Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip

Overview

General Information

Sample URL:https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsd
Analysis ID:1284400
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w7x64
  • chrome.exe (PID: 2728 cmdline: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 6ACAE527E744C80997B25EF2A0485D5E)
    • chrome.exe (PID: 1280 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=984,3082125091231155652,1986206945202247580,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1336 /prefetch:8 MD5: 6ACAE527E744C80997B25EF2A0485D5E)
  • chrome.exe (PID: 264 cmdline: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip MD5: 6ACAE527E744C80997B25EF2A0485D5E)
    • chrome.exe (PID: 3076 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1072,1244314507077814543,10674633888874670333,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1264 /prefetch:8 MD5: 6ACAE527E744C80997B25EF2A0485D5E)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-84.0.4147.135Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49183 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49182 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49183
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49182
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=WP.289365
Source: classification engineClassification label: clean0.win@31/0@2/4
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=984,3082125091231155652,1986206945202247580,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1336 /prefetch:8
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1072,1244314507077814543,10674633888874670333,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1264 /prefetch:8
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=984,3082125091231155652,1986206945202247580,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1336 /prefetch:8Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1072,1244314507077814543,10674633888874670333,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1264 /prefetch:8Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1284400 URL: https://www.google.com/trav... Startdate: 02/08/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        13 chrome.exe 8->13         started        process4 dnsIp5 17 accounts.google.com 142.250.203.109, 443, 49182 GOOGLEUS United States 10->17 19 clients.l.google.com 142.250.203.110, 443, 49183 GOOGLEUS United States 10->19 21 2 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.203.109
truefalse
    high
    clients.l.google.com
    142.250.203.110
    truefalse
      high
      clients2.google.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
          high
          https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.203.110
            clients.l.google.comUnited States
            15169GOOGLEUSfalse
            142.250.203.109
            accounts.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.255
            Joe Sandbox Version:38.0.0 Beryl
            Analysis ID:1284400
            Start date and time:2023-08-02 14:24:24 +02:00
            Joe Sandbox Product:CloudBasic
            Overall analysis duration:0h 3m 49s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip
            Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
            Number of analysed new started processes analysed:4
            Number of new started drivers analysed:2
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • HDC enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@31/0@2/4
            EGA Information:Failed
            HDC Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): vga.dll
            • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
            • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com, www.gstatic.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Aug 2, 2023 14:25:19.639597893 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:19.639652014 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:19.639741898 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:19.640074015 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.640100002 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.640177965 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.642697096 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:19.642728090 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:19.642990112 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.643017054 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.799166918 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.799387932 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:19.800693035 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.800739050 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.801091909 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:19.801112890 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:19.801217079 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.801302910 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.802772045 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:19.802850962 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:19.802875996 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:19.802933931 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.096251011 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:20.096673965 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.097724915 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:20.097767115 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.114757061 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.115102053 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:20.115901947 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.115967989 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:20.131613016 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.131742954 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:20.131764889 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.131994963 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.132066965 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:20.132997036 CEST49183443192.168.2.22142.250.203.110
            Aug 2, 2023 14:25:20.133043051 CEST44349183142.250.203.110192.168.2.22
            Aug 2, 2023 14:25:20.185425043 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:20.185528994 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.185574055 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:20.185851097 CEST44349182142.250.203.109192.168.2.22
            Aug 2, 2023 14:25:20.185929060 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.196221113 CEST49182443192.168.2.22142.250.203.109
            Aug 2, 2023 14:25:20.196247101 CEST44349182142.250.203.109192.168.2.22
            TimestampSource PortDest PortSource IPDest IP
            Aug 2, 2023 14:25:17.000565052 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:17.040488005 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:17.075448036 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:17.750559092 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:17.790572882 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:17.825582027 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.501291037 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.541479111 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.588202953 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.871352911 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.887295961 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:18.887415886 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:19.579910040 CEST5316053192.168.2.228.8.8.8
            Aug 2, 2023 14:25:19.582402945 CEST6494853192.168.2.228.8.8.8
            Aug 2, 2023 14:25:19.613794088 CEST53531608.8.8.8192.168.2.22
            Aug 2, 2023 14:25:19.623590946 CEST53649488.8.8.8192.168.2.22
            Aug 2, 2023 14:25:19.633316994 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:19.648824930 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:19.648894072 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:20.384120941 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:20.399749041 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:20.399749041 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:23.775346994 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:23.987097979 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:24.139302969 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:24.533127069 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:24.751528978 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:24.891978025 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:25.297597885 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:25.516001940 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:25.656431913 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:27.889827967 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:27.891740084 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:27.910032988 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:28.651909113 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:28.654283047 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:28.667479992 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:29.414180994 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:29.416429996 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:25:29.429825068 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:00.171969891 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:00.932411909 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:01.683247089 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:16.588846922 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:17.334549904 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:18.093794107 CEST137137192.168.2.22192.168.2.255
            Aug 2, 2023 14:26:37.367703915 CEST138138192.168.2.22192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Aug 2, 2023 14:25:19.579910040 CEST192.168.2.228.8.8.80x2624Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
            Aug 2, 2023 14:25:19.582402945 CEST192.168.2.228.8.8.80x1d9bStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Aug 2, 2023 14:25:19.613794088 CEST8.8.8.8192.168.2.220x2624No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
            Aug 2, 2023 14:25:19.623590946 CEST8.8.8.8192.168.2.220x1d9bNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
            Aug 2, 2023 14:25:19.623590946 CEST8.8.8.8192.168.2.220x1d9bNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
            • clients2.google.com
            • accounts.google.com
            Session IDSource IPSource PortDestination IPDestination PortProcess
            0192.168.2.2249183142.250.203.110443C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            TimestampkBytes transferredDirectionData
            2023-08-02 12:25:20 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
            Host: clients2.google.com
            Connection: keep-alive
            X-Goog-Update-Interactivity: fg
            X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfm
            X-Goog-Update-Updater: chromecrx-84.0.4147.135
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: empty
            User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2023-08-02 12:25:20 UTC1INHTTP/1.1 200 OK
            Content-Security-Policy: script-src 'report-sample' 'nonce-pzGtqwsjhlKskpR45FZRmg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
            Pragma: no-cache
            Expires: Mon, 01 Jan 1990 00:00:00 GMT
            Date: Wed, 02 Aug 2023 12:25:20 GMT
            Content-Type: text/xml; charset=UTF-8
            X-Daynum: 6057
            X-Daystart: 19520
            X-Content-Type-Options: nosniff
            X-Frame-Options: SAMEORIGIN
            X-XSS-Protection: 1; mode=block
            Server: GSE
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Accept-Ranges: none
            Vary: Accept-Encoding
            Connection: close
            Transfer-Encoding: chunked
            2023-08-02 12:25:20 UTC2INData Raw: 33 31 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 30 35 37 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 39 35 32 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
            Data Ascii: 31a<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6057" elapsed_seconds="19520"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
            2023-08-02 12:25:20 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 70 6b 65 64 63 6a 6b 64 65 66 67 70 64 65 6c 70 62 63 6d 62 6d 65 6f 6d 63 6a 62 65 65 6d 66 6d 22 20 73 74 61 74 75 73 3d 22 65 72 72 6f 72 2d 75 6e 6b 6e 6f 77 6e
            Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app><app appid="pkedcjkdefgpdelpbcmbmeomcjbeemfm" status="error-unknown
            2023-08-02 12:25:20 UTC2INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Session IDSource IPSource PortDestination IPDestination PortProcess
            1192.168.2.2249182142.250.203.109443C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            TimestampkBytes transferredDirectionData
            2023-08-02 12:25:20 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
            Host: accounts.google.com
            Connection: keep-alive
            Content-Length: 1
            Origin: https://www.google.com
            Content-Type: application/x-www-form-urlencoded
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: empty
            User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.135 Safari/537.36
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: CONSENT=WP.289365
            2023-08-02 12:25:20 UTC1OUTData Raw: 20
            Data Ascii:
            2023-08-02 12:25:20 UTC2INHTTP/1.1 200 OK
            Content-Type: application/json; charset=utf-8
            Access-Control-Allow-Origin: https://www.google.com
            Access-Control-Allow-Credentials: true
            X-Content-Type-Options: nosniff
            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
            Pragma: no-cache
            Expires: Mon, 01 Jan 1990 00:00:00 GMT
            Date: Wed, 02 Aug 2023 12:25:20 GMT
            Strict-Transport-Security: max-age=31536000; includeSubDomains
            Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
            Content-Security-Policy: script-src 'report-sample' 'nonce-nXeUOclJzn4dGIRKyJ4Cqw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
            Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
            Cross-Origin-Opener-Policy: same-origin
            Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
            Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
            Server: ESF
            X-XSS-Protection: 0
            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
            Accept-Ranges: none
            Vary: Accept-Encoding
            Connection: close
            Transfer-Encoding: chunked
            2023-08-02 12:25:20 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
            Data Ascii: 11["gaia.l.a.r",[]]
            2023-08-02 12:25:20 UTC4INData Raw: 30 0d 0a 0d 0a
            Data Ascii: 0


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:14:24:57
            Start date:02/08/2023
            Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
            Imagebase:0x13f210000
            File size:1'820'656 bytes
            MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low

            Target ID:1
            Start time:14:24:58
            Start date:02/08/2023
            Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=984,3082125091231155652,1986206945202247580,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1336 /prefetch:8
            Imagebase:0x13f210000
            File size:1'820'656 bytes
            MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low

            Target ID:4
            Start time:14:25:01
            Start date:02/08/2023
            Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://www.google.com/travel/clk?pc=AA80OsxOJqDJTtimFViThn67OQkloT30Ajm0l4ZvLJJer0pJHlDs6FtKUzjSNqFcVCDDRK9HbWM9J68g_B5lWBQlAc6FRf4zwpPAQbYRTV4byfvHC1SF4YRK3ax3ADGyZ2SM3lU&pcurl=https://portal-fundsdistribution-recipient.zip
            Imagebase:0x13f210000
            File size:1'820'656 bytes
            MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low

            Target ID:5
            Start time:14:25:02
            Start date:02/08/2023
            Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1072,1244314507077814543,10674633888874670333,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1264 /prefetch:8
            Imagebase:0x13f210000
            File size:1'820'656 bytes
            MD5 hash:6ACAE527E744C80997B25EF2A0485D5E
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low

            No disassembly