=Qb4Wr0FKnUppk0C6RdxLiqiAF1YA4fVyxOY8OQInsnDEDh26svm2tSC01A718DKUqP1UFZeyDCHxjQ6ifN6qPw%3d%3d
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly