Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://survey.apps.pdricloud.com

Overview

General Information

Sample URL:http://survey.apps.pdricloud.com
Analysis ID:736952
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1796 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2880 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1724,i,4850779736149216259,13576850689647810483,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5984 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://survey.apps.pdricloud.com MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@27/0@5/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1724,i,4850779736149216259,13576850689647810483,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://survey.apps.pdricloud.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1724,i,4850779736149216259,13576850689647810483,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://survey.apps.pdricloud.com0%VirustotalBrowse
http://survey.apps.pdricloud.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.143.141
truefalse
    high
    www.google.com
    142.251.143.132
    truefalse
      high
      clients.l.google.com
      142.251.143.174
      truefalse
        high
        prod-app-964824229.us-east-1.elb.amazonaws.com
        54.173.73.112
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            survey.apps.pdricloud.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  54.173.73.112
                  prod-app-964824229.us-east-1.elb.amazonaws.comUnited States
                  14618AMAZON-AESUSfalse
                  52.72.68.102
                  unknownUnited States
                  14618AMAZON-AESUSfalse
                  142.251.143.132
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.251.143.141
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.251.143.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  54.196.226.234
                  unknownUnited States
                  14618AMAZON-AESUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:736952
                  Start date and time:2022-11-03 12:24:48 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 4m 40s
                  Hypervisor based Inspection enabled:false
                  Report type:light
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://survey.apps.pdricloud.com
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@27/0@5/9
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                  • TCP Packets have been reduced to 100
                  • Excluded IPs from analysis (whitelisted): 142.251.143.163, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 3, 2022 12:25:48.802701950 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:48.802755117 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:48.802844048 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:48.803380013 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:48.803431988 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.803505898 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:48.803925037 CET4970380192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:48.805438042 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:48.805475950 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:48.805727005 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:48.805757046 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.844378948 CET4970480192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:48.898370981 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:48.899574995 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:48.899631977 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:48.901560068 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.905193090 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:48.905323029 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:48.907047033 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:48.907084942 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.908086061 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.908185005 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:48.909775972 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:48.909842968 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.074856043 CET4970680192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:49.075782061 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.075880051 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.075968027 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.077219009 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.077241898 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.181154966 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.203989983 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.204034090 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.206408978 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.206577063 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.371680021 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.371748924 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.372133970 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.372145891 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.372394085 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.372456074 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.372601032 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.372708082 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.373692989 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:49.373733997 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.373862982 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.374790907 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:49.374839067 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.428797007 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.428985119 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.429013014 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.429891109 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.430006981 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.435445070 CET49702443192.168.2.5142.251.143.174
                  Nov 3, 2022 12:25:49.435475111 CET44349702142.251.143.174192.168.2.5
                  Nov 3, 2022 12:25:49.443157911 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.443341017 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:49.443344116 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.443411112 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:49.470700026 CET49701443192.168.2.5142.251.143.141
                  Nov 3, 2022 12:25:49.470757008 CET44349701142.251.143.141192.168.2.5
                  Nov 3, 2022 12:25:49.485311985 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:49.485356092 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:49.585659981 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:25:51.878565073 CET4970380192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:51.879978895 CET4970480192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:52.085540056 CET4970680192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:57.879961014 CET4970380192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:57.879981041 CET4970480192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:58.085958004 CET4970680192.168.2.554.173.73.112
                  Nov 3, 2022 12:25:59.149203062 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:59.149300098 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:25:59.149430037 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:26:02.964536905 CET49708443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:26:02.964579105 CET44349708142.251.143.132192.168.2.5
                  Nov 3, 2022 12:26:10.074806929 CET4972480192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:10.075242043 CET4972580192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:10.188272953 CET4972680192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:13.087141037 CET4972480192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:13.089790106 CET4972580192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:13.381136894 CET4972680192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:19.087588072 CET4972480192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:19.091315985 CET4972580192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:19.474607944 CET4972680192.168.2.552.72.68.102
                  Nov 3, 2022 12:26:31.089457035 CET4973980192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:31.089732885 CET4974080192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:31.588469982 CET4974180192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:34.276499033 CET4973980192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:34.276540995 CET4974080192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:34.679806948 CET4974180192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:40.339196920 CET4973980192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:40.339270115 CET4974080192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:40.739217997 CET4974180192.168.2.554.196.226.234
                  Nov 3, 2022 12:26:48.876180887 CET49745443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:26:48.876341105 CET44349745142.251.143.132192.168.2.5
                  Nov 3, 2022 12:26:48.876657009 CET49745443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:26:48.909447908 CET49745443192.168.2.5142.251.143.132
                  Nov 3, 2022 12:26:48.909512997 CET44349745142.251.143.132192.168.2.5
                  Nov 3, 2022 12:26:49.001848936 CET44349745142.251.143.132192.168.2.5
                  Nov 3, 2022 12:26:49.044893026 CET49745443192.168.2.5142.251.143.132
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 3, 2022 12:25:48.138623953 CET5144153192.168.2.58.8.8.8
                  Nov 3, 2022 12:25:48.140582085 CET4917753192.168.2.58.8.8.8
                  Nov 3, 2022 12:25:48.156235933 CET53514418.8.8.8192.168.2.5
                  Nov 3, 2022 12:25:48.163027048 CET53491778.8.8.8192.168.2.5
                  Nov 3, 2022 12:25:48.737209082 CET6145253192.168.2.58.8.8.8
                  Nov 3, 2022 12:25:48.771136999 CET53614528.8.8.8192.168.2.5
                  Nov 3, 2022 12:25:48.895803928 CET6532353192.168.2.58.8.8.8
                  Nov 3, 2022 12:25:48.916290045 CET53653238.8.8.8192.168.2.5
                  Nov 3, 2022 12:26:53.776024103 CET6028453192.168.2.58.8.8.8
                  Nov 3, 2022 12:26:53.801664114 CET53602848.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Nov 3, 2022 12:25:48.138623953 CET192.168.2.58.8.8.80x9bc3Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.140582085 CET192.168.2.58.8.8.80x2159Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.737209082 CET192.168.2.58.8.8.80x2bbeStandard query (0)survey.apps.pdricloud.comA (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.895803928 CET192.168.2.58.8.8.80xa9e4Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Nov 3, 2022 12:26:53.776024103 CET192.168.2.58.8.8.80xbbc9Standard query (0)survey.apps.pdricloud.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Nov 3, 2022 12:25:48.156235933 CET8.8.8.8192.168.2.50x9bc3No error (0)accounts.google.com142.251.143.141A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.163027048 CET8.8.8.8192.168.2.50x2159No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Nov 3, 2022 12:25:48.163027048 CET8.8.8.8192.168.2.50x2159No error (0)clients.l.google.com142.251.143.174A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.771136999 CET8.8.8.8192.168.2.50x2bbeNo error (0)survey.apps.pdricloud.comprod-app-964824229.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Nov 3, 2022 12:25:48.771136999 CET8.8.8.8192.168.2.50x2bbeNo error (0)prod-app-964824229.us-east-1.elb.amazonaws.com54.173.73.112A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.771136999 CET8.8.8.8192.168.2.50x2bbeNo error (0)prod-app-964824229.us-east-1.elb.amazonaws.com52.72.68.102A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.771136999 CET8.8.8.8192.168.2.50x2bbeNo error (0)prod-app-964824229.us-east-1.elb.amazonaws.com54.196.226.234A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:25:48.916290045 CET8.8.8.8192.168.2.50xa9e4No error (0)www.google.com142.251.143.132A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:26:53.801664114 CET8.8.8.8192.168.2.50xbbc9No error (0)survey.apps.pdricloud.comprod-app-964824229.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Nov 3, 2022 12:26:53.801664114 CET8.8.8.8192.168.2.50xbbc9No error (0)prod-app-964824229.us-east-1.elb.amazonaws.com52.72.68.102A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:26:53.801664114 CET8.8.8.8192.168.2.50xbbc9No error (0)prod-app-964824229.us-east-1.elb.amazonaws.com54.173.73.112A (IP address)IN (0x0001)false
                  Nov 3, 2022 12:26:53.801664114 CET8.8.8.8192.168.2.50xbbc9No error (0)prod-app-964824229.us-east-1.elb.amazonaws.com54.196.226.234A (IP address)IN (0x0001)false
                  • clients2.google.com
                  • accounts.google.com

                  Click to jump to process

                  Target ID:0
                  Start time:12:25:42
                  Start date:03/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:12:25:43
                  Start date:03/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1724,i,4850779736149216259,13576850689647810483,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:12:25:44
                  Start date:03/11/2022
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://survey.apps.pdricloud.com
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly