Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://vidanalytics.taboola.com

Overview

General Information

Sample URL:https://vidanalytics.taboola.com
Analysis ID:1523177
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2212,i,15547285882173545694,11219266375267795134,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vidanalytics.taboola.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://vidanalytics.taboola.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: vidanalytics.taboola.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: vidanalytics.taboola.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://vidanalytics.taboola.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: vidanalytics.taboola.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2212,i,15547285882173545694,11219266375267795134,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vidanalytics.taboola.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2212,i,15547285882173545694,11219266375267795134,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://vidanalytics.taboola.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
tls13.taboola.map.fastly.net0%VirustotalBrowse
vidanalytics.taboola.com0%VirustotalBrowse
www.google.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
tls13.taboola.map.fastly.net
151.101.129.44
truefalseunknown
www.google.com
142.250.185.132
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
vidanalytics.taboola.com
unknown
unknownfalseunknown
NameMaliciousAntivirus DetectionReputation
https://vidanalytics.taboola.com/favicon.icofalse
    unknown
    https://vidanalytics.taboola.com/false
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      151.101.129.44
      tls13.taboola.map.fastly.netUnited States
      54113FASTLYUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.185.132
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1523177
      Start date and time:2024-10-01 08:30:25 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 4s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://vidanalytics.taboola.com
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:9
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@16/4@4/4
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 216.58.212.131, 142.250.186.78, 64.233.184.84, 34.104.35.123, 20.114.59.183, 93.184.221.240, 52.165.164.15, 192.229.221.95, 13.95.31.18, 142.250.186.131
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      InputOutput
      URL: https://vidanalytics.taboola.com/ Model: jbxai
      {
      "brand":[],
      "contains_trigger_text":false,
      "trigger_text":"",
      "prominent_button_name":"unknown",
      "text_input_field_labels":"unknown",
      "pdf_icon_visible":false,
      "has_visible_captcha":false,
      "has_urgent_text":false,
      "has_visible_qrcode":false}
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):552
      Entropy (8bit):4.703264786773916
      Encrypted:false
      SSDEEP:12:TvEBnoVI9BnzlI5r8INGlTF5TF5TF5TF5TF5TFK:YBnoUBnRDTPTPTPTPTPTc
      MD5:141CD0F7B679FA9218B79290D1E0E973
      SHA1:A7AAB25238CB1141A8E19B792901A9B77126EEAB
      SHA-256:E2FA6B937E801E1D2B00BD533D84AB378E209074A49533D4696A3AEF8D20666B
      SHA-512:9E22788D8C8ED8C473C9A2512A392DD53CA059FD2586D76248CE85492FD8A8154C7B662B53404182C927191AEF0EB110794CDAB665FF71D001FDA04980FDEAA4
      Malicious:false
      Reputation:low
      URL:https://vidanalytics.taboola.com/
      Preview:<html>..<head><title>400 Bad Request</title></head>..<body>..<center><h1>400 Bad Request</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):552
      Entropy (8bit):4.703264786773916
      Encrypted:false
      SSDEEP:12:TvEBnoVI9BnzlI5r8INGlTF5TF5TF5TF5TF5TFK:YBnoUBnRDTPTPTPTPTPTc
      MD5:141CD0F7B679FA9218B79290D1E0E973
      SHA1:A7AAB25238CB1141A8E19B792901A9B77126EEAB
      SHA-256:E2FA6B937E801E1D2B00BD533D84AB378E209074A49533D4696A3AEF8D20666B
      SHA-512:9E22788D8C8ED8C473C9A2512A392DD53CA059FD2586D76248CE85492FD8A8154C7B662B53404182C927191AEF0EB110794CDAB665FF71D001FDA04980FDEAA4
      Malicious:false
      Reputation:low
      URL:https://vidanalytics.taboola.com/favicon.ico
      Preview:<html>..<head><title>400 Bad Request</title></head>..<body>..<center><h1>400 Bad Request</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Oct 1, 2024 08:31:12.084997892 CEST49675443192.168.2.4173.222.162.32
      Oct 1, 2024 08:31:21.802628994 CEST49675443192.168.2.4173.222.162.32
      Oct 1, 2024 08:31:22.634841919 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.634886026 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:22.634958029 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.634996891 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.635036945 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:22.635093927 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.635194063 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.635205984 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:22.635396004 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:22.635411024 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.093178034 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.093595982 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.093622923 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.094609022 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.094683886 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.095762014 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.095825911 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.096064091 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.096072912 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.109643936 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.109867096 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.109913111 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.110918999 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.110994101 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.111321926 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.111397028 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.142172098 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.272507906 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.272541046 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.320684910 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.327949047 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.328052998 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.328119993 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.329046965 CEST49736443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.329070091 CEST44349736151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.386332989 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.431405067 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.628582954 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.628820896 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:23.628978968 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.629405022 CEST49735443192.168.2.4151.101.129.44
      Oct 1, 2024 08:31:23.629421949 CEST44349735151.101.129.44192.168.2.4
      Oct 1, 2024 08:31:24.583868027 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:24.583969116 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:24.584053993 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:24.584280968 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:24.584314108 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.215770006 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.237133026 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:25.237168074 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.238145113 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.238217115 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:25.241488934 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:25.241553068 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.286542892 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:25.286565065 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:25.333426952 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:26.445229053 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:26.445254087 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:26.445405960 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:26.450098038 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:26.450109005 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.097040892 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.097135067 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.100976944 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.100985050 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.101186037 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.145944118 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.162064075 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.207403898 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.375519037 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.375566959 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.375806093 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.379251003 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.379266024 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.379302025 CEST49740443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.379308939 CEST44349740184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.544476986 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.544521093 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:27.544625044 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.545336008 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:27.545351028 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.179392099 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.179630995 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.180807114 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.180818081 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.181076050 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.182145119 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.227411032 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.455499887 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.455563068 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.455899954 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.456291914 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.456291914 CEST49741443192.168.2.4184.28.90.27
      Oct 1, 2024 08:31:28.456311941 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:28.456319094 CEST44349741184.28.90.27192.168.2.4
      Oct 1, 2024 08:31:35.121068954 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:35.121133089 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:35.121220112 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:35.902143955 CEST49739443192.168.2.4142.250.185.132
      Oct 1, 2024 08:31:35.902192116 CEST44349739142.250.185.132192.168.2.4
      Oct 1, 2024 08:31:39.085827112 CEST4972380192.168.2.4199.232.214.172
      Oct 1, 2024 08:31:39.091084003 CEST8049723199.232.214.172192.168.2.4
      Oct 1, 2024 08:31:39.091171980 CEST4972380192.168.2.4199.232.214.172
      Oct 1, 2024 08:32:24.627326965 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:24.627372026 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:24.627450943 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:24.627737045 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:24.627757072 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:25.274725914 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:25.275021076 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:25.275032997 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:25.275408983 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:25.275749922 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:25.275810957 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:25.318592072 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:27.240590096 CEST4972480192.168.2.4199.232.214.172
      Oct 1, 2024 08:32:27.545202017 CEST8049724199.232.214.172192.168.2.4
      Oct 1, 2024 08:32:27.545367002 CEST4972480192.168.2.4199.232.214.172
      Oct 1, 2024 08:32:36.117501974 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:36.117589951 CEST44349750142.250.185.132192.168.2.4
      Oct 1, 2024 08:32:36.117729902 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:37.743372917 CEST49750443192.168.2.4142.250.185.132
      Oct 1, 2024 08:32:37.743405104 CEST44349750142.250.185.132192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Oct 1, 2024 08:31:21.050945044 CEST53585471.1.1.1192.168.2.4
      Oct 1, 2024 08:31:21.051707983 CEST53582271.1.1.1192.168.2.4
      Oct 1, 2024 08:31:22.139981031 CEST53511861.1.1.1192.168.2.4
      Oct 1, 2024 08:31:22.623709917 CEST5400153192.168.2.41.1.1.1
      Oct 1, 2024 08:31:22.624335051 CEST5953653192.168.2.41.1.1.1
      Oct 1, 2024 08:31:22.630745888 CEST53540011.1.1.1192.168.2.4
      Oct 1, 2024 08:31:22.631225109 CEST53595361.1.1.1192.168.2.4
      Oct 1, 2024 08:31:24.575896978 CEST5780653192.168.2.41.1.1.1
      Oct 1, 2024 08:31:24.576204062 CEST5085853192.168.2.41.1.1.1
      Oct 1, 2024 08:31:24.582637072 CEST53578061.1.1.1192.168.2.4
      Oct 1, 2024 08:31:24.582705021 CEST53508581.1.1.1192.168.2.4
      Oct 1, 2024 08:31:38.746777058 CEST138138192.168.2.4192.168.2.255
      Oct 1, 2024 08:31:39.217571020 CEST53630601.1.1.1192.168.2.4
      Oct 1, 2024 08:31:58.318932056 CEST53635551.1.1.1192.168.2.4
      Oct 1, 2024 08:32:20.249763012 CEST53609591.1.1.1192.168.2.4
      Oct 1, 2024 08:32:20.952577114 CEST53533861.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Oct 1, 2024 08:31:22.623709917 CEST192.168.2.41.1.1.10x9885Standard query (0)vidanalytics.taboola.comA (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:22.624335051 CEST192.168.2.41.1.1.10x7e95Standard query (0)vidanalytics.taboola.com65IN (0x0001)false
      Oct 1, 2024 08:31:24.575896978 CEST192.168.2.41.1.1.10xd8bdStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:24.576204062 CEST192.168.2.41.1.1.10x4868Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Oct 1, 2024 08:31:22.630745888 CEST1.1.1.1192.168.2.40x9885No error (0)vidanalytics.taboola.comtls13.taboola.map.fastly.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:31:22.630745888 CEST1.1.1.1192.168.2.40x9885No error (0)tls13.taboola.map.fastly.net151.101.129.44A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:22.630745888 CEST1.1.1.1192.168.2.40x9885No error (0)tls13.taboola.map.fastly.net151.101.65.44A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:22.630745888 CEST1.1.1.1192.168.2.40x9885No error (0)tls13.taboola.map.fastly.net151.101.1.44A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:22.630745888 CEST1.1.1.1192.168.2.40x9885No error (0)tls13.taboola.map.fastly.net151.101.193.44A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:22.631225109 CEST1.1.1.1192.168.2.40x7e95No error (0)vidanalytics.taboola.comtls13.taboola.map.fastly.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:31:24.582637072 CEST1.1.1.1192.168.2.40xd8bdNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:24.582705021 CEST1.1.1.1192.168.2.40x4868No error (0)www.google.com65IN (0x0001)false
      Oct 1, 2024 08:31:38.094635010 CEST1.1.1.1192.168.2.40x70e8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:31:38.094635010 CEST1.1.1.1192.168.2.40x70e8No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Oct 1, 2024 08:31:54.326086044 CEST1.1.1.1192.168.2.40xd72aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:31:54.326086044 CEST1.1.1.1192.168.2.40xd72aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Oct 1, 2024 08:32:13.453450918 CEST1.1.1.1192.168.2.40x9cf7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:32:13.453450918 CEST1.1.1.1192.168.2.40x9cf7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Oct 1, 2024 08:32:33.358122110 CEST1.1.1.1192.168.2.40x8d6cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 08:32:33.358122110 CEST1.1.1.1192.168.2.40x8d6cNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      • vidanalytics.taboola.com
      • https:
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449736151.101.129.444436016C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-10-01 06:31:23 UTC667OUTGET / HTTP/1.1
      Host: vidanalytics.taboola.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-10-01 06:31:23 UTC358INHTTP/1.1 400 Bad Request
      Connection: close
      Content-Length: 552
      Server: nginx
      Content-Type: text/html
      X-backend-name: 5i41NEgLZrTBnTzubPzIMu--F_NLB_VIDEO_UI_00102
      Accept-Ranges: bytes
      Date: Tue, 01 Oct 2024 06:31:23 GMT
      Via: 1.1 varnish
      X-Served-By: cache-nyc-kteb1890022-NYC
      X-Cache: MISS
      X-Cache-Hits: 0
      X-Timer: S1727764283.150429,VS0,VE138
      2024-10-01 06:31:23 UTC552INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72
      Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chr


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449735151.101.129.444436016C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-10-01 06:31:23 UTC604OUTGET /favicon.ico HTTP/1.1
      Host: vidanalytics.taboola.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://vidanalytics.taboola.com/
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-10-01 06:31:23 UTC358INHTTP/1.1 400 Bad Request
      Connection: close
      Content-Length: 552
      Server: nginx
      Content-Type: text/html
      X-backend-name: 5i41NEgLZrTBnTzubPzIMu--F_NLB_VIDEO_UI_00101
      Accept-Ranges: bytes
      Date: Tue, 01 Oct 2024 06:31:23 GMT
      Via: 1.1 varnish
      X-Served-By: cache-nyc-kteb1890087-NYC
      X-Cache: MISS
      X-Cache-Hits: 0
      X-Timer: S1727764283.446027,VS0,VE138
      2024-10-01 06:31:23 UTC552INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72
      Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chr


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.449740184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-10-01 06:31:27 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-10-01 06:31:27 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-neu-z1
      Cache-Control: public, max-age=209663
      Date: Tue, 01 Oct 2024 06:31:27 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.449741184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-10-01 06:31:28 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-10-01 06:31:28 UTC515INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=209606
      Date: Tue, 01 Oct 2024 06:31:28 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-10-01 06:31:28 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:02:31:16
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:1
      Start time:02:31:18
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2212,i,15547285882173545694,11219266375267795134,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:02:31:21
      Start date:01/10/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vidanalytics.taboola.com"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly