Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1

Overview

General Information

Sample URL:https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Fu
Analysis ID:1296925
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 5164 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
    • chrome.exe (PID: 5472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2812 --field-trial-handle=2588,i,4458651840048700992,7296907126945281215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • chrome.exe (PID: 5936 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1Avira URL Cloud: detection malicious, Label: phishing
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-115.0.5790.171Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: AEC=Ad49MVEVy5CxtQLtYrblzXz4DifLm5q80KxkAsZM0tGClBBQswyzDRIjhA; CONSENT=PENDING+494; SOCS=CAESHAgCEhJnd3NfMjAyMzA4MDMtMF9SQzIaAmVuIAEaBgiA0dCmBg; __Secure-ENID=14.SE=FEqwE5eimu_CzO8QanixDxMiVRDl1S74wJwxQG4kibYxHFlarNLstM6_FtN3tkTBDN7NI-PM3BH3uafw_juj7Kua5Sxw58UIqMyDvhq3JStE-0GsITWS9X0QrbjvmkA5MVBf-Eb4RLTTefnPk1F_g7MJo2hXw4TzaSRHE_HtskdpjjbT9g
Source: Google Drive.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: classification engineClassification label: mal48.win@26/6@23/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2812 --field-trial-handle=2588,i,4458651840048700992,7296907126945281215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2812 --field-trial-handle=2588,i,4458651840048700992,7296907126945281215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.203.110
truefalse
    high
    accounts.google.com
    172.217.168.77
    truefalse
      high
      www.google.com
      172.217.168.68
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            mail.sandiegofenceinstallers.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=115.0.5790.171&lang=en-GB&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  172.217.168.68
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  172.217.168.77
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.110
                  google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  Joe Sandbox Version:38.0.0 Beryl
                  Analysis ID:1296925
                  Start date and time:2023-08-24 19:54:42 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 6m 51s
                  Hypervisor based Inspection enabled:false
                  Report type:light
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:18
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@26/6@23/5
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, SgrmBroker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): www.bing.com, geover.prod.do.dsp.mp.microsoft.com, fs.microsoft.com, geo.prod.do.dsp.mp.microsoft.com, edgedl.me.gvt1.com, store-images.s-microsoft.com, eudb.ris.api.iris.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, crl3.digicert.com, img-prod-cms-rt-microsoft-com.akamaized.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2675
                  Entropy (8bit):4.007260914312631
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA1o9ehwiZUklqehDBA3:8JTXRu0
                  MD5:F89E794712FBC3FDB2662D011BFB1499
                  SHA1:77E64DADCAEF4F698D436BC5231A9CBDF62DFEF0
                  SHA-256:1330865DEC91D4FCA1A30D227583D0955323F462FA93BB988726038A48044723
                  SHA-512:31DDFF63D71735695C55A0D193F576E0D91EA4E74B95C8BFEEACB18C96F9A3DA57A6BFBD09329F1FF241E0622C8352183813B6A3BA235EC25247449075DF71C3
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2677
                  Entropy (8bit):4.024747132109703
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA1t9eh/iZUkAQkqehEBA2:8JTXRK9QN
                  MD5:1AEA5612DEECC3F2561447B4B4F6ECF4
                  SHA1:28899BF346DF9DFF657C9B64AD88624EC451F001
                  SHA-256:C7755D40925E73C034CE662E4B71D3812E5EFD4E2ECBF0A9CA8F7C2460BB94F4
                  SHA-512:D968C2F5249C370D078EEB579A89FFF142587003BB2014D7885110BF844EF8FF2FEDDD828AF58F68B8EC69FAA681D82455D03C9661E1D0425D85CEFC959FD870
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2691
                  Entropy (8bit):4.037217293964395
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA14J9eh7sFiZUkmgqeh7suBABX:8JTXRUnA
                  MD5:AEEFACADB40D10043C10F990652E5C0F
                  SHA1:EB355FD9CDE1880C44357B0B1C832A336C454D62
                  SHA-256:D022CC03E7DC073FF148E03D2285CEA0518B4E4E37D4C812900887B6F08957D7
                  SHA-512:297FCED5E614EEB7E5F17912639FD7306AD8DA5FB2F181E62873435E5DC2B1A034FB4E1E2D965A2D9B8B71EB885488E3DEE54C3422F6A5542B77A3386FD4A843
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2679
                  Entropy (8bit):4.022570982288567
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA1u9ehDiZUkwqehIBAR:8JTXRX2
                  MD5:BECA0F68E829779199F82EBC1EB8B76B
                  SHA1:8DB55DBFC03D51054C974F44FD166A3BD057C2B9
                  SHA-256:D42902BA680DFD2F1ABB3C1DC48A1B555E481B4CE77CF0EC6A7EDB810BADCAF9
                  SHA-512:15B977A7E8C902FE701B0863B71EF1A181C8D3568375E27A48072180C14DB2EE76B8807B3FD9A66E522A02F5A4A7222651B27EACD94E7114B63AE9E192FD69E1
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2679
                  Entropy (8bit):4.010808466195076
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA1c9ehBiZUk1W1qehqBAC:8JTXR39K
                  MD5:B9F2936701C4933B0D379B29E9A7E7D5
                  SHA1:F018781D48E844E4E6EC52E2BDA53A133288FB61
                  SHA-256:45A2A1F5A802A59A6FF69C14EBAA7E4EBD6E83112BDBCE6C404911F7ACDCCC08
                  SHA-512:99787F16D8FA761A29DA5FB5DFECD3107598D9275EA240C19F28AF269D53ABA821839D2ACB0713EFB5E9FD312090EAB28A5E9771BA0D0E11004F58ED8E97CF41
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Sep 30 06:28:28 2020, mtime=Thu Aug 10 09:45:23 2023, atime=Tue Aug 1 18:57:01 2023, length=1158936, window=hide
                  Category:dropped
                  Size (bytes):2681
                  Entropy (8bit):4.025997287023558
                  Encrypted:false
                  SSDEEP:48:8JTcd9bORmH2idAKZdA1duTn9ehOuTbbiZUk5OjqehOuTbABAyT+:8JTXRgTqTbxWOvTbAPT
                  MD5:7FC955EAC109DD3BF2C641B74C239AFE
                  SHA1:124014CCCF0EF4CA41FA478BE83C64E37FC0F7AF
                  SHA-256:C3BBE95275CA812F029F850BDD4A701DE40C68F48511B85F96FDDA34E408A4C4
                  SHA-512:09544D5B1F8AD730C9ABFB78033A5B8F6FE2C34D7FE2766B04D789D53D2E88CBBBE7D2BDAA58EF2341A7FC5719073CA61D5D0D7621593CE453A36827B2F677C6
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ....b.J........w.....,V............................1....P.O. .:i.....+00.../C:\.....................1......W.U..PROGRA~1..t......L..W.....E...............J........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....>Q.;..Google..>......>Q.;.W...............................G.o.o.g.l.e.....T.1......W.U..Chrome..>......>Q.;.W...........................c.>.C.h.r.o.m.e.....`.1......W.U..APPLIC~1..H......>Q.;.W............................A.A.p.p.l.i.c.a.t.i.o.n.....n.2......W!. .CHROME~1.EXE..R......>Q.;.W.U.....}......................h.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........}\.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Aug 24, 2023 19:55:43.272048950 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.272094965 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.272238970 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.278661013 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.278709888 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.285154104 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.285213947 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.285300970 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.300944090 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.300986052 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.374636889 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.379035950 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.396414042 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.396464109 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.396583080 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.396615028 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.397726059 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.397916079 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.400037050 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.400279999 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.400470972 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.400587082 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.411048889 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.411361933 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.414484978 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.414525986 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.414845943 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.415066004 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.415436029 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.415473938 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.449373960 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.449471951 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.449506998 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.449600935 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.449682951 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.463841915 CEST49699443192.168.2.4142.250.203.110
                  Aug 24, 2023 19:55:43.463892937 CEST44349699142.250.203.110192.168.2.4
                  Aug 24, 2023 19:55:43.471487045 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.471667051 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.471702099 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.471740961 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:43.471811056 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.480424881 CEST49698443192.168.2.4172.217.168.77
                  Aug 24, 2023 19:55:43.480458021 CEST44349698172.217.168.77192.168.2.4
                  Aug 24, 2023 19:55:45.776206017 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.776258945 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.776357889 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.776896954 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.776932955 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.832093000 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.834053040 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.834115028 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.835616112 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.835745096 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.839303970 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.839565992 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:45.979052067 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:45.979095936 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:46.082629919 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:55.813098907 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:55.813198090 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:55:55.813333035 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:58.430896044 CEST49701443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:55:58.430934906 CEST44349701172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:45.873914957 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:45.873964071 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:45.874064922 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:45.874588013 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:45.874610901 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:48.494669914 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:48.495296001 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:48.495340109 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:48.496139050 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:48.496824980 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:48.496987104 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:48.540262938 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:56:58.552169085 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:58.552306890 CEST44349733172.217.168.68192.168.2.4
                  Aug 24, 2023 19:56:58.552408934 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:57:00.646816015 CEST49733443192.168.2.4172.217.168.68
                  Aug 24, 2023 19:57:00.646857977 CEST44349733172.217.168.68192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Aug 24, 2023 19:55:43.165520906 CEST6331553192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.165896893 CEST6226553192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.166512966 CEST6083853192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.167280912 CEST5381953192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.190660954 CEST53608388.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.202553988 CEST53633158.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.205363035 CEST53538198.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.211195946 CEST53622658.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.214791059 CEST53518168.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.761799097 CEST4978553192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.762279987 CEST6387253192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:43.903652906 CEST53498178.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:43.968375921 CEST53497858.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:44.106445074 CEST6255053192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:44.292721987 CEST53625508.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:45.716069937 CEST6480353192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:45.718527079 CEST5438853192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:45.728313923 CEST6452253192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:45.728740931 CEST5365353192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:45.736471891 CEST53648038.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:45.748250008 CEST53543888.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:45.752182961 CEST53536538.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:45.770896912 CEST53645228.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:46.725970984 CEST5208653192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:46.726480961 CEST6419653192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:46.959121943 CEST53520868.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:47.011681080 CEST5539853192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:47.040098906 CEST53553988.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:48.790116072 CEST53638728.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:51.741915941 CEST53641968.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:52.126959085 CEST6133053192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:52.127614975 CEST6092653192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:52.320254087 CEST53613308.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:52.363343954 CEST4924753192.168.2.48.8.8.8
                  Aug 24, 2023 19:55:52.391532898 CEST53492478.8.8.8192.168.2.4
                  Aug 24, 2023 19:55:57.154635906 CEST53609268.8.8.8192.168.2.4
                  Aug 24, 2023 19:56:22.445149899 CEST6349453192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:22.445710897 CEST5790253192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:23.467422009 CEST6103853192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:23.468245029 CEST6196053192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:23.765650988 CEST53610388.8.8.8192.168.2.4
                  Aug 24, 2023 19:56:23.845350981 CEST5301453192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:25.001065969 CEST5301453192.168.2.48.8.8.8
                  Aug 24, 2023 19:56:25.038093090 CEST53530148.8.8.8192.168.2.4
                  Aug 24, 2023 19:56:57.392524004 CEST53622048.8.8.8192.168.2.4
                  TimestampSource IPDest IPChecksumCodeType
                  Aug 24, 2023 19:55:43.903860092 CEST192.168.2.48.8.8.8d02f(Port unreachable)Destination Unreachable
                  Aug 24, 2023 19:55:48.791524887 CEST192.168.2.48.8.8.8d004(Port unreachable)Destination Unreachable
                  Aug 24, 2023 19:55:51.742080927 CEST192.168.2.48.8.8.8d004(Port unreachable)Destination Unreachable
                  Aug 24, 2023 19:55:57.154798031 CEST192.168.2.48.8.8.8d004(Port unreachable)Destination Unreachable
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Aug 24, 2023 19:55:43.165520906 CEST192.168.2.48.8.8.80xdf3cStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:43.165896893 CEST192.168.2.48.8.8.80xd10aStandard query (0)clients2.google.com65IN (0x0001)false
                  Aug 24, 2023 19:55:43.166512966 CEST192.168.2.48.8.8.80x2005Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:43.167280912 CEST192.168.2.48.8.8.80x9eddStandard query (0)accounts.google.com65IN (0x0001)false
                  Aug 24, 2023 19:55:43.761799097 CEST192.168.2.48.8.8.80xf970Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:43.762279987 CEST192.168.2.48.8.8.80x6567Standard query (0)mail.sandiegofenceinstallers.com65IN (0x0001)false
                  Aug 24, 2023 19:55:44.106445074 CEST192.168.2.48.8.8.80x45ebStandard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.716069937 CEST192.168.2.48.8.8.80xe8baStandard query (0)google.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.718527079 CEST192.168.2.48.8.8.80xd474Standard query (0)google.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.728313923 CEST192.168.2.48.8.8.80x7004Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.728740931 CEST192.168.2.48.8.8.80x123bStandard query (0)www.google.com65IN (0x0001)false
                  Aug 24, 2023 19:55:46.725970984 CEST192.168.2.48.8.8.80xc910Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:46.726480961 CEST192.168.2.48.8.8.80xc8afStandard query (0)mail.sandiegofenceinstallers.com65IN (0x0001)false
                  Aug 24, 2023 19:55:47.011681080 CEST192.168.2.48.8.8.80xafd0Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:52.126959085 CEST192.168.2.48.8.8.80xb981Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:52.127614975 CEST192.168.2.48.8.8.80xe0b1Standard query (0)mail.sandiegofenceinstallers.com65IN (0x0001)false
                  Aug 24, 2023 19:55:52.363343954 CEST192.168.2.48.8.8.80xe2Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:56:22.445149899 CEST192.168.2.48.8.8.80x238aStandard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:56:22.445710897 CEST192.168.2.48.8.8.80xcf4Standard query (0)mail.sandiegofenceinstallers.com65IN (0x0001)false
                  Aug 24, 2023 19:56:23.467422009 CEST192.168.2.48.8.8.80x905Standard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:56:23.468245029 CEST192.168.2.48.8.8.80x5508Standard query (0)mail.sandiegofenceinstallers.com65IN (0x0001)false
                  Aug 24, 2023 19:56:23.845350981 CEST192.168.2.48.8.8.80xe69eStandard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  Aug 24, 2023 19:56:25.001065969 CEST192.168.2.48.8.8.80xe69eStandard query (0)mail.sandiegofenceinstallers.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Aug 24, 2023 19:55:43.190660954 CEST8.8.8.8192.168.2.40x2005No error (0)accounts.google.com172.217.168.77A (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:43.202553988 CEST8.8.8.8192.168.2.40xdf3cNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Aug 24, 2023 19:55:43.202553988 CEST8.8.8.8192.168.2.40xdf3cNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:43.211195946 CEST8.8.8.8192.168.2.40xd10aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Aug 24, 2023 19:55:45.736471891 CEST8.8.8.8192.168.2.40xe8baNo error (0)google.com142.250.203.110A (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.748250008 CEST8.8.8.8192.168.2.40xd474No error (0)google.com142.250.203.110A (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:45.752182961 CEST8.8.8.8192.168.2.40x123bNo error (0)www.google.com65IN (0x0001)false
                  Aug 24, 2023 19:55:45.770896912 CEST8.8.8.8192.168.2.40x7004No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                  Aug 24, 2023 19:55:48.790116072 CEST8.8.8.8192.168.2.40x6567Server failure (2)mail.sandiegofenceinstallers.comnonenone65IN (0x0001)false
                  Aug 24, 2023 19:55:51.741915941 CEST8.8.8.8192.168.2.40xc8afServer failure (2)mail.sandiegofenceinstallers.comnonenone65IN (0x0001)false
                  Aug 24, 2023 19:55:57.154635906 CEST8.8.8.8192.168.2.40xe0b1Server failure (2)mail.sandiegofenceinstallers.comnonenone65IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com

                  Click to jump to process

                  Target ID:1
                  Start time:19:55:38
                  Start date:24/08/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7c94b0000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:19:55:40
                  Start date:24/08/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2812 --field-trial-handle=2588,i,4458651840048700992,7296907126945281215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7c94b0000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:4
                  Start time:19:55:42
                  Start date:24/08/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mail.sandiegofenceinstallers.com/login_up.php?success_redirect_url=%2Findex.php%2Ffalse%2Fpy1n.html%2Fdiscovercard.com%2Fdfs%2Faccounthome%2Fsummary%2F-www.schwab.com%2Fsecure.accurint.com%2Funfcu2.org%2Flogin1
                  Imagebase:0x7ff7c94b0000
                  File size:3'219'224 bytes
                  MD5 hash:8D1C4713ACB7CC2AAAEE4477C58A80BA
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly