Edit tour

Windows Analysis Report
http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556

Overview

General Information

Sample URL:http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
Analysis ID:874255
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5612 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5968 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1732,i,16200984928723150921,8986171839187517471,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6348 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556HTTP Parser: No favicon
Source: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556 HTTP/1.1Host: r1.visualwebsiteoptimizer.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: r1.visualwebsiteoptimizer.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556 HTTP/1.1Host: r1.visualwebsiteoptimizer.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: r1.visualwebsiteoptimizer.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: r1.visualwebsiteoptimizer.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: classification engineClassification label: clean0.win@24/3@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1732,i,16200984928723150921,8986171839187517471,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1732,i,16200984928723150921,8986171839187517471,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 874255 URL: http://r1.visualwebsiteopti... Startdate: 24/05/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49704, 49708 GOOGLEUS United States 10->17 19 accounts.google.com 172.217.168.45, 443, 49697 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n12775560%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.168.45
truefalse
    high
    r1.visualwebsiteoptimizer.com
    35.245.208.72
    truefalse
      high
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        216.58.215.238
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556false
              high
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556false
                  high
                  http://r1.visualwebsiteoptimizer.com/favicon.icofalse
                    high
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      35.245.208.72
                      r1.visualwebsiteoptimizer.comUnited States
                      15169GOOGLEUSfalse
                      172.217.168.45
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      216.58.215.238
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      142.250.203.100
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.2.22
                      192.168.2.1
                      Joe Sandbox Version:37.1.0 Beryl
                      Analysis ID:874255
                      Start date and time:2023-05-24 00:57:06 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 4m 45s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:5
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean0.win@24/3@5/7
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                      • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123, 216.58.215.227
                      • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                      • Not all processes where analyzed, report is missing behavior information
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:gzip compressed data, from Unix, truncated
                      Category:dropped
                      Size (bytes):20
                      Entropy (8bit):1.2917601481809733
                      Encrypted:false
                      SSDEEP:3:Ftt:Xt
                      MD5:7029066C27AC6F5EF18D660D5741979A
                      SHA1:46C6643F07AA7F6BFE7118DE926B86DEFC5087C4
                      SHA-256:59869DB34853933B239F1E2219CF7D431DA006AA919635478511FABBFC8849D2
                      SHA-512:7E8E93F4A89CE7FAE011403E14A1D53544C6E6F6B6010D61129DC27937806D2B03802610D7999EAB33A4C36B0F9E001D9D76001B8354087634C1AA9C740C536F
                      Malicious:false
                      Reputation:low
                      Preview:....................
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:GIF image data, version 89a, 1 x 1
                      Category:downloaded
                      Size (bytes):35
                      Entropy (8bit):2.9889227488523016
                      Encrypted:false
                      SSDEEP:3:CUdrllHh/:HJ/
                      MD5:28D6814F309EA289F847C69CF91194C6
                      SHA1:0F4E929DD5BB2564F7AB9C76338E04E292A42ACE
                      SHA-256:8337212354871836E6763A41E615916C89BAC5B3F1F0ADF60BA43C7C806E1015
                      SHA-512:1D68B92E8D822FE82DC7563EDD7B37F3418A02A89F1A9F0454CCA664C2FC2565235E0D85540FF9BE0B20175BE3F5B7B4EAE1175067465D5CCA13486AAB4C582C
                      Malicious:false
                      Reputation:low
                      URL:http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Preview:GIF89a.............,...........D..;
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:gzip compressed data, from Unix, truncated
                      Category:downloaded
                      Size (bytes):20
                      Entropy (8bit):1.2917601481809733
                      Encrypted:false
                      SSDEEP:3:Ftt:Xt
                      MD5:7029066C27AC6F5EF18D660D5741979A
                      SHA1:46C6643F07AA7F6BFE7118DE926B86DEFC5087C4
                      SHA-256:59869DB34853933B239F1E2219CF7D431DA006AA919635478511FABBFC8849D2
                      SHA-512:7E8E93F4A89CE7FAE011403E14A1D53544C6E6F6B6010D61129DC27937806D2B03802610D7999EAB33A4C36B0F9E001D9D76001B8354087634C1AA9C740C536F
                      Malicious:false
                      Reputation:low
                      URL:http://r1.visualwebsiteoptimizer.com/favicon.ico
                      Preview:....................
                      No static file info

                      Download Network PCAP: filteredfull

                      • Total Packets: 62
                      • 443 (HTTPS)
                      • 80 (HTTP)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      May 24, 2023 00:57:59.894068956 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:57:59.894146919 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:57:59.894301891 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:57:59.895158052 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:57:59.895224094 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:57:59.895314932 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:57:59.895826101 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:57:59.895869970 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:57:59.897011042 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:57:59.897066116 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.033041954 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.033474922 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.033526897 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.035068035 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.035649061 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.035747051 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.036396980 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.036443949 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.037622929 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.037720919 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.038930893 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.039000034 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.353105068 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.353318930 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.353344917 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.353523970 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.353837013 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.353945971 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.353969097 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.354216099 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.386260986 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.386487961 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.386509895 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:00.386598110 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.398899078 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.398958921 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.401690006 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.401823044 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.401873112 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.401988029 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.402091026 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.430926085 CEST49697443192.168.2.3172.217.168.45
                      May 24, 2023 00:58:00.430977106 CEST44349697172.217.168.45192.168.2.3
                      May 24, 2023 00:58:00.431576967 CEST49699443192.168.2.3216.58.215.238
                      May 24, 2023 00:58:00.431610107 CEST44349699216.58.215.238192.168.2.3
                      May 24, 2023 00:58:01.857640028 CEST4970180192.168.2.335.245.208.72
                      May 24, 2023 00:58:01.858338118 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:01.996100903 CEST804970135.245.208.72192.168.2.3
                      May 24, 2023 00:58:01.996329069 CEST4970180192.168.2.335.245.208.72
                      May 24, 2023 00:58:01.996357918 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:01.996512890 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:02.033539057 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:02.171883106 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:02.172070980 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:02.246423960 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:02.577907085 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:02.716409922 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:02.759625912 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:03.176359892 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:03.316593885 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:03.446340084 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:03.507859945 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:03.574204922 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.574275017 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.574374914 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.574743986 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.574780941 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.637578011 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.638340950 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.638421059 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.639616966 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.639717102 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.646275997 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:03.654422045 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.654706001 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.671355963 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:03.809782982 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:03.811990023 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:03.812015057 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:03.858978987 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:04.015116930 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:04.238773108 CEST804970135.245.208.72192.168.2.3
                      May 24, 2023 00:58:04.238864899 CEST4970180192.168.2.335.245.208.72
                      May 24, 2023 00:58:05.094243050 CEST4970180192.168.2.335.245.208.72
                      May 24, 2023 00:58:05.232693911 CEST804970135.245.208.72192.168.2.3
                      May 24, 2023 00:58:13.231157064 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:58:13.231300116 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:13.684468985 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:13.684598923 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:13.684706926 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:16.418060064 CEST4970280192.168.2.335.245.208.72
                      May 24, 2023 00:58:16.418097973 CEST49704443192.168.2.3142.250.203.100
                      May 24, 2023 00:58:16.418140888 CEST44349704142.250.203.100192.168.2.3
                      May 24, 2023 00:58:16.556476116 CEST804970235.245.208.72192.168.2.3
                      May 24, 2023 00:59:03.635691881 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:03.635771990 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.635885000 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:03.636285067 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:03.636320114 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.692953110 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.696152925 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:03.696224928 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.696788073 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.702877998 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:03.703231096 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:03.773706913 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:13.727273941 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:13.727408886 CEST44349708142.250.203.100192.168.2.3
                      May 24, 2023 00:59:13.727597952 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:15.102001905 CEST49708443192.168.2.3142.250.203.100
                      May 24, 2023 00:59:15.102062941 CEST44349708142.250.203.100192.168.2.3
                      TimestampSource PortDest PortSource IPDest IP
                      May 24, 2023 00:57:59.667354107 CEST5692453192.168.2.38.8.8.8
                      May 24, 2023 00:57:59.667447090 CEST6062553192.168.2.38.8.8.8
                      May 24, 2023 00:57:59.695939064 CEST53569248.8.8.8192.168.2.3
                      May 24, 2023 00:57:59.695991993 CEST53606258.8.8.8192.168.2.3
                      May 24, 2023 00:58:01.530781031 CEST6058253192.168.2.38.8.8.8
                      May 24, 2023 00:58:01.559369087 CEST53605828.8.8.8192.168.2.3
                      May 24, 2023 00:58:03.548372030 CEST6205053192.168.2.38.8.8.8
                      May 24, 2023 00:58:03.572118044 CEST53620508.8.8.8192.168.2.3
                      May 24, 2023 00:59:03.608247995 CEST6482353192.168.2.38.8.8.8
                      May 24, 2023 00:59:03.631642103 CEST53648238.8.8.8192.168.2.3
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      May 24, 2023 00:57:59.667354107 CEST192.168.2.38.8.8.80x41ffStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                      May 24, 2023 00:57:59.667447090 CEST192.168.2.38.8.8.80xa5a5Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                      May 24, 2023 00:58:01.530781031 CEST192.168.2.38.8.8.80x2cd6Standard query (0)r1.visualwebsiteoptimizer.comA (IP address)IN (0x0001)false
                      May 24, 2023 00:58:03.548372030 CEST192.168.2.38.8.8.80x4d5dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      May 24, 2023 00:59:03.608247995 CEST192.168.2.38.8.8.80x75dbStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      May 24, 2023 00:57:59.695939064 CEST8.8.8.8192.168.2.30x41ffNo error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                      May 24, 2023 00:57:59.695991993 CEST8.8.8.8192.168.2.30xa5a5No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      May 24, 2023 00:57:59.695991993 CEST8.8.8.8192.168.2.30xa5a5No error (0)clients.l.google.com216.58.215.238A (IP address)IN (0x0001)false
                      May 24, 2023 00:58:01.559369087 CEST8.8.8.8192.168.2.30x2cd6No error (0)r1.visualwebsiteoptimizer.com35.245.208.72A (IP address)IN (0x0001)false
                      May 24, 2023 00:58:03.572118044 CEST8.8.8.8192.168.2.30x4d5dNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                      May 24, 2023 00:59:03.631642103 CEST8.8.8.8192.168.2.30x75dbNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                      • accounts.google.com
                      • clients2.google.com
                      • r1.visualwebsiteoptimizer.com
                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.349697172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.349699216.58.215.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      2192.168.2.34970235.245.208.7280C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      May 24, 2023 00:58:02.033539057 CEST538OUTGET /analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556 HTTP/1.1
                      Host: r1.visualwebsiteoptimizer.com
                      Connection: keep-alive
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      May 24, 2023 00:58:02.172070980 CEST539INHTTP/1.1 200 OK
                      Date: Tue, 23 May 2023 22:58:01 GMT
                      Content-Type: image/gif
                      Connection: keep-alive
                      Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
                      Expires: Mon, 10 Jan 2005 00:00:01 GMT
                      Pragma: no-cache
                      X-Content-Type-Options: nosniff
                      Content-Length: 35
                      Access-Control-Allow-Origin: *
                      server: r1
                      Data Raw: 47 49 46 38 39 61 01 00 01 00 80 ff 00 ff ff ff 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                      Data Ascii: GIF89a,D;
                      May 24, 2023 00:58:02.577907085 CEST539OUTGET /favicon.ico HTTP/1.1
                      Host: r1.visualwebsiteoptimizer.com
                      Connection: keep-alive
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      May 24, 2023 00:58:02.716409922 CEST539INHTTP/1.1 200 OK
                      Date: Tue, 23 May 2023 22:58:02 GMT
                      Content-Type: application/javascript; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: keep-alive
                      server: r1
                      Content-Encoding: gzip
                      Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a
                      Data Ascii: 140
                      May 24, 2023 00:58:03.176359892 CEST540OUTGET /analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556 HTTP/1.1
                      Host: r1.visualwebsiteoptimizer.com
                      Connection: keep-alive
                      Cache-Control: max-age=0
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      May 24, 2023 00:58:03.316593885 CEST541INHTTP/1.1 200 OK
                      Date: Tue, 23 May 2023 22:58:03 GMT
                      Content-Type: image/gif
                      Connection: keep-alive
                      Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
                      Expires: Mon, 10 Jan 2005 00:00:01 GMT
                      Pragma: no-cache
                      X-Content-Type-Options: nosniff
                      Content-Length: 35
                      Access-Control-Allow-Origin: *
                      server: r1
                      Data Raw: 47 49 46 38 39 61 01 00 01 00 80 ff 00 ff ff ff 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                      Data Ascii: GIF89a,D;
                      May 24, 2023 00:58:03.507859945 CEST541OUTGET /favicon.ico HTTP/1.1
                      Host: r1.visualwebsiteoptimizer.com
                      Connection: keep-alive
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Referer: http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      May 24, 2023 00:58:03.646275997 CEST547INHTTP/1.1 200 OK
                      Date: Tue, 23 May 2023 22:58:03 GMT
                      Content-Type: application/javascript; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: keep-alive
                      server: r1
                      Content-Encoding: gzip
                      Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a
                      Data Ascii: 140
                      May 24, 2023 00:58:03.671355963 CEST547OUTGET /favicon.ico HTTP/1.1
                      Host: r1.visualwebsiteoptimizer.com
                      Connection: keep-alive
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: */*
                      Accept-Encoding: gzip, deflate
                      Accept-Language: en-US,en;q=0.9
                      May 24, 2023 00:58:03.809782982 CEST548INHTTP/1.1 200 OK
                      Date: Tue, 23 May 2023 22:58:03 GMT
                      Content-Type: application/javascript; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: keep-alive
                      server: r1
                      Content-Encoding: gzip
                      Data Raw: 31 34 0d 0a 1f 8b 08 00 00 00 00 00 00 03 03 00 00 00 00 00 00 00 00 00 0d 0a 30 0d 0a 0d 0a
                      Data Ascii: 140


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.349697172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-05-23 22:58:00 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                      Host: accounts.google.com
                      Connection: keep-alive
                      Content-Length: 1
                      Origin: https://www.google.com
                      Content-Type: application/x-www-form-urlencoded
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
                      2023-05-23 22:58:00 UTC0OUTData Raw: 20
                      Data Ascii:
                      2023-05-23 22:58:00 UTC2INHTTP/1.1 200 OK
                      Content-Type: application/json; charset=utf-8
                      Access-Control-Allow-Origin: https://www.google.com
                      Access-Control-Allow-Credentials: true
                      X-Content-Type-Options: nosniff
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Tue, 23 May 2023 22:58:00 GMT
                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                      Content-Security-Policy: script-src 'report-sample' 'nonce-YAhBBCIMkYNoUBqAR_sjhA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                      Cross-Origin-Opener-Policy: same-origin
                      Server: ESF
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-05-23 22:58:00 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                      Data Ascii: 11["gaia.l.a.r",[]]
                      2023-05-23 22:58:00 UTC4INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.349699216.58.215.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-05-23 22:58:00 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                      Host: clients2.google.com
                      Connection: keep-alive
                      X-Goog-Update-Interactivity: fg
                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                      X-Goog-Update-Updater: chromecrx-104.0.5112.81
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-05-23 22:58:00 UTC1INHTTP/1.1 200 OK
                      Content-Security-Policy: script-src 'report-sample' 'nonce-B8YuK3lGu_owL4RQqYXJew' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Tue, 23 May 2023 22:58:00 GMT
                      Content-Type: text/xml; charset=UTF-8
                      X-Daynum: 5986
                      X-Daystart: 57480
                      X-Content-Type-Options: nosniff
                      X-Frame-Options: SAMEORIGIN
                      X-XSS-Protection: 1; mode=block
                      Server: GSE
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-05-23 22:58:00 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 38 36 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 37 34 38 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                      Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5986" elapsed_seconds="57480"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                      2023-05-23 22:58:00 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                      Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                      2023-05-23 22:58:00 UTC2INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      020406080s020406080100

                      Click to jump to process

                      020406080s0.0020406080100MB

                      Click to jump to process

                      Target ID:0
                      Start time:00:57:56
                      Start date:24/05/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      Target ID:1
                      Start time:00:57:57
                      Start date:24/05/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1732,i,16200984928723150921,8986171839187517471,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      Target ID:2
                      Start time:00:57:59
                      Start date:24/05/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://r1.visualwebsiteoptimizer.com/analyze?_a=609617&_u=https://www.nbcnews.com/news/us-news/fbi-sending-more-agents-louisville-kentucky-tackle-violent-crime-gangs-n1277556
                      Imagebase:0x7ff614650000
                      File size:2851656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      No disassembly