Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://updateadobeflash.website

Overview

General Information

Sample URL:http://updateadobeflash.website
Analysis ID:880595
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Antivirus detection for URL or domain

Classification

  • System is w10x64
  • chrome.exe (PID: 1348 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1636,i,18041631581025959698,2646021752260512293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5944 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://updateadobeflash.website MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://updateadobeflash.websiteAvira URL Cloud: detection malicious, Label: malware
Source: http://updateadobeflash.websiteVirustotal: Detection: 17%Perma Link
Source: https://updateadobeflash.website/favicon.icoAvira URL Cloud: Label: malware
Source: http://updateadobeflash.website/Avira URL Cloud: Label: malware
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: updateadobeflash.websiteConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: updateadobeflash.websiteConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://updateadobeflash.website/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: updateadobeflash.websiteConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Fri, 02 Jun 2023 12:56:14 GMTContent-Type: text/html; charset=UTF-8Content-Length: 13Connection: closeCache-Control: no-cache, no-store, must-revalidateExpires: 0Pragma: no-cacheVary: Accept-Encoding
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Fri, 02 Jun 2023 12:56:15 GMTContent-Type: text/htmlContent-Length: 548Connection: close
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: classification engineClassification label: mal64.win@26/1@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1636,i,18041631581025959698,2646021752260512293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://updateadobeflash.website
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1636,i,18041631581025959698,2646021752260512293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://updateadobeflash.website100%Avira URL Cloudmalware
http://updateadobeflash.website18%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://updateadobeflash.website/favicon.ico100%Avira URL Cloudmalware
http://updateadobeflash.website/100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    updateadobeflash.website
    178.159.37.95
    truefalse
      unknown
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://updateadobeflash.website/true
              • Avira URL Cloud: malware
              unknown
              https://updateadobeflash.website/favicon.icofalse
              • Avira URL Cloud: malware
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                https://updateadobeflash.website/false
                  unknown
                  https://updateadobeflash.website/false
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.250.203.100
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    142.250.203.110
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    178.159.37.95
                    updateadobeflash.websiteRussian Federation
                    206791SBY-TELECOM-ASUAfalse
                    142.250.203.109
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.1
                    Joe Sandbox Version:37.1.0 Beryl
                    Analysis ID:880595
                    Start date and time:2023-06-02 14:55:20 +02:00
                    Joe Sandbox Product:CloudBasic
                    Overall analysis duration:0h 4m 1s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://updateadobeflash.website
                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                    Number of analysed new started processes analysed:5
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • HDC enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal64.win@26/1@6/6
                    EGA Information:Failed
                    HDC Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): audiodg.exe, WMIADAP.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
                    • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                    • Not all processes where analyzed, report is missing behavior information
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):548
                    Entropy (8bit):4.688532577858027
                    Encrypted:false
                    SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                    MD5:370E16C3B7DBA286CFF055F93B9A94D8
                    SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                    SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                    SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                    Malicious:false
                    Reputation:low
                    URL:https://updateadobeflash.website/favicon.ico
                    Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Jun 2, 2023 14:56:12.956671953 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:12.956738949 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:12.956837893 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:12.957297087 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:12.957350016 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:12.957454920 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:12.958035946 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:12.958074093 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:12.958302021 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:12.958328009 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.114486933 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.114631891 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.157443047 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.157443047 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.174007893 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.174050093 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.174129963 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.174160957 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.174978971 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.175062895 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.176529884 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.176609993 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.177836895 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.177947998 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.369865894 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.370105028 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.370176077 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.370318890 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.370323896 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.370336056 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.370395899 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.370410919 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.403908014 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.403980970 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.404006004 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.404033899 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.404081106 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.405225992 CEST49692443192.168.2.4142.250.203.110
                    Jun 2, 2023 14:56:13.405251026 CEST44349692142.250.203.110192.168.2.4
                    Jun 2, 2023 14:56:13.412808895 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.419990063 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.420277119 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:13.420372009 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.421691895 CEST49693443192.168.2.4142.250.203.109
                    Jun 2, 2023 14:56:13.421720028 CEST44349693142.250.203.109192.168.2.4
                    Jun 2, 2023 14:56:14.095792055 CEST4969680192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.096519947 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.158574104 CEST8049696178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.158804893 CEST4969680192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.159315109 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.159404993 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.204835892 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.267595053 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.278424978 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.328157902 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.602838039 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.602925062 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.603069067 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.606117964 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.606152058 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.805356026 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.806842089 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.806885004 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.808072090 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.808178902 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.868191957 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.868393898 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.868413925 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.868758917 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.914202929 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:14.914249897 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.951719046 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:14.951915026 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.297610044 CEST49698443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.297662973 CEST44349698178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.637496948 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.637545109 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.637653112 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.638144016 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.638159037 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.767309904 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.767781019 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.767812014 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.768235922 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.768703938 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.768788099 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.768866062 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.812308073 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.931541920 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.931638956 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:15.931693077 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.933144093 CEST49699443192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:15.933166981 CEST44349699178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:16.765295982 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.765383959 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.765496969 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.765830994 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.765860081 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.820031881 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.823704958 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.823743105 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.825062037 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.825138092 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.827327967 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.827433109 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:16.913794994 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:16.913840055 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:17.023154974 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:26.804579973 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:26.804666042 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:26.804840088 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:29.602272987 CEST49701443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:56:29.602324009 CEST44349701142.250.203.100192.168.2.4
                    Jun 2, 2023 14:56:59.164685965 CEST4969680192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:59.227684021 CEST8049696178.159.37.95192.168.2.4
                    Jun 2, 2023 14:56:59.289588928 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:56:59.352407932 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:14.222655058 CEST8049696178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:14.223022938 CEST4969680192.168.2.4178.159.37.95
                    Jun 2, 2023 14:57:14.771373987 CEST4969680192.168.2.4178.159.37.95
                    Jun 2, 2023 14:57:14.834244967 CEST8049696178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:16.726773024 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:16.726861000 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.727087975 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:16.727441072 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:16.727483034 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.786109924 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.786971092 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:16.787029982 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.788081884 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.788862944 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:16.789016008 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:16.834161997 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:20.022268057 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:20.022308111 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:20.022331953 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:20.022527933 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:57:20.022527933 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:57:20.701265097 CEST4969780192.168.2.4178.159.37.95
                    Jun 2, 2023 14:57:20.766254902 CEST8049697178.159.37.95192.168.2.4
                    Jun 2, 2023 14:57:26.769026041 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:26.769170046 CEST44349707142.250.203.100192.168.2.4
                    Jun 2, 2023 14:57:26.769254923 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:28.699920893 CEST49707443192.168.2.4142.250.203.100
                    Jun 2, 2023 14:57:28.699990988 CEST44349707142.250.203.100192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Jun 2, 2023 14:56:12.926834106 CEST6416753192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:12.927309990 CEST5856553192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:12.947062969 CEST53641678.8.8.8192.168.2.4
                    Jun 2, 2023 14:56:12.947334051 CEST53585658.8.8.8192.168.2.4
                    Jun 2, 2023 14:56:14.040409088 CEST6068653192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:14.081527948 CEST53606868.8.8.8192.168.2.4
                    Jun 2, 2023 14:56:14.453020096 CEST5944453192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:14.473297119 CEST53594448.8.8.8192.168.2.4
                    Jun 2, 2023 14:56:16.663954020 CEST5944653192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:16.696286917 CEST53594468.8.8.8192.168.2.4
                    Jun 2, 2023 14:56:16.727150917 CEST5086153192.168.2.48.8.8.8
                    Jun 2, 2023 14:56:16.761189938 CEST53508618.8.8.8192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Jun 2, 2023 14:56:12.926834106 CEST192.168.2.48.8.8.80xd795Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:12.927309990 CEST192.168.2.48.8.8.80x2dc2Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:14.040409088 CEST192.168.2.48.8.8.80xf26dStandard query (0)updateadobeflash.websiteA (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:14.453020096 CEST192.168.2.48.8.8.80x39feStandard query (0)updateadobeflash.websiteA (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:16.663954020 CEST192.168.2.48.8.8.80xf336Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:16.727150917 CEST192.168.2.48.8.8.80xba03Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Jun 2, 2023 14:56:12.947062969 CEST8.8.8.8192.168.2.40xd795No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Jun 2, 2023 14:56:12.947062969 CEST8.8.8.8192.168.2.40xd795No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:12.947334051 CEST8.8.8.8192.168.2.40x2dc2No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:14.081527948 CEST8.8.8.8192.168.2.40xf26dNo error (0)updateadobeflash.website178.159.37.95A (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:14.473297119 CEST8.8.8.8192.168.2.40x39feNo error (0)updateadobeflash.website178.159.37.95A (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:16.696286917 CEST8.8.8.8192.168.2.40xf336No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                    Jun 2, 2023 14:56:16.761189938 CEST8.8.8.8192.168.2.40xba03No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                    • accounts.google.com
                    • clients2.google.com
                    • updateadobeflash.website
                    • https:
                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.2.449693142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.2.449692142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    2192.168.2.449698178.159.37.95443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    3192.168.2.449699178.159.37.95443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    4192.168.2.449697178.159.37.9580C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    Jun 2, 2023 14:56:14.204835892 CEST362OUTGET / HTTP/1.1
                    Host: updateadobeflash.website
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                    Jun 2, 2023 14:56:14.278424978 CEST362INHTTP/1.1 301 Moved Permanently
                    Server: nginx
                    Date: Fri, 02 Jun 2023 12:56:14 GMT
                    Content-Type: text/html; charset=UTF-8
                    Content-Length: 0
                    Connection: keep-alive
                    Cache-Control: no-cache, no-store, must-revalidate
                    Expires: 0
                    Location: https://updateadobeflash.website/
                    Pragma: no-cache
                    Vary: Accept-Encoding
                    Access-Control-Allow-Origin: *
                    Jun 2, 2023 14:56:59.289588928 CEST413OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    5192.168.2.449696178.159.37.9580C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    Jun 2, 2023 14:56:59.164685965 CEST413OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.2.449693142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-06-02 12:56:13 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                    2023-06-02 12:56:13 UTC0OUTData Raw: 20
                    Data Ascii:
                    2023-06-02 12:56:13 UTC2INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Fri, 02 Jun 2023 12:56:13 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Content-Security-Policy: script-src 'report-sample' 'nonce-f5Qqg2ifnQrxdQF8XC_mfQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Cross-Origin-Opener-Policy: same-origin
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-06-02 12:56:13 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2023-06-02 12:56:13 UTC4INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.2.449692142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-06-02 12:56:13 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-104.0.5112.81
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                    2023-06-02 12:56:13 UTC1INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-FEAdYqWfMbWdDOsLS3S-9g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Fri, 02 Jun 2023 12:56:13 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 5996
                    X-Daystart: 21373
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2023-06-02 12:56:13 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 39 36 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 31 33 37 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5996" elapsed_seconds="21373"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2023-06-02 12:56:13 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2023-06-02 12:56:13 UTC2INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    2192.168.2.449698178.159.37.95443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-06-02 12:56:14 UTC4OUTGET / HTTP/1.1
                    Host: updateadobeflash.website
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                    2023-06-02 12:56:14 UTC4INHTTP/1.1 404 Not Found
                    Server: nginx
                    Date: Fri, 02 Jun 2023 12:56:14 GMT
                    Content-Type: text/html; charset=UTF-8
                    Content-Length: 13
                    Connection: close
                    Cache-Control: no-cache, no-store, must-revalidate
                    Expires: 0
                    Pragma: no-cache
                    Vary: Accept-Encoding
                    2023-06-02 12:56:14 UTC5INData Raw: 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64
                    Data Ascii: 404 Not Found


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    3192.168.2.449699178.159.37.95443C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampkBytes transferredDirectionData
                    2023-06-02 12:56:15 UTC5OUTGET /favicon.ico HTTP/1.1
                    Host: updateadobeflash.website
                    Connection: keep-alive
                    sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://updateadobeflash.website/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
                    2023-06-02 12:56:15 UTC5INHTTP/1.1 404 Not Found
                    Server: nginx
                    Date: Fri, 02 Jun 2023 12:56:15 GMT
                    Content-Type: text/html
                    Content-Length: 548
                    Connection: close
                    2023-06-02 12:56:15 UTC5INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                    Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:14:56:09
                    Start date:02/06/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff683680000
                    File size:2851656 bytes
                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low

                    Target ID:1
                    Start time:14:56:10
                    Start date:02/06/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1636,i,18041631581025959698,2646021752260512293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff683680000
                    File size:2851656 bytes
                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low

                    Target ID:2
                    Start time:14:56:12
                    Start date:02/06/2023
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://updateadobeflash.website
                    Imagebase:0x7ff683680000
                    File size:2851656 bytes
                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low

                    No disassembly