Edit tour

Windows Analysis Report
http://checkip.dyndns.org/

Overview

General Information

Sample URL:http://checkip.dyndns.org/
Analysis ID:881264
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5896 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 6076 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,15488895745892127565,16048142722933977914,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6420 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://checkip.dyndns.org/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://checkip.dyndns.org/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://checkip.dyndns.org/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://checkip.dyndns.org/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: checkip.dyndns.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
Source: classification engineClassification label: clean0.win@24/3@5/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,15488895745892127565,16048142722933977914,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://checkip.dyndns.org/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,15488895745892127565,16048142722933977914,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 881264 URL: http://checkip.dyndns.org/ Startdate: 03/06/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 checkip.dyndns.com 132.226.8.169, 49701, 49702, 80 UTMEMUS United States 10->17 19 www.google.com 142.250.203.100, 443, 49706, 49709 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://checkip.dyndns.org/0%URL Reputationsafe
http://checkip.dyndns.org/0%URL Reputationsafe
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
checkip.dyndns.org0%VirustotalBrowse
checkip.dyndns.com0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://checkip.dyndns.org/favicon.ico0%VirustotalBrowse
http://checkip.dyndns.org/favicon.ico0%Avira URL Cloudsafe
http://checkip.dyndns.org/0%VirustotalBrowse

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    www.google.com
    142.250.203.100
    truefalse
      high
      clients.l.google.com
      142.250.203.110
      truefalse
        high
        checkip.dyndns.com
        132.226.8.169
        truefalseunknown
        clients2.google.com
        unknown
        unknownfalse
          high
          checkip.dyndns.org
          unknown
          unknownfalseunknown
          NameMaliciousAntivirus DetectionReputation
          http://checkip.dyndns.org/falseunknown
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            http://checkip.dyndns.org/falseunknown
            http://checkip.dyndns.org/favicon.icofalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              132.226.8.169
              checkip.dyndns.comUnited States
              16989UTMEMUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.203.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              142.250.203.110
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              142.250.203.109
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              Joe Sandbox Version:37.1.0 Beryl
              Analysis ID:881264
              Start date and time:2023-06-03 22:30:00 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 4m 7s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://checkip.dyndns.org/
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:5
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@24/3@5/6
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
              • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):106
              Entropy (8bit):4.797700087260106
              Encrypted:false
              SSDEEP:3:qVZxgROCQ+y8RRCXbZ6SXOy0Wt+gRFK3G:qzxU4+b3CX96kOPo+gRFmG
              MD5:8216E69A47FFC4A22DBFBBA15BF8E6A8
              SHA1:C21C6E3345D683DCE51C9725A625482F13C0277E
              SHA-256:28AA4492A5F44B0C5EA5D4FE22E93B0D1DFAAC88A1DBDFF97CC0D958A1DD2470
              SHA-512:A31DCD391C642E1C487BBD8948F4760B081A5D0C474516261F5032CBFF0F6421E744AD9569815E51699ED2CB4A2F555646D0670A89E2E04ECCF2F3FBD73D1E30
              Malicious:false
              Reputation:low
              Preview:<html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>..
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):106
              Entropy (8bit):4.797700087260106
              Encrypted:false
              SSDEEP:3:qVZxgROCQ+y8RRCXbZ6SXOy0Wt+gRFK3G:qzxU4+b3CX96kOPo+gRFmG
              MD5:8216E69A47FFC4A22DBFBBA15BF8E6A8
              SHA1:C21C6E3345D683DCE51C9725A625482F13C0277E
              SHA-256:28AA4492A5F44B0C5EA5D4FE22E93B0D1DFAAC88A1DBDFF97CC0D958A1DD2470
              SHA-512:A31DCD391C642E1C487BBD8948F4760B081A5D0C474516261F5032CBFF0F6421E744AD9569815E51699ED2CB4A2F555646D0670A89E2E04ECCF2F3FBD73D1E30
              Malicious:false
              Reputation:low
              URL:http://checkip.dyndns.org/
              Preview:<html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>..
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):106
              Entropy (8bit):4.797700087260106
              Encrypted:false
              SSDEEP:3:qVZxgROCQ+y8RRCXbZ6SXOy0Wt+gRFK3G:qzxU4+b3CX96kOPo+gRFmG
              MD5:8216E69A47FFC4A22DBFBBA15BF8E6A8
              SHA1:C21C6E3345D683DCE51C9725A625482F13C0277E
              SHA-256:28AA4492A5F44B0C5EA5D4FE22E93B0D1DFAAC88A1DBDFF97CC0D958A1DD2470
              SHA-512:A31DCD391C642E1C487BBD8948F4760B081A5D0C474516261F5032CBFF0F6421E744AD9569815E51699ED2CB4A2F555646D0670A89E2E04ECCF2F3FBD73D1E30
              Malicious:false
              Reputation:low
              URL:http://checkip.dyndns.org/favicon.ico
              Preview:<html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>..
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 65
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Jun 3, 2023 22:30:53.523269892 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.523344994 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.523436069 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.524005890 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.524043083 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.527024031 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.527106047 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.527216911 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.527527094 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.527570009 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.591871023 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.592351913 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.592405081 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.593164921 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.593271017 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.594671965 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.594774008 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.621730089 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.622049093 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.622093916 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.623959064 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.624089003 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.857752085 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.858077049 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.858099937 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.858232975 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.858525038 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.858665943 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.858688116 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.859472990 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.895627975 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.895719051 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.895764112 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.895982027 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.896054029 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.896761894 CEST49697443192.168.2.3142.250.203.110
              Jun 3, 2023 22:30:53.896795034 CEST44349697142.250.203.110192.168.2.3
              Jun 3, 2023 22:30:53.899133921 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.899179935 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.914489031 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.914599895 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.914642096 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.914674997 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:53.914783001 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.915702105 CEST49698443192.168.2.3142.250.203.109
              Jun 3, 2023 22:30:53.915751934 CEST44349698142.250.203.109192.168.2.3
              Jun 3, 2023 22:30:54.626039028 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:54.626975060 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:54.907033920 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:54.907198906 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:54.908449888 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:54.908607006 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:54.981848955 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:55.262830019 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:55.263355970 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:55.371046066 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:55.816777945 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.098098040 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:56.125200987 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.135762930 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.406008005 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:56.406457901 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:56.417226076 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:56.470633030 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.555402994 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.555738926 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:56.836450100 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:56.850471973 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:57.131532907 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:30:57.273683071 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.273763895 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.273890018 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.274113894 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.274137020 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.282891035 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:30:57.339492083 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.340295076 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.340329885 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.341640949 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.341753006 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.345046043 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.345171928 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.454837084 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:30:57.454884052 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:30:57.564186096 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:07.336971045 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:07.337166071 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:07.337271929 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:08.985075951 CEST49706443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:08.985127926 CEST44349706142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:41.411210060 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:31:41.692151070 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:31:42.149766922 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:31:42.430283070 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:31:57.332938910 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:57.333014965 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.333153963 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:57.333512068 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:57.333549023 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.388931036 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.389595032 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:57.389626026 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.390556097 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.391614914 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:31:57.391840935 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:31:57.433187008 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:32:01.406002998 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:32:01.406162024 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:32:02.071129084 CEST4970280192.168.2.3132.226.8.169
              Jun 3, 2023 22:32:02.131270885 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:32:02.131422997 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:32:02.351860046 CEST8049702132.226.8.169192.168.2.3
              Jun 3, 2023 22:32:04.068669081 CEST4970180192.168.2.3132.226.8.169
              Jun 3, 2023 22:32:04.348893881 CEST8049701132.226.8.169192.168.2.3
              Jun 3, 2023 22:32:07.467269897 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:32:07.467360973 CEST44349709142.250.203.100192.168.2.3
              Jun 3, 2023 22:32:07.467433929 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:32:08.056365013 CEST49709443192.168.2.3142.250.203.100
              Jun 3, 2023 22:32:08.056406021 CEST44349709142.250.203.100192.168.2.3
              TimestampSource PortDest PortSource IPDest IP
              Jun 3, 2023 22:30:53.481220961 CEST6062553192.168.2.38.8.8.8
              Jun 3, 2023 22:30:53.482160091 CEST4930253192.168.2.38.8.8.8
              Jun 3, 2023 22:30:53.515140057 CEST53493028.8.8.8192.168.2.3
              Jun 3, 2023 22:30:53.521821022 CEST53606258.8.8.8192.168.2.3
              Jun 3, 2023 22:30:54.602063894 CEST5295553192.168.2.38.8.8.8
              Jun 3, 2023 22:30:54.620937109 CEST53529558.8.8.8192.168.2.3
              Jun 3, 2023 22:30:57.240780115 CEST6205053192.168.2.38.8.8.8
              Jun 3, 2023 22:30:57.255590916 CEST53620508.8.8.8192.168.2.3
              Jun 3, 2023 22:31:57.310326099 CEST5811953192.168.2.38.8.8.8
              Jun 3, 2023 22:31:57.330629110 CEST53581198.8.8.8192.168.2.3
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jun 3, 2023 22:30:53.481220961 CEST192.168.2.38.8.8.80xbd3eStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:53.482160091 CEST192.168.2.38.8.8.80xbf0eStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.602063894 CEST192.168.2.38.8.8.80x4eefStandard query (0)checkip.dyndns.orgA (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:57.240780115 CEST192.168.2.38.8.8.80x5c63Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Jun 3, 2023 22:31:57.310326099 CEST192.168.2.38.8.8.80x3f55Standard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jun 3, 2023 22:30:53.515140057 CEST8.8.8.8192.168.2.30xbf0eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Jun 3, 2023 22:30:53.515140057 CEST8.8.8.8192.168.2.30xbf0eNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:53.521821022 CEST8.8.8.8192.168.2.30xbd3eNo error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.orgcheckip.dyndns.comCNAME (Canonical name)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.com132.226.8.169A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.com193.122.130.0A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.com193.122.6.168A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.com132.226.247.73A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:54.620937109 CEST8.8.8.8192.168.2.30x4eefNo error (0)checkip.dyndns.com158.101.44.242A (IP address)IN (0x0001)false
              Jun 3, 2023 22:30:57.255590916 CEST8.8.8.8192.168.2.30x5c63No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
              Jun 3, 2023 22:31:57.330629110 CEST8.8.8.8192.168.2.30x3f55No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
              • clients2.google.com
              • accounts.google.com
              • checkip.dyndns.org
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349697142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349698142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              2192.168.2.349701132.226.8.16980C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              Jun 3, 2023 22:30:54.981848955 CEST543OUTGET / HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:55.263355970 CEST544INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:55 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:30:55.816777945 CEST544OUTGET /favicon.ico HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://checkip.dyndns.org/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:56.098098040 CEST544INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:55 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:30:56.135762930 CEST545OUTGET /favicon.ico HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: */*
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:56.417226076 CEST546INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:56 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:30:56.555402994 CEST546OUTGET /favicon.ico HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://checkip.dyndns.org/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:56.836450100 CEST547INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:56 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:30:56.850471973 CEST547OUTGET /favicon.ico HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: */*
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:57.131532907 CEST547INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:56 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:31:42.149766922 CEST554OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortProcess
              3192.168.2.349702132.226.8.16980C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              Jun 3, 2023 22:30:56.125200987 CEST545OUTGET / HTTP/1.1
              Host: checkip.dyndns.org
              Connection: keep-alive
              Cache-Control: max-age=0
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Referer: http://checkip.dyndns.org/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Jun 3, 2023 22:30:56.406457901 CEST546INHTTP/1.1 200 OK
              Date: Sat, 03 Jun 2023 20:30:56 GMT
              Content-Type: text/html
              Content-Length: 106
              Connection: keep-alive
              Cache-Control: no-cache
              Pragma: no-cache
              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 30 32 2e 31 32 39 2e 31 34 33 2e 34 33 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 102.129.143.43</body></html>
              Jun 3, 2023 22:31:41.411210060 CEST554OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.349697142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-06-03 20:30:53 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-06-03 20:30:53 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-inUH4FKwr34M0dT9-6OIeg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Sat, 03 Jun 2023 20:30:53 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5997
              X-Daystart: 48653
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-06-03 20:30:53 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 39 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 38 36 35 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5997" elapsed_seconds="48653"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-06-03 20:30:53 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-06-03 20:30:53 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.349698142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-06-03 20:30:53 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: CONSENT=PENDING+904; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg
              2023-06-03 20:30:53 UTC1OUTData Raw: 20
              Data Ascii:
              2023-06-03 20:30:53 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Sat, 03 Jun 2023 20:30:53 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Cross-Origin-Opener-Policy: same-origin
              Content-Security-Policy: script-src 'report-sample' 'nonce-y_vdNbDaU2SGedfX4a2wuQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-06-03 20:30:53 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-06-03 20:30:53 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              Target ID:0
              Start time:22:30:51
              Start date:03/06/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:1
              Start time:22:30:52
              Start date:03/06/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,15488895745892127565,16048142722933977914,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:22:30:54
              Start date:03/06/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://checkip.dyndns.org/
              Imagebase:0x7ff614650000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly