Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://nero-massage.shop

Overview

General Information

Sample URL:http://nero-massage.shop
Analysis ID:753422
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2328 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5152 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1812,i,3518441739163221011,6637184233728530685,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5352 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://nero-massage.shop MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: nero-massage.shopConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: nero-massage.shopConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://nero-massage.shop/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: clean0.win@25/0@5/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1812,i,3518441739163221011,6637184233728530685,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://nero-massage.shop
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1812,i,3518441739163221011,6637184233728530685,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://nero-massage.shop0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://nero-massage.shop/favicon.ico0%Avira URL Cloudsafe
http://nero-massage.shop/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.168.45
truefalse
    high
    nero-massage.shop
    212.192.218.253
    truefalse
      unknown
      www.google.com
      172.217.168.36
      truefalse
        high
        clients.l.google.com
        142.250.203.110
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://nero-massage.shop/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                http://nero-massage.shop/false
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.217.168.68
                unknownUnited States
                15169GOOGLEUSfalse
                172.217.168.45
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                172.217.168.36
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.203.110
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                212.192.218.253
                nero-massage.shopRussian Federation
                8663KUBANNETRUfalse
                IP
                192.168.2.1
                127.0.0.1
                Joe Sandbox Version:36.0.0 Rainbow Opal
                Analysis ID:753422
                Start date and time:2022-11-24 19:52:32 +01:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 3m 56s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://nero-massage.shop
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:12
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@25/0@5/8
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Nov 24, 2022 19:53:31.423285007 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:31.423355103 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:31.423434973 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:31.424011946 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:31.424046993 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:31.493980885 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:31.499541044 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:31.499573946 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:31.501488924 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:31.501599073 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:31.539515972 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.539561987 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.539634943 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.539920092 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.539932013 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.610112906 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.746639013 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.968321085 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.968385935 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.970623970 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.970649958 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.970714092 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.972928047 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:31.973007917 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:31.973042011 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.046624899 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:32.914686918 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:32.914762020 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.914999962 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:32.915014029 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.915146112 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.915210962 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:32.915245056 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.915534019 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.915927887 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:32.915965080 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.949918985 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.950086117 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:32.950143099 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.950196028 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:32.950251102 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:32.993544102 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.993673086 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:32.993729115 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.994059086 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:32.994124889 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:33.118357897 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.118360043 CET49700443192.168.2.3142.250.203.110
                Nov 24, 2022 19:53:33.118438959 CET44349700142.250.203.110192.168.2.3
                Nov 24, 2022 19:53:33.120249987 CET49698443192.168.2.3172.217.168.45
                Nov 24, 2022 19:53:33.120311022 CET44349698172.217.168.45192.168.2.3
                Nov 24, 2022 19:53:33.124341965 CET4970280192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.170217991 CET4970380192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.220031977 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.220130920 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.227030039 CET8049702212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.227173090 CET4970280192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.273191929 CET8049703212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.273358107 CET4970380192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.322195053 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.424112082 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.426261902 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.514729977 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.674765110 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:33.777182102 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.777218103 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.777236938 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:53:33.777350903 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:53:34.531985044 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.532059908 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.532160044 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.532707930 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.532824993 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.594708920 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.595299959 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.595340967 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.597248077 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.597320080 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.614911079 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.614952087 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.615217924 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.761991024 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:34.762031078 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:34.961536884 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:44.584458113 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:44.584551096 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:53:44.584625959 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:46.052603006 CET49707443192.168.2.3172.217.168.36
                Nov 24, 2022 19:53:46.052645922 CET44349707172.217.168.36192.168.2.3
                Nov 24, 2022 19:54:18.240581036 CET4970280192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:18.287508965 CET4970380192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:18.342931986 CET8049702212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:18.390132904 CET8049703212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:18.787626028 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:18.889396906 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:33.334175110 CET8049702212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:33.334989071 CET4970280192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:33.376420021 CET8049703212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:33.376907110 CET4970380192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:34.607464075 CET4970380192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:34.607490063 CET4970280192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:34.607975960 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:34.608025074 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.608107090 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:34.608957052 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:34.608983994 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.667789936 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.668751001 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:34.668814898 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.669987917 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.671118021 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:34.671161890 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.671360970 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:34.709938049 CET8049703212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:34.709994078 CET8049702212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:34.726356983 CET49731443192.168.2.3172.217.168.68
                Nov 24, 2022 19:54:38.777882099 CET8049701212.192.218.253192.168.2.3
                Nov 24, 2022 19:54:38.778009892 CET4970180192.168.2.3212.192.218.253
                Nov 24, 2022 19:54:44.647192955 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:44.647295952 CET44349731172.217.168.68192.168.2.3
                Nov 24, 2022 19:54:44.647372007 CET49731443192.168.2.3172.217.168.68
                TimestampSource PortDest PortSource IPDest IP
                Nov 24, 2022 19:53:31.290333033 CET5238753192.168.2.38.8.8.8
                Nov 24, 2022 19:53:31.293097973 CET5692453192.168.2.38.8.8.8
                Nov 24, 2022 19:53:31.318754911 CET53569248.8.8.8192.168.2.3
                Nov 24, 2022 19:53:31.332197905 CET53523878.8.8.8192.168.2.3
                Nov 24, 2022 19:53:32.778382063 CET6062553192.168.2.38.8.8.8
                Nov 24, 2022 19:53:32.800947905 CET53606258.8.8.8192.168.2.3
                Nov 24, 2022 19:53:34.503326893 CET6058253192.168.2.38.8.8.8
                Nov 24, 2022 19:53:34.522851944 CET53605828.8.8.8192.168.2.3
                Nov 24, 2022 19:54:34.580152988 CET6074953192.168.2.38.8.8.8
                Nov 24, 2022 19:54:34.599622011 CET53607498.8.8.8192.168.2.3
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Nov 24, 2022 19:53:31.290333033 CET192.168.2.38.8.8.80xe865Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:31.293097973 CET192.168.2.38.8.8.80x1a75Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:32.778382063 CET192.168.2.38.8.8.80xe00fStandard query (0)nero-massage.shopA (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:34.503326893 CET192.168.2.38.8.8.80x8233Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Nov 24, 2022 19:54:34.580152988 CET192.168.2.38.8.8.80x9fe9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Nov 24, 2022 19:53:31.318754911 CET8.8.8.8192.168.2.30x1a75No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:31.332197905 CET8.8.8.8192.168.2.30xe865No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Nov 24, 2022 19:53:31.332197905 CET8.8.8.8192.168.2.30xe865No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:32.800947905 CET8.8.8.8192.168.2.30xe00fNo error (0)nero-massage.shop212.192.218.253A (IP address)IN (0x0001)false
                Nov 24, 2022 19:53:34.522851944 CET8.8.8.8192.168.2.30x8233No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                Nov 24, 2022 19:54:34.599622011 CET8.8.8.8192.168.2.30x9fe9No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • nero-massage.shop
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349700142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349698172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.349701212.192.218.25380C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Nov 24, 2022 19:53:33.322195053 CET179OUTGET / HTTP/1.1
                Host: nero-massage.shop
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Nov 24, 2022 19:53:33.426261902 CET179INHTTP/1.1 200 OK
                Server: nginx/1.18.0
                Date: Thu, 24 Nov 2022 18:53:15 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: keep-alive
                X-Powered-By: PHP/7.3.17
                Data Raw: 31 0d 0a 0a 0d 0a 30 0d 0a 0d 0a
                Data Ascii: 10
                Nov 24, 2022 19:53:33.674765110 CET180OUTGET /favicon.ico HTTP/1.1
                Host: nero-massage.shop
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Referer: http://nero-massage.shop/
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Nov 24, 2022 19:53:33.777182102 CET181INHTTP/1.1 200 OK
                Server: nginx/1.18.0
                Date: Thu, 24 Nov 2022 18:53:16 GMT
                Content-Type: image/x-icon
                Content-Length: 1406
                Last-Modified: Wed, 15 Jun 2016 01:14:34 GMT
                Connection: keep-alive
                ETag: "5760abfa-57e"
                Accept-Ranges: bytes
                Nov 24, 2022 19:53:33.777218103 CET182INData Raw: 00 00 01 00 01 00 10 10 00 00 00 00 00 00 68 05 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 08 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                Data Ascii: h(
                Nov 24, 2022 19:53:33.777236938 CET182INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                Data Ascii:
                Nov 24, 2022 19:54:18.787626028 CET525OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.349702212.192.218.25380C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Nov 24, 2022 19:54:18.240581036 CET525OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                4192.168.2.349703212.192.218.25380C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Nov 24, 2022 19:54:18.287508965 CET525OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349700142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-11-24 18:53:32 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-11-24 18:53:32 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-apyOByC1C6-VKninSvFTBA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Thu, 24 Nov 2022 18:53:32 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5806
                X-Daystart: 39212
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-11-24 18:53:32 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 30 36 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 39 32 31 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5806" elapsed_seconds="39212"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2022-11-24 18:53:32 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                2022-11-24 18:53:32 UTC3INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349698172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-11-24 18:53:32 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                2022-11-24 18:53:32 UTC1OUTData Raw: 20
                Data Ascii:
                2022-11-24 18:53:32 UTC3INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Thu, 24 Nov 2022 18:53:32 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-zwXou871vltiQBUSDW7Qhw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-11-24 18:53:32 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2022-11-24 18:53:32 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:19:53:28
                Start date:24/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:19:53:29
                Start date:24/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1812,i,3518441739163221011,6637184233728530685,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:2
                Start time:19:53:30
                Start date:24/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://nero-massage.shop
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly