Edit tour

Windows Analysis Report
https://x.bidswitch.net

Overview

General Information

Sample URL:https://x.bidswitch.net
Analysis ID:898732
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6116 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 640 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1616,i,5423607378220563789,13624569778070016486,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6004 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://x.bidswitch.net MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://x.bidswitch.net/HTTP Parser: No favicon
Source: https://x.bidswitch.net/HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: x.bidswitch.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: x.bidswitch.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://x.bidswitch.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: x.bidswitch.netConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://x.bidswitch.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 03 Jul 2023 09:34:21 GMTContent-Length: 9Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 03 Jul 2023 09:34:21 GMTContent-Length: 9Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 03 Jul 2023 09:34:22 GMTContent-Length: 9Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
Source: classification engineClassification label: clean0.win@25/2@7/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1616,i,5423607378220563789,13624569778070016486,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://x.bidswitch.net
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1616,i,5423607378220563789,13624569778070016486,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 898732 URL: https://x.bidswitch.net Startdate: 03/07/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 clients.l.google.com 142.251.36.174, 443, 49707 GOOGLEUS United States 10->17 19 accounts.google.com 142.251.36.237, 443, 49708 GOOGLEUS United States 10->19 21 4 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://x.bidswitch.net1%VirustotalBrowse
https://x.bidswitch.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://x.bidswitch.net/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com
35.157.132.87
truefalse
    high
    accounts.google.com
    142.251.36.237
    truefalse
      high
      www.google.com
      172.217.16.164
      truefalse
        high
        clients.l.google.com
        142.251.36.174
        truefalse
          high
          x.bidswitch.net
          unknown
          unknownfalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://x.bidswitch.net/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                https://x.bidswitch.net/false
                  unknown
                  https://x.bidswitch.net/false
                    unknown
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      35.157.132.87
                      alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.comUnited States
                      16509AMAZON-02USfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      142.251.36.237
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      142.251.36.174
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      172.217.16.164
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.2.1
                      Joe Sandbox Version:37.1.0 Beryl
                      Analysis ID:898732
                      Start date and time:2023-07-03 11:33:14 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 6m 2s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:https://x.bidswitch.net
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:4
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean0.win@25/2@7/6
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      • Exclude process from analysis (whitelisted): WMIADAP.exe
                      • Excluded IPs from analysis (whitelisted): 172.217.16.163, 34.104.35.123
                      • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                      • Not all processes where analyzed, report is missing behavior information
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):9
                      Entropy (8bit):2.94770277922009
                      Encrypted:false
                      SSDEEP:3:Obn:Obn
                      MD5:9D1EAD73E678FA2F51A70A933B0BF017
                      SHA1:D205CBD6783332A212C5AE92D73C77178C2D2F28
                      SHA-256:0019DFC4B32D63C1392AA264AED2253C1E0C2FB09216F8E2CC269BBFB8BB49B5
                      SHA-512:935B3D516E996F6D25948BA8A54C1B7F70F7F0E3F517E36481FDF0196C2C5CFC2841F86E891F3DF9517746B7FB605DB47CDDED1B8FF78D9482DDAA621DB43A34
                      Malicious:false
                      Reputation:low
                      URL:https://x.bidswitch.net/favicon.ico
                      Preview:Not Found
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):9
                      Entropy (8bit):2.94770277922009
                      Encrypted:false
                      SSDEEP:3:Obn:Obn
                      MD5:9D1EAD73E678FA2F51A70A933B0BF017
                      SHA1:D205CBD6783332A212C5AE92D73C77178C2D2F28
                      SHA-256:0019DFC4B32D63C1392AA264AED2253C1E0C2FB09216F8E2CC269BBFB8BB49B5
                      SHA-512:935B3D516E996F6D25948BA8A54C1B7F70F7F0E3F517E36481FDF0196C2C5CFC2841F86E891F3DF9517746B7FB605DB47CDDED1B8FF78D9482DDAA621DB43A34
                      Malicious:false
                      Reputation:low
                      URL:https://x.bidswitch.net/
                      Preview:Not Found
                      No static file info

                      Download Network PCAP: filteredfull

                      • Total Packets: 83
                      • 443 (HTTPS)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      Jul 3, 2023 11:34:19.173289061 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.173373938 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.173470020 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.174380064 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.174449921 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.174534082 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.175069094 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.175121069 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.175389051 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.175436020 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.262526035 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.265137911 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.265166998 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.270874977 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.270994902 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.287880898 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.335020065 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.479446888 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.479480982 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.480554104 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.480679035 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.482053041 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.482137918 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.577213049 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.577397108 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.577893972 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.578078985 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.578608990 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.578634977 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.578785896 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.578825951 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.613325119 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.613410950 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.613441944 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.613529921 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.613583088 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.615468979 CEST49707443192.168.2.6142.251.36.174
                      Jul 3, 2023 11:34:19.615494013 CEST44349707142.251.36.174192.168.2.6
                      Jul 3, 2023 11:34:19.629071951 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.629210949 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.629235983 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.629292965 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:19.629343987 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.630285025 CEST49708443192.168.2.6142.251.36.237
                      Jul 3, 2023 11:34:19.630311012 CEST44349708142.251.36.237192.168.2.6
                      Jul 3, 2023 11:34:20.886372089 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.886437893 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.886570930 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.887499094 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.887530088 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.890620947 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.890666008 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.890754938 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.891261101 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.891289949 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.964734077 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.965204954 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.965250015 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.967350006 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.967442989 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.971050024 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.971487045 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:20.971513987 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.973643064 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:20.973716974 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.207297087 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.207628965 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.207647085 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.209759951 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.210002899 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.228878975 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.228965998 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.234654903 CEST49711443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.234709978 CEST4434971135.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.250808954 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.250840902 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.291883945 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.677089930 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.698203087 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.698324919 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:21.698395967 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.699975967 CEST49712443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:21.700011969 CEST4434971235.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.488023043 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.488090992 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.488173962 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.488403082 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.488439083 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.488507986 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.490593910 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.490612030 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.491175890 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.491202116 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.547353029 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.547422886 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.547938108 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.547965050 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.548343897 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.548367023 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.548732042 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.549138069 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.549659967 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.549819946 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.550177097 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.551736116 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.551949978 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.571221113 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.571284056 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.571368933 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.573349953 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.573379993 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.583774090 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.583898067 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.583996058 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.624207020 CEST49713443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.624255896 CEST4434971335.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.627470016 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.627938986 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.628002882 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.629508018 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.629642963 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.641993999 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.642395020 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.722954035 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:22.722989082 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:22.756293058 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:22.756441116 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:22.823033094 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:32.629228115 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:32.629312992 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:32.629470110 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:36.014009953 CEST49716443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:34:36.014053106 CEST44349716172.217.16.164192.168.2.6
                      Jul 3, 2023 11:34:36.548396111 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:36.548569918 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:34:36.548680067 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:38.454587936 CEST49714443192.168.2.635.157.132.87
                      Jul 3, 2023 11:34:38.454641104 CEST4434971435.157.132.87192.168.2.6
                      Jul 3, 2023 11:35:22.612535954 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:22.612603903 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.612704992 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:22.613421917 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:22.613455057 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.662919998 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.663460970 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:22.663489103 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.663958073 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.664539099 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:22.664643049 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:22.713906050 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:32.673996925 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:32.674113989 CEST44349719172.217.16.164192.168.2.6
                      Jul 3, 2023 11:35:32.674365997 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:34.426301003 CEST49719443192.168.2.6172.217.16.164
                      Jul 3, 2023 11:35:34.426335096 CEST44349719172.217.16.164192.168.2.6
                      TimestampSource PortDest PortSource IPDest IP
                      Jul 3, 2023 11:34:19.057285070 CEST5908253192.168.2.68.8.8.8
                      Jul 3, 2023 11:34:19.057796955 CEST5950453192.168.2.68.8.8.8
                      Jul 3, 2023 11:34:19.090471029 CEST53590828.8.8.8192.168.2.6
                      Jul 3, 2023 11:34:19.098956108 CEST53595048.8.8.8192.168.2.6
                      Jul 3, 2023 11:34:20.625799894 CEST6322953192.168.2.68.8.8.8
                      Jul 3, 2023 11:34:20.672956944 CEST53632298.8.8.8192.168.2.6
                      Jul 3, 2023 11:34:22.493494034 CEST5153053192.168.2.68.8.8.8
                      Jul 3, 2023 11:34:22.533875942 CEST53515308.8.8.8192.168.2.6
                      Jul 3, 2023 11:34:22.539205074 CEST5612253192.168.2.68.8.8.8
                      Jul 3, 2023 11:34:22.567070961 CEST53561228.8.8.8192.168.2.6
                      Jul 3, 2023 11:35:22.545908928 CEST5675053192.168.2.68.8.8.8
                      Jul 3, 2023 11:35:22.574570894 CEST53567508.8.8.8192.168.2.6
                      Jul 3, 2023 11:35:22.577924013 CEST5933653192.168.2.68.8.8.8
                      Jul 3, 2023 11:35:22.606704950 CEST53593368.8.8.8192.168.2.6
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Jul 3, 2023 11:34:19.057285070 CEST192.168.2.68.8.8.80xd10bStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:19.057796955 CEST192.168.2.68.8.8.80xa7dStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.625799894 CEST192.168.2.68.8.8.80x824cStandard query (0)x.bidswitch.netA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:22.493494034 CEST192.168.2.68.8.8.80x4ac4Standard query (0)www.google.comA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:22.539205074 CEST192.168.2.68.8.8.80x1a0eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:35:22.545908928 CEST192.168.2.68.8.8.80x2abeStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      Jul 3, 2023 11:35:22.577924013 CEST192.168.2.68.8.8.80x63ccStandard query (0)www.google.comA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jul 3, 2023 11:34:19.090471029 CEST8.8.8.8192.168.2.60xd10bNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                      Jul 3, 2023 11:34:19.090471029 CEST8.8.8.8192.168.2.60xd10bNo error (0)clients.l.google.com142.251.36.174A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:19.098956108 CEST8.8.8.8192.168.2.60xa7dNo error (0)accounts.google.com142.251.36.237A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)x.bidswitch.netalb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com35.157.132.87A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com18.194.138.81A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com3.68.181.55A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com35.156.133.126A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com35.156.96.37A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com18.196.95.248A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com35.158.250.162A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:20.672956944 CEST8.8.8.8192.168.2.60x824cNo error (0)alb-aws-fr-bruges-1875226813.eu-central-1.elb.amazonaws.com3.65.208.176A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:22.533875942 CEST8.8.8.8192.168.2.60x4ac4No error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:34:22.567070961 CEST8.8.8.8192.168.2.60x1a0eNo error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:35:22.574570894 CEST8.8.8.8192.168.2.60x2abeNo error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                      Jul 3, 2023 11:35:22.606704950 CEST8.8.8.8192.168.2.60x63ccNo error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                      • accounts.google.com
                      • clients2.google.com
                      • x.bidswitch.net
                      • https:
                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      0192.168.2.649708142.251.36.237443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-07-03 09:34:19 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                      Host: accounts.google.com
                      Connection: keep-alive
                      Content-Length: 1
                      Origin: https://www.google.com
                      Content-Type: application/x-www-form-urlencoded
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
                      2023-07-03 09:34:19 UTC0OUTData Raw: 20
                      Data Ascii:
                      2023-07-03 09:34:19 UTC2INHTTP/1.1 200 OK
                      Content-Type: application/json; charset=utf-8
                      Access-Control-Allow-Origin: https://www.google.com
                      Access-Control-Allow-Credentials: true
                      X-Content-Type-Options: nosniff
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Mon, 03 Jul 2023 09:34:19 GMT
                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                      Content-Security-Policy: script-src 'report-sample' 'nonce-hzt19b_XYE1xKbIa5RweWQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                      Cross-Origin-Opener-Policy: same-origin
                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                      Server: ESF
                      X-XSS-Protection: 0
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-07-03 09:34:19 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                      Data Ascii: 11["gaia.l.a.r",[]]
                      2023-07-03 09:34:19 UTC4INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      1192.168.2.649707142.251.36.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-07-03 09:34:19 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                      Host: clients2.google.com
                      Connection: keep-alive
                      X-Goog-Update-Interactivity: fg
                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                      X-Goog-Update-Updater: chromecrx-104.0.5112.81
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: empty
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-07-03 09:34:19 UTC1INHTTP/1.1 200 OK
                      Content-Security-Policy: script-src 'report-sample' 'nonce-KOmIIzu6PBXcjKOBrHMeUw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                      Pragma: no-cache
                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                      Date: Mon, 03 Jul 2023 09:34:19 GMT
                      Content-Type: text/xml; charset=UTF-8
                      X-Daynum: 6027
                      X-Daystart: 9259
                      X-Content-Type-Options: nosniff
                      X-Frame-Options: SAMEORIGIN
                      X-XSS-Protection: 1; mode=block
                      Server: GSE
                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                      Accept-Ranges: none
                      Vary: Accept-Encoding
                      Connection: close
                      Transfer-Encoding: chunked
                      2023-07-03 09:34:19 UTC2INData Raw: 32 63 38 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 32 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 39 32 35 39 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22 20
                      Data Ascii: 2c8<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6027" elapsed_seconds="9259"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                      2023-07-03 09:34:19 UTC2INData Raw: 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                      Data Ascii: 3f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                      2023-07-03 09:34:19 UTC2INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      2192.168.2.64971135.157.132.87443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-07-03 09:34:21 UTC4OUTGET / HTTP/1.1
                      Host: x.bidswitch.net
                      Connection: keep-alive
                      sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Sec-Fetch-Site: none
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-User: ?1
                      Sec-Fetch-Dest: document
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-07-03 09:34:21 UTC5INHTTP/1.1 404 Not Found
                      Date: Mon, 03 Jul 2023 09:34:21 GMT
                      Content-Length: 9
                      Connection: close
                      2023-07-03 09:34:21 UTC5INData Raw: 4e 6f 74 20 46 6f 75 6e 64
                      Data Ascii: Not Found


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      3192.168.2.64971235.157.132.87443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-07-03 09:34:21 UTC5OUTGET /favicon.ico HTTP/1.1
                      Host: x.bidswitch.net
                      Connection: keep-alive
                      sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                      sec-ch-ua-mobile: ?0
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      sec-ch-ua-platform: "Windows"
                      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: no-cors
                      Sec-Fetch-Dest: image
                      Referer: https://x.bidswitch.net/
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-07-03 09:34:21 UTC5INHTTP/1.1 404 Not Found
                      Date: Mon, 03 Jul 2023 09:34:21 GMT
                      Content-Length: 9
                      Connection: close
                      2023-07-03 09:34:21 UTC5INData Raw: 4e 6f 74 20 46 6f 75 6e 64
                      Data Ascii: Not Found


                      Session IDSource IPSource PortDestination IPDestination PortProcess
                      4192.168.2.64971335.157.132.87443C:\Program Files\Google\Chrome\Application\chrome.exe
                      TimestampkBytes transferredDirectionData
                      2023-07-03 09:34:22 UTC5OUTGET / HTTP/1.1
                      Host: x.bidswitch.net
                      Connection: keep-alive
                      Cache-Control: max-age=0
                      sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                      sec-ch-ua-mobile: ?0
                      sec-ch-ua-platform: "Windows"
                      Upgrade-Insecure-Requests: 1
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                      Sec-Fetch-Site: same-origin
                      Sec-Fetch-Mode: navigate
                      Sec-Fetch-Dest: document
                      Referer: https://x.bidswitch.net/
                      Accept-Encoding: gzip, deflate, br
                      Accept-Language: en-US,en;q=0.9
                      2023-07-03 09:34:22 UTC6INHTTP/1.1 404 Not Found
                      Date: Mon, 03 Jul 2023 09:34:22 GMT
                      Content-Length: 9
                      Connection: close
                      2023-07-03 09:34:22 UTC6INData Raw: 4e 6f 74 20 46 6f 75 6e 64
                      Data Ascii: Not Found


                      020406080s020406080100

                      Click to jump to process

                      020406080s0.0020406080100MB

                      Click to jump to process

                      Target ID:0
                      Start time:11:34:15
                      Start date:03/07/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                      Imagebase:0x7ff6f9750000
                      File size:2'851'656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      Target ID:1
                      Start time:11:34:16
                      Start date:03/07/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1616,i,5423607378220563789,13624569778070016486,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                      Imagebase:0x7ff6f9750000
                      File size:2'851'656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low

                      Target ID:2
                      Start time:11:34:20
                      Start date:03/07/2023
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://x.bidswitch.net
                      Imagebase:0x7ff6f9750000
                      File size:2'851'656 bytes
                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      No disassembly