Windows Analysis Report
https://drive.google.com/file/d/1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc/view

Overview

General Information

Sample URL: https://drive.google.com/file/d/1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc/view
Analysis ID: 1432106
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&followup=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&ifkv=AaSxoQwhuqJe4fTrwoAG_tLDsGAq7OABepLlV0bVbjYgQsi8jrYbsBwCJVoPUdqKI0AEClBJKaW1MA&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1174077171%3A1714130945264250&theme=mn&ddm=0 HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown TCP traffic detected without corresponding DNS query: 23.196.177.159
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /file/d/1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc/view HTTP/1.1Host: drive.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /auth_warmup HTTP/1.1Host: drive.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://drive.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=Q3IjpsCLHOjamouMp0h7mN-0rE-TYfN6BdbUVAsjCcTRovm7TuUbJoUpo0-RyTwKN6Un4KwvoCEg_D2FiLh9tFSytutQF7qhsV4q_1MeSPcTMLebaKQn6gjr9_X9JkQPm-ST9_pxa6rX4KzKA8Sv0Lu92gocQXj0mbDnTOHhAEA
Source: global traffic HTTP traffic detected: GET /drivesharing/clientmodel?id=1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc&foreignService=texmex&authuser=0&origin=https%3A%2F%2Fdrive.google.com HTTP/1.1Host: drive.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://drive.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=Q3IjpsCLHOjamouMp0h7mN-0rE-TYfN6BdbUVAsjCcTRovm7TuUbJoUpo0-RyTwKN6Un4KwvoCEg_D2FiLh9tFSytutQF7qhsV4q_1MeSPcTMLebaKQn6gjr9_X9JkQPm-ST9_pxa6rX4KzKA8Sv0Lu92gocQXj0mbDnTOHhAEA
Source: global traffic HTTP traffic detected: GET /viewer2/prod-02/archive?ck=drive&ds=APznzaYUfl2TcJ5k351Mz-oX5D0kiuP7VzHKjZ8VEoILiA2hdfvaiUTaVkyZkL2oXmvQURSPYmy1Ko05ZlZTcL4BdmjpOJ0KpcFGdGN3Lr-yF2n9lKZDtjR92HHKNGxegMjoovZuStNsOmmlGFFXUFNqLwzzkH_l_i-ybx3ph0Py9NW7-CeFmRr7pFJI9wcxTmwNKl_vsHLV9uuyTYtXgsxvMRoEE6QTcyRYus3pdixWgfNFGbgXKxXWU56TDg03f6-acXmnBFA3LD2GChyGqmSW0Bh2gfvxpSoStUgvKDUc75Q5mRUpM6bKL5pG2e0G-fQyHPFcfUDJ5kN2tB8iY8dsbpbQlA54s5wfSna98QQ854jnnHfcAfcAZQGtGBo_iF7Hec9hxqMB-FzNo7Xq4SoyneNepy394uk-Kh3m54q3WHo8XPXetR8%3D&authuser=0&page=0 HTTP/1.1Host: drive.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://drive.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=Q3IjpsCLHOjamouMp0h7mN-0rE-TYfN6BdbUVAsjCcTRovm7TuUbJoUpo0-RyTwKN6Un4KwvoCEg_D2FiLh9tFSytutQF7qhsV4q_1MeSPcTMLebaKQn6gjr9_X9JkQPm-ST9_pxa6rX4KzKA8Sv0Lu92gocQXj0mbDnTOHhAEA
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /images/branding/googlelogo/1x/googlelogo_color_150x54dp.png HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://accounts.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /js/googleapis.proxy.js?onload=startup HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://content.googleapis.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=googleapis_proxy/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_0?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://content.googleapis.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /images/branding/googlelogo/1x/googlelogo_color_150x54dp.png HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /viewer2/prod-02/archive?ck=drive&ds=APznzaYUfl2TcJ5k351Mz-oX5D0kiuP7VzHKjZ8VEoILiA2hdfvaiUTaVkyZkL2oXmvQURSPYmy1Ko05ZlZTcL4BdmjpOJ0KpcFGdGN3Lr-yF2n9lKZDtjR92HHKNGxegMjoovZuStNsOmmlGFFXUFNqLwzzkH_l_i-ybx3ph0Py9NW7-CeFmRr7pFJI9wcxTmwNKl_vsHLV9uuyTYtXgsxvMRoEE6QTcyRYus3pdixWgfNFGbgXKxXWU56TDg03f6-acXmnBFA3LD2GChyGqmSW0Bh2gfvxpSoStUgvKDUc75Q5mRUpM6bKL5pG2e0G-fQyHPFcfUDJ5kN2tB8iY8dsbpbQlA54s5wfSna98QQ854jnnHfcAfcAZQGtGBo_iF7Hec9hxqMB-FzNo7Xq4SoyneNepy394uk-Kh3m54q3WHo8XPXetR8%3D&authuser=0&page=0 HTTP/1.1Host: drive.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /file/d/1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc/docos/p/sync?resourcekey&id=1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc&reqid=0 HTTP/1.1Host: drive.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /a-/ALV-UjU2mXLWCJzi1jm2LT5yGThl-tAzKHxVR-sixA5EW9xURqjmIyc=s64 HTTP/1.1Host: lh3.googleusercontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://drive.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /a-/ALV-UjU2mXLWCJzi1jm2LT5yGThl-tAzKHxVR-sixA5EW9xURqjmIyc=s64 HTTP/1.1Host: lh3.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: global traffic HTTP traffic detected: GET /log?format=json&hasfast=true&authuser=0 HTTP/1.1Host: play.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=DGx8IcyS7I3q2e-I1ed4wEnHCFKlikCcif-7d7KseeZ9ZULb1B5vgUkHV--0HY9ELLvyGQkhFN6Kc5bxgiowBem2p19uvcufBm4PVisSviRS6FmTaN7hLbyr7MLEfG3UUyrvLbboYPo-HuDqhTp3gUbHhLols3tE2OHJc2FHRDI
Source: chromecache_71.2.dr String found in binary or memory: disableRealtimeCallback:!1,drive_share:{skipInitCommand:!0},csi:{rate:.01},client:{cors:!1},signInDeprecation:{rate:0},include_granted_scopes:!0,llang:"en",iframes:{youtube:{params:{location:["search","hash"]},url:":socialhost:/:session_prefix:_/widget/render/youtube?usegapi=1",methods:["scroll","openwindow"]},ytsubscribe:{url:"https://www.youtube.com/subscribe_embed?usegapi=1"},plus_circle:{params:{url:""},url:":socialhost:/:session_prefix::se:_/widget/plus/circle?usegapi=1"},plus_share:{params:{url:""}, equals www.youtube.com (Youtube)
Source: chromecache_85.2.dr String found in binary or memory: ff=u(["https://sandbox.google.com/tools/feedback/"]),gf=u(["https://www.google.cn/tools/feedback/"]),hf=u(["https://help.youtube.com/tools/feedback/"]),jf=u(["https://asx-frontend-staging.corp.google.com/inapp/"]),kf=u(["https://asx-frontend-staging.corp.google.com/tools/feedback/"]),lf=u(["https://localhost.corp.google.com/inapp/"]),mf=u(["https://localhost.proxy.googlers.com/inapp/"]),nf=S(Pe),of=[S(Qe),S(Re)],pf=[S(Se),S(Te),S(Ue),S(Ve),S(We),S(Xe),S(Ye),S(Ze),S($e),S(af)],qf=[S(bf),S(cf)],rf= equals www.youtube.com (Youtube)
Source: chromecache_73.2.dr String found in binary or memory: var izb=function(a){return nh(function(){return KC(a,hzb,U4a)},function(b,c){(void 0===c||500>c)&&b.cancel()},function(b,c){(void 0===c||500>c)&&b.cancel()}).then()},jzb=function(a,b){b.then(function(){a.state=2;for(var c=n(a.C),d=c.next();!d.done;d=c.next())d.value.Mc.resolve();a.C.splice(0,a.C.length)},function(){var c=a.C.shift();c?(jzb(a,c.promise),c.Mc.resolve()):a.state=0})};var kzb=function(a){I.call(this);this.context=a;a=this.context.fa();this.C=TC(a)||new WF;this.Ge=new Rh(E(this.C,6,"AIzaSyDVQw45DwoYh632gvsP5vPDqEKvb-Ywnb8"),ki(a)||"0",E(this.C,7,"https://workspacevideo-pa.googleapis.com"),void 0,!0,void 0,!0,void 0,void 0);this.Ge.init();this.sa(this.Ge)};N(kzb,I);var lzb=function(a){YF.call(this,a.la());this.context=a};N(lzb,YF);lzb.prototype.D=function(){return"onYouTubeIframeAPIReady"};lzb.prototype.H=function(){var a=TC(this.context.fa())||new WF;return RAa(E(a,1,"https://www.youtube.com"),"iframe_api")};lzb.prototype.C=function(){return wj("YT.Player",this.la().getWindow())};var sJ=function(a){Hf.call(this);this.C=a;this.sa(this.C);var b=a.fa();a=a.la();this.L=null;this.ha=!1;this.R=0;this.O=null;DC(b)||tf(b,83);var c=M(b,iD,112);c=null!=c?C(c,1):null;c="string"===typeof c?oe(c):"https://drive.google.com";this.Ia=FOa(c);this.J=new xh(this);this.sa(this.J);this.D=new Mgb;this.sa(this.D);mzb(this,b,a);c=this.C.fa();var d=M(c,iD,112);null!=d&&oi(d,7)&&(dF(this.D,new O6a(this.C)),dF(this.D,new nD(this.C)));(d=Qh(c))&&G(d,7,!1)&&(dF(this.D,new pD(this.C)),dF(this.D,new V6a(this.C))); equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: drive.google.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: apis.google.com
Source: global traffic DNS traffic detected: DNS query: play.google.com
Source: global traffic DNS traffic detected: DNS query: blobcomments-pa.clients6.google.com
Source: global traffic DNS traffic detected: DNS query: peoplestackwebexperiments-pa.clients6.google.com
Source: global traffic DNS traffic detected: DNS query: lh3.googleusercontent.com
Source: unknown HTTP traffic detected: POST /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveContent-Length: 1966sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: text/plain;charset=UTF-8Accept: */*Origin: https://drive.google.comX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://drive.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=513=Q3IjpsCLHOjamouMp0h7mN-0rE-TYfN6BdbUVAsjCcTRovm7TuUbJoUpo0-RyTwKN6Un4KwvoCEg_D2FiLh9tFSytutQF7qhsV4q_1MeSPcTMLebaKQn6gjr9_X9JkQPm-ST9_pxa6rX4KzKA8Sv0Lu92gocQXj0mbDnTOHhAEA
Source: chromecache_73.2.dr, chromecache_74.2.dr String found in binary or memory: http://csi.gstatic.com/csi
Source: chromecache_85.2.dr String found in binary or memory: http://localhost.corp.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: http://localhost.proxy.googlers.com/inapp/
Source: chromecache_73.2.dr String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: chromecache_93.2.dr, chromecache_69.2.dr String found in binary or memory: http://www.bohemiancoding.com/sketch
Source: chromecache_93.2.dr, chromecache_69.2.dr String found in binary or memory: http://www.bohemiancoding.com/sketch/ns
Source: chromecache_73.2.dr, chromecache_77.2.dr String found in binary or memory: http://www.broofa.com
Source: chromecache_74.2.dr String found in binary or memory: https://accounts.google.com/o/fedcm/config.json
Source: chromecache_74.2.dr String found in binary or memory: https://accounts.google.com/o/oauth2/auth
Source: chromecache_74.2.dr String found in binary or memory: https://accounts.google.com/o/oauth2/iframe
Source: chromecache_71.2.dr, chromecache_98.2.dr, chromecache_97.2.dr String found in binary or memory: https://accounts.google.com/o/oauth2/postmessageRelay
Source: chromecache_71.2.dr, chromecache_98.2.dr, chromecache_97.2.dr, chromecache_77.2.dr String found in binary or memory: https://apis.google.com
Source: chromecache_73.2.dr, chromecache_81.2.dr String found in binary or memory: https://apis.google.com/js/api.js
Source: chromecache_73.2.dr, chromecache_85.2.dr String found in binary or memory: https://apis.google.com/js/client.js
Source: chromecache_71.2.dr String found in binary or memory: https://apis.google.com/js/googleapis.proxy.js
Source: chromecache_67.2.dr String found in binary or memory: https://apis.google.com/js/googleapis.proxy.js?onload=startup
Source: chromecache_73.2.dr String found in binary or memory: https://apps-drive-picker-dev.corp.google.com/picker/minpick/main
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.co.uk/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.co.uk/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.com/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.de/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.google.de/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.youtube.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-autopush.corp.youtube.com/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-staging.corp.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-frontend-staging.corp.google.com/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-help-frontend-autopush.corp.youtube.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://asx-help-frontend-autopush.corp.youtube.com/tools/feedback/
Source: chromecache_71.2.dr String found in binary or memory: https://classroom.google.com/sharewidget?usegapi=1
Source: chromecache_71.2.dr String found in binary or memory: https://clients3.google.com/cast/chromecast/home/widget/backdrop?usegapi=1
Source: chromecache_73.2.dr String found in binary or memory: https://clients5.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://clients5.google.com/webstore/wall/widget
Source: chromecache_81.2.dr, chromecache_74.2.dr String found in binary or memory: https://clients6.google.com
Source: chromecache_74.2.dr String found in binary or memory: https://console.developers.google.com/
Source: chromecache_81.2.dr String found in binary or memory: https://content-googleapis-staging.sandbox.google.com
Source: chromecache_81.2.dr String found in binary or memory: https://content-googleapis-test.sandbox.google.com
Source: chromecache_71.2.dr, chromecache_98.2.dr, chromecache_97.2.dr, chromecache_74.2.dr String found in binary or memory: https://content.googleapis.com
Source: chromecache_73.2.dr, chromecache_74.2.dr String found in binary or memory: https://csi.gstatic.com/csi
Source: chromecache_98.2.dr, chromecache_97.2.dr String found in binary or memory: https://csp.withgoogle.com/csp/lcreport/
Source: chromecache_71.2.dr String found in binary or memory: https://dataconnector.corp.google.com/:session_prefix:ui/widgetview?usegapi=1
Source: chromecache_74.2.dr String found in binary or memory: https://developers.google.com/
Source: chromecache_74.2.dr String found in binary or memory: https://developers.google.com/api-client-library/javascript/reference/referencedocs
Source: chromecache_74.2.dr String found in binary or memory: https://developers.google.com/identity/gsi/web/guides/gis-migration)
Source: chromecache_74.2.dr String found in binary or memory: https://developers.googleblog.com/2018/03/discontinuing-support-for-json-rpc-and.html
Source: chromecache_73.2.dr String found in binary or memory: https://docs.google.com/document/d/1kganm9BHI3TsF8ogVulX2o4DzzO8XA4gu8aIKneTTNU/preview
Source: chromecache_98.2.dr, chromecache_97.2.dr String found in binary or memory: https://domains.google.com/suggest/flow
Source: chromecache_73.2.dr String found in binary or memory: https://drive-thirdparty.googleusercontent.com/
Source: chromecache_73.2.dr String found in binary or memory: https://drive.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://drive.google.com/drive/my-drive
Source: chromecache_73.2.dr String found in binary or memory: https://drive.google.com/picker/minpick/main
Source: chromecache_73.2.dr String found in binary or memory: https://drive.google.com/requestreview?id=
Source: chromecache_71.2.dr String found in binary or memory: https://drive.google.com/savetodrivebutton?usegapi=1
Source: chromecache_73.2.dr String found in binary or memory: https://drive.google.com/viewer
Source: chromecache_73.2.dr String found in binary or memory: https://drivemetadata.clients6.google.com
Source: chromecache_71.2.dr String found in binary or memory: https://families.google.com/webcreation?usegapi=1&usegapi=1
Source: chromecache_85.2.dr String found in binary or memory: https://feedback-pa.clients6.google.com
Source: chromecache_85.2.dr String found in binary or memory: https://feedback.googleusercontent.com/resources/annotator.css
Source: chromecache_85.2.dr String found in binary or memory: https://feedback.googleusercontent.com/resources/render_frame2.html
Source: chromecache_85.2.dr String found in binary or memory: https://feedback2-test.corp.google.com/inapp/%
Source: chromecache_85.2.dr String found in binary or memory: https://feedback2-test.corp.google.com/tools/feedback/%
Source: chromecache_85.2.dr String found in binary or memory: https://feedback2-test.corp.googleusercontent.com/inapp/%
Source: chromecache_85.2.dr String found in binary or memory: https://feedback2-test.corp.googleusercontent.com/tools/feedback/%
Source: chromecache_76.2.dr String found in binary or memory: https://fonts.google.com/license/googlerestricted
Source: chromecache_73.2.dr String found in binary or memory: https://fonts.googleapis.com
Source: chromecache_73.2.dr String found in binary or memory: https://fonts.gstatic.com
Source: chromecache_81.2.dr String found in binary or memory: https://fonts.gstatic.com/s/e/notoemoji/
Source: chromecache_76.2.dr String found in binary or memory: https://fonts.gstatic.com/s/googlesans/v59/4UasrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iqcsih3SAyH6cAwhX9RP
Source: chromecache_77.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/alert/v11/gm_grey200-36dp/2x/gm_alert_gm_grey200_3
Source: chromecache_77.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/alert/v11/gm_grey600-36dp/2x/gm_alert_gm_grey600_3
Source: chromecache_77.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/close/v19/gm_grey200-24dp/1x/gm_close_gm_grey200_2
Source: chromecache_77.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/close/v19/gm_grey600-24dp/1x/gm_close_gm_grey600_2
Source: chromecache_73.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialiconsfilled/close/v19/gm_grey200-24dp/1x/gm_filled_close
Source: chromecache_85.2.dr String found in binary or memory: https://gstatic.com/uservoice/surveys/resources/
Source: chromecache_85.2.dr String found in binary or memory: https://help.youtube.com/tools/feedback/
Source: chromecache_81.2.dr String found in binary or memory: https://lh3.googleusercontent.com/a/default-user
Source: chromecache_85.2.dr String found in binary or memory: https://localhost.corp.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://localhost.proxy.googlers.com/inapp/
Source: chromecache_73.2.dr String found in binary or memory: https://mygoogle.corp.google.com/help/answer/9011840
Source: chromecache_73.2.dr String found in binary or memory: https://onepick-autopush.sandbox.google.com/picker/minpick/main
Source: chromecache_73.2.dr String found in binary or memory: https://onepick-preprod.sandbox.google.com/picker/minpick/main
Source: chromecache_73.2.dr String found in binary or memory: https://onepick-staging-drivequal.sandbox.google.com/picker/minpick/main
Source: chromecache_73.2.dr String found in binary or memory: https://onepick-staging.sandbox.google.com/picker/minpick/main
Source: chromecache_71.2.dr String found in binary or memory: https://pay.google.com/gp/v/widget/save
Source: chromecache_73.2.dr String found in binary or memory: https://play.google.com
Source: chromecache_77.2.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_71.2.dr String found in binary or memory: https://play.google.com/work/embedded/search?usegapi=1&usegapi=1
Source: chromecache_97.2.dr String found in binary or memory: https://plus.google.com
Source: chromecache_71.2.dr, chromecache_98.2.dr, chromecache_97.2.dr String found in binary or memory: https://plus.googleapis.com
Source: chromecache_73.2.dr String found in binary or memory: https://policies.google.com/privacy
Source: chromecache_73.2.dr String found in binary or memory: https://policies.google.com/terms
Source: chromecache_73.2.dr String found in binary or memory: https://policies.google.com/terms/generative-ai
Source: chromecache_73.2.dr String found in binary or memory: https://preprod-dynamite-alpha-us-signaler-pa.clients6.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://preprod-dynamite-alpha-us-signaler-pa.googleapis.com
Source: chromecache_73.2.dr String found in binary or memory: https://punctual-dev.corp.google.com
Source: chromecache_85.2.dr String found in binary or memory: https://sandbox.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://sandbox.google.com/inapp/%
Source: chromecache_85.2.dr String found in binary or memory: https://sandbox.google.com/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://sandbox.google.com/tools/feedback/%
Source: chromecache_85.2.dr String found in binary or memory: https://scone-pa.clients6.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://signaler-pa.clients6.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://signaler-pa.googleapis.com
Source: chromecache_73.2.dr String found in binary or memory: https://signaler-pa.youtube.com
Source: chromecache_73.2.dr String found in binary or memory: https://signaler-staging.sandbox.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://ssl.gstatic.com/docs/common/cleardot.gif
Source: chromecache_74.2.dr String found in binary or memory: https://ssl.gstatic.com/gb/js/
Source: chromecache_71.2.dr String found in binary or memory: https://ssl.gstatic.com/microscope/embed/
Source: chromecache_85.2.dr String found in binary or memory: https://stagingqual-feedback-pa-googleapis.sandbox.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com
Source: chromecache_85.2.dr String found in binary or memory: https://support.google.com/
Source: chromecache_81.2.dr String found in binary or memory: https://support.google.com/contacts/answer/7345608
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/docs/answer/148505
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/docs/answer/37603
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/docs/answer/49114
Source: chromecache_81.2.dr String found in binary or memory: https://support.google.com/docs/answer/65129
Source: chromecache_81.2.dr String found in binary or memory: https://support.google.com/docs/answer/65129?hl=en
Source: chromecache_81.2.dr String found in binary or memory: https://support.google.com/docs?p=comments_guide
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/drive/answer/2407404?hl=en
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/drive/answer/2423485?hl=%s
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/drive/answer/2423694
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/drive/answer/7650301
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/google-workspace-individual/?p=esignatur
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/google-workspace-individual/?p=esignature_signer_terms
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/google-workspace-individual/?p=esignature_signer_tos
Source: chromecache_85.2.dr String found in binary or memory: https://support.google.com/inapp/
Source: chromecache_85.2.dr String found in binary or memory: https://support.google.com/inapp/%
Source: chromecache_73.2.dr String found in binary or memory: https://support.google.com/legal/answer/3110420
Source: chromecache_71.2.dr String found in binary or memory: https://talkgadget.google.com/:session_prefix:talkgadget/_/widget
Source: chromecache_85.2.dr String found in binary or memory: https://test-scone-pa-googleapis.sandbox.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
Source: chromecache_73.2.dr String found in binary or memory: https://workspace.google.com
Source: chromecache_71.2.dr, chromecache_98.2.dr, chromecache_97.2.dr String found in binary or memory: https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
Source: chromecache_73.2.dr String found in binary or memory: https://workspacevideo-pa.googleapis.com
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.cn/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.cn/tools/feedback/%
Source: chromecache_73.2.dr String found in binary or memory: https://www.google.com
Source: chromecache_73.2.dr String found in binary or memory: https://www.google.com/recaptcha/api.js?trustedtypes=true
Source: chromecache_71.2.dr String found in binary or memory: https://www.google.com/shopping/customerreviews/badge?usegapi=1
Source: chromecache_71.2.dr String found in binary or memory: https://www.google.com/shopping/customerreviews/optin?usegapi=1
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.com/tools/feedback
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.com/tools/feedback/
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.com/tools/feedback/%
Source: chromecache_85.2.dr String found in binary or memory: https://www.google.com/tools/feedback/help_panel_binary.js
Source: chromecache_74.2.dr String found in binary or memory: https://www.googleapis.com/auth/plus.login
Source: chromecache_97.2.dr String found in binary or memory: https://www.googleapis.com/auth/plus.me
Source: chromecache_97.2.dr String found in binary or memory: https://www.googleapis.com/auth/plus.people.recommended
Source: chromecache_73.2.dr String found in binary or memory: https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js
Source: chromecache_77.2.dr String found in binary or memory: https://www.gstatic.com/gb/html/afbp.html
Source: chromecache_73.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/productlogos/calendar_2020q4/v13/192px.svg
Source: chromecache_73.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/productlogos/tasks/v10/192px.svg
Source: chromecache_77.2.dr String found in binary or memory: https://www.gstatic.com/images/icons/material/anim/mspin/mspin_googcolor_medium.css
Source: chromecache_77.2.dr String found in binary or memory: https://www.gstatic.com/images/icons/material/anim/mspin/mspin_googcolor_small.css
Source: chromecache_77.2.dr String found in binary or memory: https://www.gstatic.com/images/icons/material/system/1x/broken_image_grey600_18dp.png
Source: chromecache_77.2.dr String found in binary or memory: https://www.gstatic.com/images/icons/material/system/2x/broken_image_grey600_18dp.png
Source: chromecache_71.2.dr String found in binary or memory: https://www.gstatic.com/partners/badge/templates/badge.html?usegapi=1
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/change_email_address_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/change_name_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/content_copy_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/content_cut_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/email_copy_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/info_outline_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/phone_copy_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/visibility_grey300.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/dark_theme/visibility_off_grey200.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/change_email_address_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/change_name_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/content_copy_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/content_cut_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/domain_disabled_grey900.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/email_copy_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/info_outline_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/phone_copy_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/visibility_grey700.svg
Source: chromecache_81.2.dr String found in binary or memory: https://www.gstatic.com/people/peoplekit/icons/light_theme/visibility_off_grey700.svg
Source: chromecache_85.2.dr String found in binary or memory: https://www.gstatic.com/uservoice/feedback/client/web/
Source: chromecache_85.2.dr String found in binary or memory: https://www.gstatic.com/uservoice/surveys/resources/
Source: chromecache_73.2.dr String found in binary or memory: https://www.youtube.com
Source: chromecache_71.2.dr String found in binary or memory: https://www.youtube.com/subscribe_embed?usegapi=1
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49807 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49810 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49816
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49813
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49812
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49810
Source: unknown Network traffic detected: HTTP traffic on port 49816 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 49812 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49802 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49806 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49807
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49806
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49803
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49802
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.196.177.159:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engine Classification label: clean0.win@18/62@26/8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2000,i,14581527048622102592,2490894029752333022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://drive.google.com/file/d/1HmJh1r0AHBaVt_XxqEt2i6WUzzgePMuc/view"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2000,i,14581527048622102592,2490894029752333022,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs