Edit tour

Windows Analysis Report
https://.blob.core.windows.net

Overview

General Information

Sample URL:https://.blob.core.windows.net
Analysis ID:868654
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 1724 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://.blob.core.windows.net/ MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6688 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1764,i,12663068152591345820,18443021375276517629,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: clean0.win@31/0@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://.blob.core.windows.net/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1764,i,12663068152591345820,18443021375276517629,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1764,i,12663068152591345820,18443021375276517629,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 868654 URL: https://.blob.core.windows.net Startdate: 18/05/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 14 1 2->5         started        dnsIp3 11 192.168.2.1 unknown unknown 5->11 13 239.255.255.250 unknown Reserved 5->13 8 chrome.exe 5->8         started        process4 dnsIp5 15 www.google.com 142.250.184.228, 443, 49735, 49741 GOOGLEUS United States 8->15 17 clients.l.google.com 142.250.185.78, 443, 49731 GOOGLEUS United States 8->17 19 2 other IPs or domains 8->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://.blob.core.windows.net0%Avira URL Cloudsafe
https://.blob.core.windows.net0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.212.173
truefalse
    high
    www.google.com
    142.250.184.228
    truefalse
      high
      clients.l.google.com
      142.250.185.78
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.185.78
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              216.58.212.173
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              142.250.184.228
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              Joe Sandbox Version:37.1.0 Beryl
              Analysis ID:868654
              Start date and time:2023-05-18 00:18:39 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 3m 51s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Sample URL:https://.blob.core.windows.net
              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:1
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@31/0@6/5
              • Exclude process from analysis (whitelisted): WMIADAP.exe, SgrmBroker.exe, usocoreworker.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.186.99, 34.104.35.123, 142.250.185.163
              • Excluded domains from analysis (whitelisted): client.wns.windows.com, edgedl.me.gvt1.com, login.live.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 45
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              May 18, 2023 00:19:16.431649923 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.431744099 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.431906939 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.432123899 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.432182074 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.432296038 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.440331936 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.440407038 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.444221020 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.444269896 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.508245945 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.528040886 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.528115034 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.531414986 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.531595945 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.548712969 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.549160004 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.549195051 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.549773932 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.549861908 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.551224947 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.551312923 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.877253056 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.877604008 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.877657890 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.877907991 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.877968073 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.878106117 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.878673077 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.878706932 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.909950018 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.910126925 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.910165071 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.910224915 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.910284996 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.915071964 CEST49731443192.168.2.3142.250.185.78
              May 18, 2023 00:19:16.915117025 CEST44349731142.250.185.78192.168.2.3
              May 18, 2023 00:19:16.921113014 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.945005894 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.945323944 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:16.945434093 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.947242022 CEST49730443192.168.2.3216.58.212.173
              May 18, 2023 00:19:16.947285891 CEST44349730216.58.212.173192.168.2.3
              May 18, 2023 00:19:20.219568014 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.219655991 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.219777107 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.220109940 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.220134020 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.285060883 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.285607100 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.285674095 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.287467003 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.287645102 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.289920092 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.290142059 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.380026102 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:20.380079985 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:20.479983091 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:30.316298008 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:30.316366911 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:19:30.316639900 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:32.178769112 CEST49735443192.168.2.3142.250.184.228
              May 18, 2023 00:19:32.178834915 CEST44349735142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.263823986 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:20.263906956 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.264009953 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:20.264369965 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:20.264394045 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.326663017 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.327174902 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:20.327239037 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.328306913 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.328777075 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:20.328991890 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:20.370245934 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:30.324054003 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:30.324198008 CEST44349741142.250.184.228192.168.2.3
              May 18, 2023 00:20:30.324512959 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:52.711473942 CEST49741443192.168.2.3142.250.184.228
              May 18, 2023 00:20:52.711544037 CEST44349741142.250.184.228192.168.2.3
              TimestampSource PortDest PortSource IPDest IP
              May 18, 2023 00:19:16.262734890 CEST4924453192.168.2.31.1.1.1
              May 18, 2023 00:19:16.263202906 CEST6330253192.168.2.31.1.1.1
              May 18, 2023 00:19:16.279871941 CEST53492441.1.1.1192.168.2.3
              May 18, 2023 00:19:16.280179977 CEST53633021.1.1.1192.168.2.3
              May 18, 2023 00:19:20.172970057 CEST5237053192.168.2.31.1.1.1
              May 18, 2023 00:19:20.190172911 CEST53523701.1.1.1192.168.2.3
              May 18, 2023 00:19:20.195452929 CEST5809953192.168.2.31.1.1.1
              May 18, 2023 00:19:20.212558985 CEST53580991.1.1.1192.168.2.3
              May 18, 2023 00:20:20.225635052 CEST6248353192.168.2.31.1.1.1
              May 18, 2023 00:20:20.242744923 CEST53624831.1.1.1192.168.2.3
              May 18, 2023 00:20:20.245426893 CEST5826053192.168.2.31.1.1.1
              May 18, 2023 00:20:20.262562990 CEST53582601.1.1.1192.168.2.3
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              May 18, 2023 00:19:16.262734890 CEST192.168.2.31.1.1.10x6d6Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              May 18, 2023 00:19:16.263202906 CEST192.168.2.31.1.1.10x767aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              May 18, 2023 00:19:20.172970057 CEST192.168.2.31.1.1.10x8278Standard query (0)www.google.comA (IP address)IN (0x0001)false
              May 18, 2023 00:19:20.195452929 CEST192.168.2.31.1.1.10x76a5Standard query (0)www.google.comA (IP address)IN (0x0001)false
              May 18, 2023 00:20:20.225635052 CEST192.168.2.31.1.1.10x94Standard query (0)www.google.comA (IP address)IN (0x0001)false
              May 18, 2023 00:20:20.245426893 CEST192.168.2.31.1.1.10xdb34Standard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              May 18, 2023 00:19:16.279871941 CEST1.1.1.1192.168.2.30x6d6No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              May 18, 2023 00:19:16.279871941 CEST1.1.1.1192.168.2.30x6d6No error (0)clients.l.google.com142.250.185.78A (IP address)IN (0x0001)false
              May 18, 2023 00:19:16.280179977 CEST1.1.1.1192.168.2.30x767aNo error (0)accounts.google.com216.58.212.173A (IP address)IN (0x0001)false
              May 18, 2023 00:19:20.190172911 CEST1.1.1.1192.168.2.30x8278No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              May 18, 2023 00:19:20.212558985 CEST1.1.1.1192.168.2.30x76a5No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              May 18, 2023 00:20:20.242744923 CEST1.1.1.1192.168.2.30x94No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              May 18, 2023 00:20:20.262562990 CEST1.1.1.1192.168.2.30xdb34No error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              • accounts.google.com
              • clients2.google.com
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349730216.58.212.173443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-05-17 22:19:16 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
              2023-05-17 22:19:16 UTC0OUTData Raw: 20
              Data Ascii:
              2023-05-17 22:19:16 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 17 May 2023 22:19:16 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Content-Security-Policy: script-src 'report-sample' 'nonce-xMDMZutPz0Fb0mefRAWqQQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Cross-Origin-Opener-Policy: same-origin
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-05-17 22:19:16 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-05-17 22:19:16 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349731142.250.185.78443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-05-17 22:19:16 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.102
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-05-17 22:19:16 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-fjZVhiqgvBvosjcQWTd9fA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Wed, 17 May 2023 22:19:16 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5980
              X-Daystart: 55156
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-05-17 22:19:16 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 38 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 35 31 35 36 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5980" elapsed_seconds="55156"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-05-17 22:19:16 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-05-17 22:19:16 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              050100s020406080100

              Click to jump to process

              050100s0.0020406080100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:6
              Start time:00:19:12
              Start date:18/05/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://.blob.core.windows.net/
              Imagebase:0x7ff70f0c0000
              File size:2852640 bytes
              MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:7
              Start time:00:19:14
              Start date:18/05/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1764,i,12663068152591345820,18443021375276517629,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff70f0c0000
              File size:2852640 bytes
              MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly