Edit tour

Windows Analysis Report
http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/

Overview

General Information

Sample URL:http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
Analysis ID:875377
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5528 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5632 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1744,i,7218008699742444428,5306249040074539145,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6244 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@24/3@5/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1744,i,7218008699742444428,5306249040074539145,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1744,i,7218008699742444428,5306249040074539145,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 875377 URL: http://96di2d2p5oueba3r2ka3... Startdate: 25/05/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 www.google.com 142.250.203.100, 443, 49730, 49734 GOOGLEUS United States 10->17 19 accounts.google.com 142.250.203.109, 443, 49722 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/2%VirustotalBrowse
http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
t-9999.fdv2-t-msedge.net
13.107.237.254
truefalse
    unknown
    accounts.google.com
    142.250.203.109
    truefalse
      high
      k-9999.k-msedge.net
      13.107.18.254
      truefalse
        unknown
        PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com
        54.77.139.23
        truefalse
          high
          www.google.com
          142.250.203.100
          truefalse
            high
            clients.l.google.com
            216.58.215.238
            truefalse
              high
              clients2.google.com
              unknown
              unknownfalse
                high
                96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com
                unknown
                unknownfalse
                  unknown
                  NameMaliciousAntivirus DetectionReputation
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/favicon.icofalse
                      • Avira URL Cloud: safe
                      unknown
                      http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/false
                        unknown
                        http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/false
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          54.77.139.23
                          PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comUnited States
                          16509AMAZON-02USfalse
                          239.255.255.250
                          unknownReserved
                          unknownunknownfalse
                          216.58.215.238
                          clients.l.google.comUnited States
                          15169GOOGLEUSfalse
                          142.250.203.100
                          www.google.comUnited States
                          15169GOOGLEUSfalse
                          142.250.203.109
                          accounts.google.comUnited States
                          15169GOOGLEUSfalse
                          IP
                          192.168.2.1
                          Joe Sandbox Version:37.1.0 Beryl
                          Analysis ID:875377
                          Start date and time:2023-05-25 13:13:25 +02:00
                          Joe Sandbox Product:CloudBasic
                          Overall analysis duration:0h 5m 43s
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:browseurl.jbs
                          Sample URL:http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                          Number of analysed new started processes analysed:6
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • HDC enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Detection:CLEAN
                          Classification:clean0.win@24/3@5/6
                          EGA Information:Failed
                          HDC Information:Failed
                          HCA Information:
                          • Successful, ratio: 100%
                          • Number of executed functions: 0
                          • Number of non-executed functions: 0
                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe
                          • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123, 172.217.168.3
                          • Excluded domains from analysis (whitelisted): l-ring.msedge.net, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, t-ring-fdv2.msedge.net, clientservices.googleapis.com, k-ring.msedge.net
                          • Not all processes where analyzed, report is missing behavior information
                          No simulations
                          No context
                          No context
                          No context
                          No context
                          No context
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:HTML document, ASCII text, with no line terminators
                          Category:downloaded
                          Size (bytes):55
                          Entropy (8bit):4.49900834965228
                          Encrypted:false
                          SSDEEP:3:qVZqRKiRUrHZyMcZcKa:qzADCTZyMou
                          MD5:6AF92FAB1AD91C158BD1F99E3A8F996B
                          SHA1:AF427C1735C3748AC59D3A7FE67251D7D3225544
                          SHA-256:85747A417436C72879DD0BD7CBA9C1A97048B3CA3FD63C55E1EDD54CB5133C16
                          SHA-512:245E5BB887D37FD1D1065CDCF6E2F8BC61D4313D8689ABFB1F49948C5AFD35D4907994CD70A76C5125AFCE81623874C00EC1528A0D360E28A771332ACF9752C4
                          Malicious:false
                          Reputation:low
                          URL:http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
                          Preview:<html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:HTML document, ASCII text, with no line terminators
                          Category:dropped
                          Size (bytes):55
                          Entropy (8bit):4.49900834965228
                          Encrypted:false
                          SSDEEP:3:qVZqRKiRUrHZyMcZcKa:qzADCTZyMou
                          MD5:6AF92FAB1AD91C158BD1F99E3A8F996B
                          SHA1:AF427C1735C3748AC59D3A7FE67251D7D3225544
                          SHA-256:85747A417436C72879DD0BD7CBA9C1A97048B3CA3FD63C55E1EDD54CB5133C16
                          SHA-512:245E5BB887D37FD1D1065CDCF6E2F8BC61D4313D8689ABFB1F49948C5AFD35D4907994CD70A76C5125AFCE81623874C00EC1528A0D360E28A771332ACF9752C4
                          Malicious:false
                          Reputation:low
                          Preview:<html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:HTML document, ASCII text, with no line terminators
                          Category:downloaded
                          Size (bytes):84
                          Entropy (8bit):4.510899565429859
                          Encrypted:false
                          SSDEEP:3:qVZqRKiRUrHZyMcUKFrHZyMcZcKa:qzADCTZyMMTZyMou
                          MD5:D5AB8E324325A3AD1CD0B594D5B8E839
                          SHA1:D6946235253125A7916AA14D044EC2F14BA40AB1
                          SHA-256:8CCAD01C94D212ED852AFD80B27224D04D62B47B71726999A11991222D8B7618
                          SHA-512:0F35BCC5D74ACC5B2CC4ACFE37282087C0FBB651D90FBD079680297C7881B17B1A9ABB3F965CAF4DA8A6AAD7572125CFFF561DE40722FF0BB3324D1BF4286DC4
                          Malicious:false
                          Reputation:low
                          URL:http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/favicon.ico
                          Preview:<html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>
                          No static file info

                          Download Network PCAP: filteredfull

                          • Total Packets: 60
                          • 443 (HTTPS)
                          • 80 (HTTP)
                          • 53 (DNS)
                          TimestampSource PortDest PortSource IPDest IP
                          May 25, 2023 13:14:27.895004988 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:27.895080090 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:27.895194054 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:27.895998001 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.896049976 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.896115065 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.896502972 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:27.896544933 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:27.897044897 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.897066116 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.961822987 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.963963032 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.963999033 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.964572906 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.964648008 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.965459108 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:27.965519905 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:27.981420040 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:27.990566969 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:27.990634918 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:27.992983103 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:27.993087053 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.265266895 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.265674114 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.265676975 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.265934944 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:28.266160011 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:28.266185045 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:28.266218901 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:28.300569057 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:28.300683022 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:28.300729990 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:28.300755978 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:28.300828934 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:28.312293053 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.314623117 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.314671040 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.318960905 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.319031954 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.319058895 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.319242001 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.319314003 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.364280939 CEST49722443192.168.2.5142.250.203.109
                          May 25, 2023 13:14:28.364325047 CEST44349722142.250.203.109192.168.2.5
                          May 25, 2023 13:14:28.365010023 CEST49724443192.168.2.5216.58.215.238
                          May 25, 2023 13:14:28.365042925 CEST44349724216.58.215.238192.168.2.5
                          May 25, 2023 13:14:30.194005966 CEST4972680192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.194823027 CEST4972780192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.241257906 CEST804972654.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.241316080 CEST804972754.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.241354942 CEST4972680192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.241497993 CEST4972780192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.242022991 CEST4972780192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.287221909 CEST804972754.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.287300110 CEST804972754.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.287323952 CEST804972754.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.287463903 CEST4972780192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.312385082 CEST4972780192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.357840061 CEST804972754.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.462739944 CEST4972680192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.509196043 CEST804972654.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.509239912 CEST804972654.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.509260893 CEST804972654.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.509355068 CEST4972680192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.510898113 CEST4972680192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.518587112 CEST4972980192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.557168961 CEST804972654.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.563246965 CEST804972954.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.563416004 CEST4972980192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.563987970 CEST4972980192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.607460976 CEST804972954.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.607516050 CEST804972954.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.607557058 CEST804972954.77.139.23192.168.2.5
                          May 25, 2023 13:14:30.607650995 CEST4972980192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.613513947 CEST4972980192.168.2.554.77.139.23
                          May 25, 2023 13:14:30.657064915 CEST804972954.77.139.23192.168.2.5
                          May 25, 2023 13:14:31.470725060 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.470788002 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.470851898 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.471256971 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.471273899 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.527390957 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.528871059 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.528892994 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.530249119 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.530431032 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.533185959 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.533339977 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.704396009 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:31.704422951 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:31.813993931 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:41.504343033 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:41.504457951 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:14:41.504666090 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:44.216526985 CEST49730443192.168.2.5142.250.203.100
                          May 25, 2023 13:14:44.216559887 CEST44349730142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.548584938 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:31.548645973 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.548727036 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:31.550090075 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:31.550129890 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.601200104 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.601696014 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:31.601726055 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.602710962 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.603468895 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:31.603740931 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:31.644474983 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:41.631675959 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:41.631795883 CEST44349734142.250.203.100192.168.2.5
                          May 25, 2023 13:15:41.647078991 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:43.534704924 CEST49734443192.168.2.5142.250.203.100
                          May 25, 2023 13:15:43.534768105 CEST44349734142.250.203.100192.168.2.5
                          TimestampSource PortDest PortSource IPDest IP
                          May 25, 2023 13:14:27.826630116 CEST5148453192.168.2.58.8.8.8
                          May 25, 2023 13:14:27.827585936 CEST6344653192.168.2.58.8.8.8
                          May 25, 2023 13:14:27.846530914 CEST53514848.8.8.8192.168.2.5
                          May 25, 2023 13:14:27.855504990 CEST53634468.8.8.8192.168.2.5
                          May 25, 2023 13:14:30.091880083 CEST5506853192.168.2.58.8.8.8
                          May 25, 2023 13:14:30.160716057 CEST53550688.8.8.8192.168.2.5
                          May 25, 2023 13:14:31.453761101 CEST5853253192.168.2.58.8.8.8
                          May 25, 2023 13:14:31.468574047 CEST53585328.8.8.8192.168.2.5
                          May 25, 2023 13:15:31.523710012 CEST4995953192.168.2.58.8.8.8
                          May 25, 2023 13:15:31.546705008 CEST53499598.8.8.8192.168.2.5
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          May 25, 2023 13:14:27.826630116 CEST192.168.2.58.8.8.80x6558Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                          May 25, 2023 13:14:27.827585936 CEST192.168.2.58.8.8.80xc505Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                          May 25, 2023 13:14:30.091880083 CEST192.168.2.58.8.8.80xae07Standard query (0)96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.comA (IP address)IN (0x0001)false
                          May 25, 2023 13:14:31.453761101 CEST192.168.2.58.8.8.80x4a8fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                          May 25, 2023 13:15:31.523710012 CEST192.168.2.58.8.8.80x963eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          May 25, 2023 13:14:19.990155935 CEST8.8.8.8192.168.2.50xff66No error (0)t-ring.t-9999.fdv2-t-msedge.nett-9999.fdv2-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          May 25, 2023 13:14:19.990155935 CEST8.8.8.8192.168.2.50xff66No error (0)t-9999.fdv2-t-msedge.net13.107.237.254A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:20.271960974 CEST8.8.8.8192.168.2.50xeeeaNo error (0)k-ring.k-9999.k-msedge.netk-9999.k-msedge.netCNAME (Canonical name)IN (0x0001)false
                          May 25, 2023 13:14:20.271960974 CEST8.8.8.8192.168.2.50xeeeaNo error (0)k-9999.k-msedge.net13.107.18.254A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:27.846530914 CEST8.8.8.8192.168.2.50x6558No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                          May 25, 2023 13:14:27.846530914 CEST8.8.8.8192.168.2.50x6558No error (0)clients.l.google.com216.58.215.238A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:27.855504990 CEST8.8.8.8192.168.2.50xc505No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:30.160716057 CEST8.8.8.8192.168.2.50xae07No error (0)96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.comPublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                          May 25, 2023 13:14:30.160716057 CEST8.8.8.8192.168.2.50xae07No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com54.77.139.23A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:30.160716057 CEST8.8.8.8192.168.2.50xae07No error (0)PublicInteractionNLB-3bddf5ff6abb91b6.elb.eu-west-1.amazonaws.com3.248.33.252A (IP address)IN (0x0001)false
                          May 25, 2023 13:14:31.468574047 CEST8.8.8.8192.168.2.50x4a8fNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                          May 25, 2023 13:15:31.546705008 CEST8.8.8.8192.168.2.50x963eNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                          • accounts.google.com
                          • clients2.google.com
                          • 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com
                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          0192.168.2.549722142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          1192.168.2.549724216.58.215.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          2192.168.2.54972754.77.139.2380C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          May 25, 2023 13:14:30.242022991 CEST481OUTGET / HTTP/1.1
                          Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com
                          Connection: keep-alive
                          Upgrade-Insecure-Requests: 1
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                          Accept-Encoding: gzip, deflate
                          Accept-Language: en-US,en;q=0.9
                          May 25, 2023 13:14:30.287300110 CEST481INHTTP/1.1 200 OK
                          Server: Burp Collaborator https://burpcollaborator.net/
                          X-Collaborator-Version: 4
                          Content-Type: text/html
                          Content-Length: 55
                          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 31 6f 6e 73 34 76 72 7a 69 39 6f 6b 39 72 6c 30 62 39 63 6b 64 6b 7a 6a 6a 67 69 67 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                          Data Ascii: <html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          3192.168.2.54972654.77.139.2380C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          May 25, 2023 13:14:30.462739944 CEST482OUTGET /favicon.ico HTTP/1.1
                          Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com
                          Connection: keep-alive
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                          Referer: http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
                          Accept-Encoding: gzip, deflate
                          Accept-Language: en-US,en;q=0.9
                          May 25, 2023 13:14:30.509239912 CEST482INHTTP/1.1 200 OK
                          Server: Burp Collaborator https://burpcollaborator.net/
                          X-Collaborator-Version: 4
                          Content-Type: text/html
                          Content-Length: 84
                          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 31 6f 6e 73 34 76 72 7a 69 39 6f 6b 39 72 6c 30 62 39 63 6b 64 6b 7a 6a 6a 67 69 67 7a 31 6f 6e 73 34 76 72 7a 69 39 6f 6b 39 72 6c 30 62 39 63 6b 64 6b 7a 6a 6a 67 69 67 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                          Data Ascii: <html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          4192.168.2.54972954.77.139.2380C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          May 25, 2023 13:14:30.563987970 CEST483OUTGET /favicon.ico HTTP/1.1
                          Host: 96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com
                          Connection: keep-alive
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept: */*
                          Accept-Encoding: gzip, deflate
                          Accept-Language: en-US,en;q=0.9
                          May 25, 2023 13:14:30.607516050 CEST483INHTTP/1.1 200 OK
                          Server: Burp Collaborator https://burpcollaborator.net/
                          X-Collaborator-Version: 4
                          Content-Type: text/html
                          Content-Length: 55
                          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 31 6f 6e 73 34 76 72 7a 69 39 6f 6b 39 72 6c 30 62 39 63 6b 64 6b 7a 6a 6a 67 69 67 7a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                          Data Ascii: <html><body>1ons4vrzi9ok9rl0b9ckdkzjjgigz</body></html>


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          0192.168.2.549722142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2023-05-25 11:14:28 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                          Host: accounts.google.com
                          Connection: keep-alive
                          Content-Length: 1
                          Origin: https://www.google.com
                          Content-Type: application/x-www-form-urlencoded
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: no-cors
                          Sec-Fetch-Dest: empty
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2023-05-25 11:14:28 UTC0OUTData Raw: 20
                          Data Ascii:
                          2023-05-25 11:14:28 UTC2INHTTP/1.1 200 OK
                          Content-Type: application/json; charset=utf-8
                          Access-Control-Allow-Origin: https://www.google.com
                          Access-Control-Allow-Credentials: true
                          X-Content-Type-Options: nosniff
                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                          Pragma: no-cache
                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                          Date: Thu, 25 May 2023 11:14:28 GMT
                          Strict-Transport-Security: max-age=31536000; includeSubDomains
                          Cross-Origin-Opener-Policy: same-origin
                          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                          Content-Security-Policy: script-src 'report-sample' 'nonce-GyV-NJDwnFF-jT4KNcoI9w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                          Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                          Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                          Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                          Server: ESF
                          X-XSS-Protection: 0
                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                          Accept-Ranges: none
                          Vary: Accept-Encoding
                          Connection: close
                          Transfer-Encoding: chunked
                          2023-05-25 11:14:28 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                          Data Ascii: 11["gaia.l.a.r",[]]
                          2023-05-25 11:14:28 UTC4INData Raw: 30 0d 0a 0d 0a
                          Data Ascii: 0


                          Session IDSource IPSource PortDestination IPDestination PortProcess
                          1192.168.2.549724216.58.215.238443C:\Program Files\Google\Chrome\Application\chrome.exe
                          TimestampkBytes transferredDirectionData
                          2023-05-25 11:14:28 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                          Host: clients2.google.com
                          Connection: keep-alive
                          X-Goog-Update-Interactivity: fg
                          X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                          X-Goog-Update-Updater: chromecrx-104.0.5112.81
                          Sec-Fetch-Site: none
                          Sec-Fetch-Mode: no-cors
                          Sec-Fetch-Dest: empty
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                          Accept-Encoding: gzip, deflate, br
                          Accept-Language: en-US,en;q=0.9
                          2023-05-25 11:14:28 UTC1INHTTP/1.1 200 OK
                          Content-Security-Policy: script-src 'report-sample' 'nonce-I8Gr5QRHn_JHQYsKEzF_Sw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                          Pragma: no-cache
                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                          Date: Thu, 25 May 2023 11:14:28 GMT
                          Content-Type: text/xml; charset=UTF-8
                          X-Daynum: 5988
                          X-Daystart: 15268
                          X-Content-Type-Options: nosniff
                          X-Frame-Options: SAMEORIGIN
                          X-XSS-Protection: 1; mode=block
                          Server: GSE
                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                          Accept-Ranges: none
                          Vary: Accept-Encoding
                          Connection: close
                          Transfer-Encoding: chunked
                          2023-05-25 11:14:28 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 38 38 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 35 32 36 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                          Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5988" elapsed_seconds="15268"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                          2023-05-25 11:14:28 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                          Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                          2023-05-25 11:14:28 UTC2INData Raw: 30 0d 0a 0d 0a
                          Data Ascii: 0


                          020406080s020406080100

                          Click to jump to process

                          020406080s0.0020406080100MB

                          Click to jump to process

                          Target ID:0
                          Start time:13:14:24
                          Start date:25/05/2023
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                          Imagebase:0x7ff7d31b0000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:1
                          Start time:13:14:25
                          Start date:25/05/2023
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1744,i,7218008699742444428,5306249040074539145,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                          Imagebase:0x7ff7d31b0000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:2
                          Start time:13:14:29
                          Start date:25/05/2023
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://96di2d2p5oueba3r2ka3rnj8bzhq5gt5.oastify.com/
                          Imagebase:0x7ff7d31b0000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low
                          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                          There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                          No disassembly