Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com

Overview

General Information

Sample URL:https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com
Analysis ID:715101
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2864 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2884 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1684,i,214760526226116170,2327631706366296599,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 748 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: exchange.peer1mail.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@30/0@9/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1684,i,214760526226116170,2327631706366296599,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1684,i,214760526226116170,2327631706366296599,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com0%VirustotalBrowse
https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.168.14
truefalse
    high
    accounts.google.com
    142.250.203.109
    truefalse
      high
      www.google.com
      142.250.203.100
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            exchange.peer1mail.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.203.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.110
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.203.109
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:715101
                  Start date and time:2022-10-03 16:19:21 +02:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 4m 44s
                  Hypervisor based Inspection enabled:false
                  Report type:light
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@30/0@9/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                  • TCP Packets have been reduced to 100
                  • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 3, 2022 16:20:24.051779032 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.051829100 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.051951885 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.053767920 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.053848028 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.053989887 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.060194016 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.060250998 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.060343981 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.061919928 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.061943054 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.063038111 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.063128948 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.064266920 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.064296007 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.133338928 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.165659904 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.191157103 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.232955933 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.232968092 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.233134985 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.256387949 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.256407976 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.258845091 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.258898973 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.258961916 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.259130001 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.259161949 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.259751081 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.259778023 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.259900093 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.259924889 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.260004997 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.260826111 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.260929108 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.260962009 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.261513948 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.261615992 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.335514069 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.335521936 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.658035040 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.658066988 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.658158064 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.658191919 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.658246994 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.658354998 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.658482075 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.658505917 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.658624887 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.658659935 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.658668995 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.658955097 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.658970118 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.691628933 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.691787004 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.691813946 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.691879988 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.691936016 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.713380098 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.713491917 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.713524103 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.713629007 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.713707924 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.733463049 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.733503103 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.840573072 CEST49698443192.168.2.5142.250.203.110
                  Oct 3, 2022 16:20:24.840615988 CEST44349698142.250.203.110192.168.2.5
                  Oct 3, 2022 16:20:24.842269897 CEST49699443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:24.842303991 CEST44349699142.250.203.109192.168.2.5
                  Oct 3, 2022 16:20:24.933002949 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:20:25.543442965 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.543503046 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.543601990 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.543943882 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.543970108 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.608477116 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.609059095 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.609102964 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.611253977 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.611355066 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.613387108 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.613409996 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.613637924 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.658992052 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:25.659014940 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:25.758991003 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:35.583921909 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:35.584045887 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:20:35.584132910 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:37.342545986 CEST49704443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:20:37.342590094 CEST44349704142.250.203.100192.168.2.5
                  Oct 3, 2022 16:21:09.748512030 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:21:09.748539925 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:21:25.175247908 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:21:25.175491095 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:21:25.175936937 CEST44349701142.250.203.109192.168.2.5
                  Oct 3, 2022 16:21:25.176187992 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:21:25.176187992 CEST49701443192.168.2.5142.250.203.109
                  Oct 3, 2022 16:21:25.545409918 CEST49752443192.168.2.5142.250.203.100
                  Oct 3, 2022 16:21:25.545455933 CEST44349752142.250.203.100192.168.2.5
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 3, 2022 16:20:23.419025898 CEST6189353192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:23.421101093 CEST6064953192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:23.438765049 CEST4917753192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:23.441421032 CEST53618938.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:23.449239016 CEST53606498.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:23.456290960 CEST53491778.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:24.841840029 CEST6145253192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:24.843733072 CEST6532353192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:24.859486103 CEST53614528.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:24.883538961 CEST53653238.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:25.484333992 CEST5675153192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:25.503818035 CEST53567518.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:25.737596989 CEST5503953192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:25.759984016 CEST53550398.8.8.8192.168.2.5
                  Oct 3, 2022 16:20:30.830960989 CEST5506853192.168.2.58.8.8.8
                  Oct 3, 2022 16:20:30.853333950 CEST53550688.8.8.8192.168.2.5
                  Oct 3, 2022 16:21:00.953989983 CEST6134453192.168.2.58.8.8.8
                  Oct 3, 2022 16:21:00.974195957 CEST53613448.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Oct 3, 2022 16:20:23.419025898 CEST192.168.2.58.8.8.80x97ecStandard query (0)exchange.peer1mail.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:23.421101093 CEST192.168.2.58.8.8.80x8c3aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:23.438765049 CEST192.168.2.58.8.8.80xc44eStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:24.841840029 CEST192.168.2.58.8.8.80x9acfStandard query (0)google.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:24.843733072 CEST192.168.2.58.8.8.80x6d32Standard query (0)google.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:25.484333992 CEST192.168.2.58.8.8.80x998bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:25.737596989 CEST192.168.2.58.8.8.80x43aaStandard query (0)exchange.peer1mail.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:30.830960989 CEST192.168.2.58.8.8.80xa1feStandard query (0)exchange.peer1mail.comA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:21:00.953989983 CEST192.168.2.58.8.8.80x4ff5Standard query (0)exchange.peer1mail.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Oct 3, 2022 16:20:23.441421032 CEST8.8.8.8192.168.2.50x97ecName error (3)exchange.peer1mail.comnonenoneA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:23.449239016 CEST8.8.8.8192.168.2.50x8c3aNo error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:23.456290960 CEST8.8.8.8192.168.2.50xc44eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Oct 3, 2022 16:20:23.456290960 CEST8.8.8.8192.168.2.50xc44eNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:24.859486103 CEST8.8.8.8192.168.2.50x9acfNo error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:24.883538961 CEST8.8.8.8192.168.2.50x6d32No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:25.503818035 CEST8.8.8.8192.168.2.50x998bNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:25.759984016 CEST8.8.8.8192.168.2.50x43aaName error (3)exchange.peer1mail.comnonenoneA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:20:30.853333950 CEST8.8.8.8192.168.2.50xa1feName error (3)exchange.peer1mail.comnonenoneA (IP address)IN (0x0001)false
                  Oct 3, 2022 16:21:00.974195957 CEST8.8.8.8192.168.2.50x4ff5Name error (3)exchange.peer1mail.comnonenoneA (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.549699142.250.203.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2022-10-03 14:20:24 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2022-10-03 14:20:24 UTC0OUTData Raw: 20
                  Data Ascii:
                  2022-10-03 14:20:24 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 03 Oct 2022 14:20:24 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Content-Security-Policy: script-src 'report-sample' 'nonce-slJLjbT4dUTD-cSvEIqnUw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2022-10-03 14:20:24 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2022-10-03 14:20:24 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.549698142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2022-10-03 14:20:24 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2022-10-03 14:20:24 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-qAeFj--oiOXtK19BNsBCVQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Mon, 03 Oct 2022 14:20:24 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5754
                  X-Daystart: 26424
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2022-10-03 14:20:24 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 37 35 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 36 34 32 34 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5754" elapsed_seconds="26424"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2022-10-03 14:20:24 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                  Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                  2022-10-03 14:20:24 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Target ID:0
                  Start time:16:20:18
                  Start date:03/10/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:16:20:19
                  Start date:03/10/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1684,i,214760526226116170,2327631706366296599,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:16:20:20
                  Start date:03/10/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://exchange.peer1mail.com/owa/redir.aspx?C=wgR2q3HbC0uy9E8GvGWQ2Bgy3QbVddQIcydo0BYe8b4e5zUfLN1bO9pOjhtyQAmZxMHuwgsiKX8.&URL=http%3a%2f%2fwww.pay2global.com
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly