Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://gc.psscdn.com/1x1.png

Overview

General Information

Sample URL:https://gc.psscdn.com/1x1.png
Analysis ID:1392886
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Creates files inside the system directory

Classification

  • System is w10x64
  • chrome.exe (PID: 7036 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6088 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2228,i,15793409067123977078,7030360026841101780,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 2548 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gc.psscdn.com/1x1.png MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://gc.psscdn.com/1x1.pngHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.50.93:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.50.93:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.50.93
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.134Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=UBeNCkZ3L8yXcx8qh4JFUXkwkNC9IrdiRdbjSTjqSiFh8WrRcbKr_rOJbgHY6TA4RT-6ps0bhemfwCPBsLMgPT7-gTcWqHvZvZbafOpkqRy0dLyYG9AjP2vbUBomarnc9pcZVlhHkUeUaWMurD0GGXyW05_B_1IyUNYEELmyqRg
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 184.31.50.93:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.50.93:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_7036_2097588428Jump to behavior
Source: classification engineClassification label: clean0.win@16/5@10/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2228,i,15793409067123977078,7030360026841101780,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gc.psscdn.com/1x1.png
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2228,i,15793409067123977078,7030360026841101780,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://gc.psscdn.com/1x1.png0%Avira URL Cloudsafe
https://gc.psscdn.com/1x1.png0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
gc.psscdn.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.253.124.84
truefalse
    high
    www.google.com
    74.125.136.105
    truefalse
      high
      clients.l.google.com
      64.233.177.101
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalseunknown
        clients2.google.com
        unknown
        unknownfalse
          high
          gc.psscdn.com
          unknown
          unknownfalseunknown
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://gc.psscdn.com/1x1.pngfalse
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                74.125.136.105
                www.google.comUnited States
                15169GOOGLEUSfalse
                64.233.177.101
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                172.253.124.84
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.6
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1392886
                Start date and time:2024-02-15 15:17:48 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 2s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://gc.psscdn.com/1x1.png
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:6
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/5@10/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 64.233.177.94, 34.104.35.123, 23.223.44.233, 23.223.44.246, 23.192.229.198, 23.192.229.207, 40.127.169.103, 72.21.81.240, 192.229.211.108, 52.165.164.15, 20.3.187.198
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, a412.dscb.akamai.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, gc.psscdn.com.edgesuite.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 1 x 1, 1-bit colormap, non-interlaced
                Category:downloaded
                Size (bytes):95
                Entropy (8bit):4.347811435468635
                Encrypted:false
                SSDEEP:3:yionv//thPlE+kSI+Dtmy/Y+sR3Qhl/Y3WlED//jp:6v/lhPfkCDtmywFghu3WlEDTp
                MD5:71A50DBBA44C78128B221B7DF7BB51F1
                SHA1:0EC63B140374BA704A58FA0C743CB357683313DD
                SHA-256:3EB10792D1F0C7E07E7248273540F1952D9A5A2996F4B5DF70AB026CD9F05517
                SHA-512:6AD523F5B65487369D305613366B9F68DCDEEE225291766E3B25FAF45439CA069F614030C08CA54C714FDBF7A944FAC489B1515A8BF9E0D3191E1BCBBFE6A9DF
                Malicious:false
                Reputation:low
                URL:https://gc.psscdn.com/1x1.png
                Preview:.PNG........IHDR.............%.V.....PLTE....z=.....tRNS.@..f....IDAT..c`.......!.3....IEND.B`.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 1 x 1, 1-bit colormap, non-interlaced
                Category:downloaded
                Size (bytes):95
                Entropy (8bit):4.347811435468635
                Encrypted:false
                SSDEEP:3:yionv//thPlE+kSI+Dtmy/Y+sR3Qhl/Y3WlED//jp:6v/lhPfkCDtmywFghu3WlEDTp
                MD5:71A50DBBA44C78128B221B7DF7BB51F1
                SHA1:0EC63B140374BA704A58FA0C743CB357683313DD
                SHA-256:3EB10792D1F0C7E07E7248273540F1952D9A5A2996F4B5DF70AB026CD9F05517
                SHA-512:6AD523F5B65487369D305613366B9F68DCDEEE225291766E3B25FAF45439CA069F614030C08CA54C714FDBF7A944FAC489B1515A8BF9E0D3191E1BCBBFE6A9DF
                Malicious:false
                Reputation:low
                URL:https://gc.psscdn.com/favicon.ico
                Preview:.PNG........IHDR.............%.V.....PLTE....z=.....tRNS.@..f....IDAT..c`.......!.3....IEND.B`.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 1 x 1, 1-bit colormap, non-interlaced
                Category:dropped
                Size (bytes):95
                Entropy (8bit):4.347811435468635
                Encrypted:false
                SSDEEP:3:yionv//thPlE+kSI+Dtmy/Y+sR3Qhl/Y3WlED//jp:6v/lhPfkCDtmywFghu3WlEDTp
                MD5:71A50DBBA44C78128B221B7DF7BB51F1
                SHA1:0EC63B140374BA704A58FA0C743CB357683313DD
                SHA-256:3EB10792D1F0C7E07E7248273540F1952D9A5A2996F4B5DF70AB026CD9F05517
                SHA-512:6AD523F5B65487369D305613366B9F68DCDEEE225291766E3B25FAF45439CA069F614030C08CA54C714FDBF7A944FAC489B1515A8BF9E0D3191E1BCBBFE6A9DF
                Malicious:false
                Reputation:low
                Preview:.PNG........IHDR.............%.V.....PLTE....z=.....tRNS.@..f....IDAT..c`.......!.3....IEND.B`.
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Feb 15, 2024 15:18:31.716274977 CET49673443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:31.716290951 CET49674443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:32.044394970 CET49672443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:36.926565886 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:36.926599979 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:36.926661015 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:36.927072048 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:36.927083969 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:36.927696943 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:36.927781105 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:36.928035021 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:36.930706024 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:36.930741072 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.179760933 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.179996967 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.180099010 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.180164099 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.180196047 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.180206060 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.180721998 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.180790901 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.182063103 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.182076931 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.182143927 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.182296038 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.184535980 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.184637070 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.185483932 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.185570002 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.185796022 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.185812950 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.186342001 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.186347961 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.247740984 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.308569908 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.369096994 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.369476080 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.369532108 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.370193005 CET49700443192.168.2.664.233.177.101
                Feb 15, 2024 15:18:37.370208979 CET4434970064.233.177.101192.168.2.6
                Feb 15, 2024 15:18:37.395360947 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.395675898 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:37.395847082 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.397392988 CET49701443192.168.2.6172.253.124.84
                Feb 15, 2024 15:18:37.397433043 CET44349701172.253.124.84192.168.2.6
                Feb 15, 2024 15:18:41.133507013 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.133594990 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.133698940 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.134157896 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.134198904 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.324001074 CET49673443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:41.324079990 CET49674443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:41.359167099 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.363528013 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.363584042 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.365169048 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.365288973 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.377769947 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.377994061 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.433491945 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.433552980 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:41.480452061 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:41.652160883 CET49672443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:41.777266026 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:41.777359009 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:41.777482033 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:41.780678034 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:41.780711889 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:41.993469000 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:41.993669033 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.002460957 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.002490044 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.002716064 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.042860985 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.164980888 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.205899000 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.276315928 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.276390076 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.276492119 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.276492119 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.276492119 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.315705061 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.315788031 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.315895081 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.316756964 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.316793919 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.528811932 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.528901100 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.532731056 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.532746077 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.532972097 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.537708044 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.574140072 CET49711443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.574203014 CET44349711184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.581909895 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.734549999 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.734620094 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:42.734679937 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.739633083 CET49712443192.168.2.6184.31.50.93
                Feb 15, 2024 15:18:42.739660978 CET44349712184.31.50.93192.168.2.6
                Feb 15, 2024 15:18:43.073071957 CET44349698173.222.162.64192.168.2.6
                Feb 15, 2024 15:18:43.073266983 CET49698443192.168.2.6173.222.162.64
                Feb 15, 2024 15:18:51.362848043 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:51.362937927 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:18:51.363084078 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:53.269706011 CET49710443192.168.2.674.125.136.105
                Feb 15, 2024 15:18:53.269742012 CET4434971074.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.066771984 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:41.066863060 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.067101955 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:41.068451881 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:41.068490028 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.285475016 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.285804987 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:41.285864115 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.286365986 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.286780119 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:41.286879063 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:41.341057062 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:51.317519903 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:51.317619085 CET4434972274.125.136.105192.168.2.6
                Feb 15, 2024 15:19:51.317785025 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:53.052972078 CET49722443192.168.2.674.125.136.105
                Feb 15, 2024 15:19:53.053000927 CET4434972274.125.136.105192.168.2.6
                TimestampSource PortDest PortSource IPDest IP
                Feb 15, 2024 15:18:36.807863951 CET6164953192.168.2.61.1.1.1
                Feb 15, 2024 15:18:36.808059931 CET6264853192.168.2.61.1.1.1
                Feb 15, 2024 15:18:36.808444977 CET5439553192.168.2.61.1.1.1
                Feb 15, 2024 15:18:36.808717966 CET6237953192.168.2.61.1.1.1
                Feb 15, 2024 15:18:36.834186077 CET53522701.1.1.1192.168.2.6
                Feb 15, 2024 15:18:36.925529003 CET53616491.1.1.1192.168.2.6
                Feb 15, 2024 15:18:36.925607920 CET53626481.1.1.1192.168.2.6
                Feb 15, 2024 15:18:36.925807953 CET53543951.1.1.1192.168.2.6
                Feb 15, 2024 15:18:36.926050901 CET53623791.1.1.1192.168.2.6
                Feb 15, 2024 15:18:37.551173925 CET53609821.1.1.1192.168.2.6
                Feb 15, 2024 15:18:38.551444054 CET5952853192.168.2.61.1.1.1
                Feb 15, 2024 15:18:38.551934004 CET6190853192.168.2.61.1.1.1
                Feb 15, 2024 15:18:39.508347988 CET6454553192.168.2.61.1.1.1
                Feb 15, 2024 15:18:39.508601904 CET6365653192.168.2.61.1.1.1
                Feb 15, 2024 15:18:41.013874054 CET6384153192.168.2.61.1.1.1
                Feb 15, 2024 15:18:41.014208078 CET5013653192.168.2.61.1.1.1
                Feb 15, 2024 15:18:41.131840944 CET53638411.1.1.1192.168.2.6
                Feb 15, 2024 15:18:41.131908894 CET53501361.1.1.1192.168.2.6
                Feb 15, 2024 15:18:55.337366104 CET53521981.1.1.1192.168.2.6
                Feb 15, 2024 15:19:14.163465977 CET53626741.1.1.1192.168.2.6
                Feb 15, 2024 15:19:36.509315014 CET53621451.1.1.1192.168.2.6
                Feb 15, 2024 15:19:36.943382025 CET53547791.1.1.1192.168.2.6
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Feb 15, 2024 15:18:36.807863951 CET192.168.2.61.1.1.10xc0e7Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.808059931 CET192.168.2.61.1.1.10xc180Standard query (0)clients2.google.com65IN (0x0001)false
                Feb 15, 2024 15:18:36.808444977 CET192.168.2.61.1.1.10x7664Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.808717966 CET192.168.2.61.1.1.10x95eaStandard query (0)accounts.google.com65IN (0x0001)false
                Feb 15, 2024 15:18:38.551444054 CET192.168.2.61.1.1.10xd88bStandard query (0)gc.psscdn.comA (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:38.551934004 CET192.168.2.61.1.1.10x2f97Standard query (0)gc.psscdn.com65IN (0x0001)false
                Feb 15, 2024 15:18:39.508347988 CET192.168.2.61.1.1.10x800aStandard query (0)gc.psscdn.comA (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:39.508601904 CET192.168.2.61.1.1.10x25a7Standard query (0)gc.psscdn.com65IN (0x0001)false
                Feb 15, 2024 15:18:41.013874054 CET192.168.2.61.1.1.10x401fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.014208078 CET192.168.2.61.1.1.10xef9cStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.101A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.113A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.102A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.138A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.139A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925529003 CET1.1.1.1192.168.2.60xc0e7No error (0)clients.l.google.com64.233.177.100A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:36.925607920 CET1.1.1.1192.168.2.60xc180No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:36.925807953 CET1.1.1.1192.168.2.60x7664No error (0)accounts.google.com172.253.124.84A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:38.670295954 CET1.1.1.1192.168.2.60xd88bNo error (0)gc.psscdn.comgc.psscdn.com.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:38.685245037 CET1.1.1.1192.168.2.60x2f97No error (0)gc.psscdn.comgc.psscdn.com.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:39.642611027 CET1.1.1.1192.168.2.60x25a7No error (0)gc.psscdn.comgc.psscdn.com.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:39.642694950 CET1.1.1.1192.168.2.60x800aNo error (0)gc.psscdn.comgc.psscdn.com.edgesuite.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131840944 CET1.1.1.1192.168.2.60x401fNo error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
                Feb 15, 2024 15:18:41.131908894 CET1.1.1.1192.168.2.60xef9cNo error (0)www.google.com65IN (0x0001)false
                Feb 15, 2024 15:18:53.003686905 CET1.1.1.1192.168.2.60xdcfcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:18:53.003686905 CET1.1.1.1192.168.2.60xdcfcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 15, 2024 15:19:06.324403048 CET1.1.1.1192.168.2.60x5b2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:19:06.324403048 CET1.1.1.1192.168.2.60x5b2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 15, 2024 15:19:29.254807949 CET1.1.1.1192.168.2.60xc437No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:19:29.254807949 CET1.1.1.1192.168.2.60xc437No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 15, 2024 15:19:49.255073071 CET1.1.1.1192.168.2.60xb8ceNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 15, 2024 15:19:49.255073071 CET1.1.1.1192.168.2.60xb8ceNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • accounts.google.com
                • clients2.google.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.649701172.253.124.844436088C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-15 14:18:37 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: NID=511=UBeNCkZ3L8yXcx8qh4JFUXkwkNC9IrdiRdbjSTjqSiFh8WrRcbKr_rOJbgHY6TA4RT-6ps0bhemfwCPBsLMgPT7-gTcWqHvZvZbafOpkqRy0dLyYG9AjP2vbUBomarnc9pcZVlhHkUeUaWMurD0GGXyW05_B_1IyUNYEELmyqRg
                2024-02-15 14:18:37 UTC1OUTData Raw: 20
                Data Ascii:
                2024-02-15 14:18:37 UTC1799INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Thu, 15 Feb 2024 14:18:37 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-1JR9SyOdfVFdjFcFjD47kA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Cross-Origin-Opener-Policy: same-origin
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmJw05BiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQFiIR6Ovbt2rGMTuLFn0gJGALYsF4g"
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-15 14:18:37 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2024-02-15 14:18:37 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.64970064.233.177.1014436088C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-02-15 14:18:37 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.134&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-117.0.5938.134
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-02-15 14:18:37 UTC732INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-QG0FBnyZer1h1h3QzrPRxg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Thu, 15 Feb 2024 14:18:37 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 6254
                X-Daystart: 22717
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2024-02-15 14:18:37 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 35 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 32 37 31 37 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6254" elapsed_seconds="22717"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2024-02-15 14:18:37 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2024-02-15 14:18:37 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.649711184.31.50.93443
                TimestampBytes transferredDirectionData
                2024-02-15 14:18:42 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-15 14:18:42 UTC468INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/079C)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus2-z1
                Cache-Control: public, max-age=104804
                Date: Thu, 15 Feb 2024 14:18:42 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.649712184.31.50.93443
                TimestampBytes transferredDirectionData
                2024-02-15 14:18:42 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-02-15 14:18:42 UTC456INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/0778)
                X-CID: 11
                Cache-Control: public, max-age=104829
                Date: Thu, 15 Feb 2024 14:18:42 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-02-15 14:18:42 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:15:18:32
                Start date:15/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff684c40000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:15:18:35
                Start date:15/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2228,i,15793409067123977078,7030360026841101780,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff684c40000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:15:18:37
                Start date:15/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gc.psscdn.com/1x1.png
                Imagebase:0x7ff684c40000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly